[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [xacml] Groups - XACML v3.0 Related and Nested Entities Profile Version 1.0 uploaded
Thanks Steven for the well-written document. I had some minor comments and some issues to discuss: S2.1P4:
"Evaluation of the _expression_ MAY terminate at the first value from the domain for which the iterant _expression_ evaluates to “true”."
I think the meaning of "first" here is ambiguous and might be misleading as according
to the spec, bags are unordered. I suggest either editing this to remove the word “first” or adding a sentence to emphasize that the implementation must not assume any particular order for processing of bags, and first means the first entity encountered regardless
of the order of processing. S2.1P4 and S2.2: I suggest that, since there is no formal definition of these quantifiers,
we explicitly clarify the value of ForAny and ForAll for an empty Domain. There are also two issues for discussion: -
As someone said before on the list, in case of large data sets, there should
be a mechanism to notify the PEP or PAP to include in the request only part of the related entities that are consequential in the PDP’s decision. For example, if the policy is to allow access “if the resource owner has a friend who is over 18”, this will require
including all of the resource owner’s friends in the request. Finding some way to communicate what is sufficient to be included in the request is at least worth mentioning as an implementation issue. -
There should be some sort of discussion about the completeness of the set
of operators defined in the profile. Right now, it appears that the supported operators are similar to those of description logic, but can/should we support more operators? For example, operators for “reflexive transitive closure” (e.g. friend-of-friend-of-friend-…),
“cardinality” (number of related entities that satisfy a predicate), or inverse relations? Regards, Mohammad Jafari, Ph.D. Security Architect, Edmond Scientific Company From: xacml@lists.oasis-open.org [mailto:xacml@lists.oasis-open.org]
On Behalf Of Steven Legg Submitter's message
|
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]