xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03 .pdfuploaded
MHonArc v2.5.0b2 -->xacml message
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03 .pdfuploaded
- From: Anne Anderson <[email protected]>
- To: Tim Moses <[email protected]>
- Date: Thu, 26 Aug 2004 14:07:14 -0400
Tim,
Thanks for the comments. Here is how I responded to them in
Draft 04.
On 17 August, Tim Moses writes: RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03 .pdf uploaded
> In sections 3.1.3 and 3.2.3 outcomes of "Indeterminate" and "NotApplicable"
> are not currently discussed.
I changed text to say explicitly "If any of the new request
contexts evaluates to "Deny", "Indeterminate", or
"NotApplicable", then a single <Result> containing a <Decision>
of "Deny" SHALL be placed into the response context returned to
the PEP. This is as if the responses were being combined under a
"DenyOverrides" combining algorithm, which seems to be the only
safe single choice.
> Trivial ...
>
> 19 - Include instructions for using the Web form to submit comments (see
> text on the front page of the core spec.).
Done.
> 52 - unbold "authorization". Only "decision request" is in
the glossary.
I deleted "authorization" and changed to say just "decision
request".
> 121 and elsewhere - I prefer not to use the section title in the section
> reference (e.g. Section 4.1:"scope"). This is because it isn't always clear
> where the section title ends and the normal text continues.
Done.
> 132 - Change "is the contents of the <AttributeValue>" to "SHALL be the
> contents of the <AttributeValue> element".
Done.
> 146 - <children> to <Children> and <descendants> to <Descendants>. Also,
> how about a shorter title for sections 2.1 and 2.2. I suggest: "Nodes
> identified by scope" and "Nodes identified by XPath"?
I took your suggestions for the shorter titles.
> In Section 2.1, include a note to the effect that "scope" is defined in
> Section 4.
Done.
> 161 - Eliminate duplicate "be".
Done.
> 168 & 170 - Change "the Individual Resources are" to "each Individual
> Resource is".
Done.
> 196 - Change "attribute evaluates" to "attribute is an xpath expression that
> evaluates".
Done.
> 223 - Correct formatting of <Resource>.
Done.
> 224 - Change "the mechanisms" to "the other mechanisms".
Done.
> 243 - Eliminate duplicate "a".
Done.
> 266 - Eliminate leading space.
Done.
> 277 - Change "containing" to "contains".
Done.
> 277 - Eliminate "That node SHALL be the one corresponding to the new request
> context.". I think this is redundant. Isn't it?
I removed the sentence, but changed the previous sentence to say
"nodeset that contains exactly that one node in the
^^^^
<ResourceContent> element"
My concern was that the XPath expression might well evaluate to
only a single node, but that node might be some node other than
the one that this new Request Context is being constructed for.
> 295 - Eliminate leading space.
Done. Eagle eye!
> 305 - Eliminate "That node SHALL be the one corresponding to the new request
> context.". I think this is redundant. Isn't it?
Same changes as for 277.
Thanks again.
Anne
>
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]