【问题标题】:Authoring XACML 3.0 obligations with the ALFA plugin for Eclipse使用 Eclipse 的 ALFA 插件编写 XACML 3.0 义务
【发布时间】:2014-09-25 15:47:28
【问题描述】:

我有一个XACML 请求,其中包含两个(resource:type) 属性和一个(resource:id) 属性:

    <Request xmlns="urn:oasis:names:tc:xacml:2.0:context:schema:os" >  
    <Resource>
        <Attribute AttributeId="resource:type" DataType="http://www.w3.org/2001/XMLSchema#string">
            <AttributeValue>status</AttributeValue>
        </Attribute>  
        <Attribute AttributeId="resource:type" DataType="http://www.w3.org/2001/XMLSchema#string">
            <AttributeValue>pressure</AttributeValue>
        </Attribute>  
        <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:resource:resource-id" DataType="http://www.w3.org/2001/XMLSchema#string">  
            <AttributeValue>status:of:nariman</AttributeValue>
        </Attribute>
    </Resource>  
    <Subject>
        <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id" DataType="http://www.w3.org/2001/XMLSchema#string">
            <AttributeValue>1111</AttributeValue> 
        </Attribute>
    </Subject>  
    <Action>
        <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id">
            <AttributeValue>view</AttributeValue>
        </Attribute>
    </Action>
</Request>  

我想用三个对应于上述每个资源属性的义务表达式来定义一个义务。我如何使用ALFA 做到这一点?

【问题讨论】:

  • 只是一个澄清。我想稍后通过读取每个赋值表达式中的值并执行进一步的逻辑(在 PEP 级别编写)来处理我的代码义务。

标签: authorization access-control xacml xacml3 alfa


【解决方案1】:

首先,请注意您的 XACML 请求实际上是一个 XACML 2.0 请求,而 ALFA 输出一组 XACML 3.0 策略。所以你会有一个版本不匹配。

其次,在 ALFA 中建立一个包含您的两个属性的义务,您将执行以下操作:

namespace stackoverflow{

    attribute subjectId{
        category = subjectCat
        id = "urn:oasis:names:tc:xacml:1.0:subject:subject-id"
        type = string
    }

    attribute resourceId{
        category = resourceCat
        id = "urn:oasis:names:tc:xacml:1.0:resource:resource-id"
        type = string

    }

    attribute resourceType{
        category = resourceCat
        id = "resource:type"
        type = string

    }

    attribute actionId{
        category = actionCat
        id = "urn:oasis:names:tc:xacml:1.0:action:action-id"
        type = string
    }

    obligation displayAttributes = "obligation.displayAttributes"

    policy example{
        apply firstApplicable
        rule example{
            permit
            on permit{
                obligation displayAttributes{
                    subjectId = subjectId
                    resourceId = resourceId
                    resourceType = resourceType
                    actionId = actionId
                }
            }
        }
    }
}

附带说明,您的 XACML 请求似乎存在语义错误。什么是英语等价物?现在你在问:

用户 1111 能否对 status 或 pressure 执行操作 view id 为 status:of:nariman 的资源?

您通常希望先要求压力,然后再单独或作为多个要求要求状态。

【讨论】:

  • 谢谢。实际上,我故意在一个请求中需要多个资源:类型属性。为了给这个问题提供更多的背景信息,我(作为一个主题)想提交一个查询,询问一个在这种情况下是 nariman 的患者的多个属性(状态、压力)。我有一个数据库模式,将 nariman 与她的属性以一对多的关系联系起来。
  • 那么在上面的例子中,这行:resourceType=resourceType 是否处理了所有的资源类型属性?还是我们需要为每个添加单独的赋值表达式?
  • 它处理所有的值。原因是默认情况下 XACML 中的所有属性实际上都是值包。
猜你喜欢
  • 2014-12-03
  • 2017-11-20
  • 2018-11-02
  • 1970-01-01
  • 1970-01-01
  • 2014-04-19
  • 1970-01-01
  • 2012-09-25
  • 1970-01-01
相关资源
最近更新 更多