OASIS eXtensible Access Control Markup Language (XACML) TC

 View Only
  • 1.  resource-id attribute: mandatory or optional?

    Posted 07-12-2010 14:52
    
    
    
    
    
    
    
    
    
    
    

    Dear all,

    section 10.2.6 in the xacml 3.0 core spec defines the resource-id attribute as mandatory. From my point of view it would be more convenient to define it as optional as the content-selector attribute is doing the same thing. Defining resource-id as mandatory forces decision requests to contain this attribute even if never used.

    best regards

    jan

    ________________________________________

    Jan Herrmann
    Dipl.-Inform., Dipl.-Geogr. 

    wissenschaftlicher Mitarbeiter

    Technische Universität München
    Institut für Informatik

    Lehrstuhl für Angewandte Informatik / Kooperative Systeme

    Boltzmannstr. 3
    85748 Garching

    Tel:      +49 (0)89 289-18692
    Fax:     +49 (0)89 289-18657

    Raum:
    www11.informatik.tu-muenchen.de
    ________________________________________



  • 2.  Re: [xacml] resource-id attribute: mandatory or optional?

    Posted 07-12-2010 16:12
    
    
      
    
    
    Jan,

    This is the conformance section. It means that the PDP must treat the resource-id attribute as specified. It does not say that the resource-id must be part of every request.

    (BTW, I cannot think of anything special the PDP has to do with the resource-id in the core spec anyway. The multiple and hierarchical profiles though contain lots of requirements for the PDP/context handler.)

    Best regards,
    Erik


    On 07/12/2010 04:51 PM, Jan Herrmann wrote:

    Dear all,

    section 10.2.6 in the xacml 3.0 core spec defines the resource-id attribute as mandatory. From my point of view it would be more convenient to define it as optional as the content-selector attribute is doing the same thing. Defining resource-id as mandatory forces decision requests to contain this attribute even if never used.

    best regards

    jan

    ________________________________________

    Jan Herrmann
    Dipl.-Inform., Dipl.-Geogr. 

    wissenschaftlicher Mitarbeiter

    Technische Universität München
    Institut für Informatik

    Lehrstuhl für Angewandte Informatik / Kooperative Systeme

    Boltzmannstr. 3
    85748 Garching

    Tel:      +49 (0)89 289-18692
    Fax:     +49 (0)89 289-18657

    Raum:
    www11.informatik.tu-muenchen.de
    ________________________________________