【问题标题】:How to trace the value for an attribute using obligations in XACML如何使用 XACML 中的义务跟踪属性的值
【发布时间】:2016-01-27 20:31:38
【问题描述】:

想知道是否有办法加载先前由 PIP 扩展属性查找器加载的属性值并将其 ($myattr1) 转换为义务,以便以明文形式打印输出消息,主要用于调试任务。

在我想添加到我的规则中的 XACML 义务之下(以抽象符号编写):

  <xacml2:Obligations>
    <xacml2:Obligation FulfillOn="Permit" ObligationId="debug1">
      $myattr1 = AttributeId="http://red.com/subject/groupsUserBelong"
      <xacml2:AttributeAssignment AttributeId="debug1" DataType="http://www.w3.org/2001/XMLSchema#string">Attribute found: $myattr1</xacml2:AttributeAssignment>
    </xacml2:Obligation>
  </xacml2:Obligations>

更新的代码部分

您可以在下面找到一个示例,如何将文本消息与来自 PIP 查找的动态数据结合起来,通过 ObligationExpressions 生成输出:

   <Rule Effect="Deny" RuleId="Deny-Rule1">
      <Target></Target>
      <Condition>
         <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:not">
            <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-is-in">
               <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">myGroup</AttributeValue>
               <AttributeDesignator Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" AttributeId="http://red.com/subject/groupsUserBelong" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true"></AttributeDesignator>
            </Apply>
         </Apply>
      </Condition>
      <ObligationExpressions>
         <ObligationExpression FulfillOn="Deny" ObligationId="groupscheck">
            <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:3.0:example:attribute:text">
               <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Rule 1 - The groups validation error</AttributeValue>
            </AttributeAssignmentExpression>
         </ObligationExpression>
         <ObligationExpression ObligationId="debug1" FulfillOn="Deny"> 
            <AttributeAssignmentExpression AttributeId="debug1">
            <AttributeDesignator AttributeId="http://red.com/subject/groupsUserBelong" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> 
            </AttributeAssignmentExpression> 
         </ObligationExpression> 
      </ObligationExpressions>
   </Rule>

【问题讨论】:

    标签: authorization wso2is access-control xacml abac


    【解决方案1】:

    不,这在 WSO2 IS 和 XACML 2.0 中是不可能的。为此,您需要使用 XACML 3.0。 XACML 3.0 中添加了在义务中添加变量的功能(在 XACML 规范中称为属性赋值)。

    Axiomatics Policy Server 确实支持这一点。正如您所指出的,它是一个用于调试目的的简洁功能,但也适用于其他情况,例如

    • 拒绝用户向自己转账的权利 + 通知其经理的义务。

    在此示例中,义务将包含经理的电子邮件。这是一个使用 语法的示例。

        policy transferMoney{
            target clause actionId == "transfer"
            apply firstApplicable
            rule denySelfTransfer{
                condition requestor==recipient
                deny
                on deny {
                    obligation notifyManager{
                        message = "An employee tried to transfer money to themselves"
                        employee = employeeId
                        email = managerEmail
                    }
                }
            }
        }
    

    【讨论】:

    • 亲爱的@David Brossard,请检查上面描述的解决方案,它是在WSO2环境下测试的。它解决了问题。
    • 那是 XACML 3.0。您最初的示例是 XACML 2.0
    猜你喜欢
    • 1970-01-01
    • 2012-09-25
    • 2021-08-25
    • 1970-01-01
    • 1970-01-01
    • 2018-08-14
    • 1970-01-01
    • 1970-01-01
    • 2014-06-15
    相关资源
    最近更新 更多