RE: XACML TC Charter Revision - Strawman
On the whole I agree with you, but I would argue that SAML shouldn't make
any assumptions about the policy space. To the extent that SAML may or may
not be assuming a (Subject X Object X Resource X Action) policy space it is
assuming some aspects of the authorization model.
This is something I got into for a bit when the XACML effort was being
proposed. I think the first and most important issue that we have to resolve
is: "Is it possible to define a language/schema for expressing authorization
policy without also defining an authorization model?". I would say the
answer is "no", but I think others would disagree with me.
I think we need to 'fess up to the fact that we are going to end up (one way
or another) defining an authorization model. I know that, in the past, many
good efforts have crashed on the rocks of a "common authorization model",
but I just can't see how we can define a language for expressing policies
outside of some framework for interpreting that language (Someone once asked
me to analyze the performance characteristics of a body of C code
"irrespective of the target architecture". Being young and foolish, I worked
on the problem for 2 or 3 days before I realized it was a meaningless
question.)
I think the best way to proceed is to first agree on our Use Cases, and then
define a minimally constraining authorization model that meets the needs of
those Use Cases. From there we can work on the specifics of the policy
language . . .
×
New Best Answer
This thread already has a best answer. Would you like to mark this message as the new best answer?
No
$(document).ready(function () {
$("div.messageContentColumn").find("img.media-object").on('click', function () {
if ($(this)[0].parentElement.tagName !== "A") {
var $messageContentColumn = $(this);
var source = "";
if ($messageContentColumn.data("modalsrc") !== undefined) {
source = $messageContentColumn.data("modalsrc")
} else {
source = $messageContentColumn.attr("src").replace("-T.jpg", ".jpg");
source = source.replace("-M.jpg", ".jpg");
source = source.replace("-L.jpg", ".jpg");
}
var title = $messageContentColumn.data('title') !== undefined
? $messageContentColumn.data("title")
: $messageContentColumn.attr("title") !== undefined
? $messageContentColumn.attr("title")
: "";
var $discussionImgModal = $("#discussion-img-modal");
var modalHtml = '
×' +
'
';
if ($discussionImgModal.length == 0) {
$("form").append(modalHtml);
$discussionImgModal = $("#discussion-img-modal");
$discussionImgModal.find(".close").on('click', function () {
$discussionImgModal.modal("hide");
});
}
loadImage($discussionImgModal, source, title);
}
});
function loadImage($discussionImgModal, source, title) {
var discussionImg = $discussionImgModal.find("#modalImg")[0];
discussionImg.onload = function () {
$discussionImgModal.modal("show");
};
discussionImg.src = source;
$discussionImgModal.find("#caption").html(title);
}
var replyInlineParam = HigherLogic.Util.getParameterByName('ReplyInline');
if (!HigherLogic.Util.stringIsNullOrWhiteSpace(replyInlineParam)) {
var $replyInline = $('.reply-inline[data-message-key="' + replyInlineParam + '"]');
if ($replyInline.length > 0) {
openEditor($replyInline);
}
}
$('.reply-inline').on('click',
function () {
hl_common_ui_blockUI();
var $this = $(this);
if ($('.inline-reply-snippet').length > 0) {
hl_common_ui_unBlockUI();
$('.inline-reply-snippet').find('.modal.inline-confirm').modal('show');
$('.inline-reply-snippet').find('.modal.inline-confirm').data('reply-id', $this.prop('id'));
} else {
openEditor($this);
}
});
function openEditor($this) {
$('.inline-reply-snippet').remove();
var postData = { MessageKey: $this.data('message-key'), currentUrl: window.location.href };
HigherLogic.Util.post(
'/higherlogic/ui/mvc/eGroups/eGroups/GetReplyInline',
JSON.stringify(postData),
'html'
).done(function (data) {
var redirectUrl = $(data).data('redirect-url');
if (redirectUrl) {
// gives return location for unauthenticated user redirect to login
redirectUrl = hl_common_util_updateQueryStringParameter(redirectUrl,
'ReturnUrl',
encodeURIComponent(window.location.href));
// gives return location for unsubscribed user redirect to subscribe
window.location.href = hl_common_util_updateQueryStringParameter(redirectUrl,
'PostByLink',
encodeURIComponent(window.location.href));
return;
}
$this.closest('li').append(data);
var $div = $('#' + $(data).first('div').prop('id'));
var bottomOfDiv = $div.offset().top + 500;
$('html, body').animate({
scrollTop: bottomOfDiv - $(window).height()
},
1000);
hl_common_ui_unBlockUI();
});
}
});
.related-results.block {
display: flex;
flex-wrap: wrap;
flex-direction: row;
}
.related-results.block .related-result-row {
flex: 1;
border: 1px solid #cccccc;
margin: 10px;
min-width: 200px;
max-width: 200px;
}
.related-results.block .related-result-row .meta-content-date.block {
float: left;
margin: 0px;
}
.related-results.block .related-result-row .hl-type.block {
margin-top: 5px;
margin-right: 0px;
padding-left: 0px;
margin-bottom: 10px;
text-align: center;
clear: both;
}
.related-results .related-result-row h4 {
margin-bottom: 10px;
}
.related-results .related-result-row .meta-content-date {
color: #666666;
font-size: 12px;
margin: 0px 20px 3px;
display: block;
float: right;
}
.related-results .related-result-row .meta-block {
border-left: 1px solid #ebebeb;
padding-left: 15px;
margin-top: 20px;
font-size: 12px;
}
.related-results .related-result-row .meta-block a {
color: #666;
}
.related-results .related-result-row .meta-content {
margin: 3px 0;
}
.related-results .related-result-row .img-circle {
border-radius: 50%;
width: 20px;
}
.related-results .related-result-row .owner-image {
width: 20px;
float: left;
}
.related-results .related-result-row .owner-name {
color: #666666;
font-size: 12px;
display: block;
float: left;
margin: 2px 5px;
}
.related-results .related-result-row .content-type {
padding-bottom: 5px;
padding-top: 5px;
color: #006621;
font-size: 12px;
font-weight: bold;
}
.related-results .related-result-row .content-tags {
margin-bottom: 5px;
margin-top: 10px;
}
.related-results .related-result-row .content-tags a {
margin-bottom: 10px;
}
.related-results .related-result-row .content-tags a {
display: inline-block;
}
.related-results .related-result-row .match-block {
color: #808080;
}
.related-results .related-result-row .result-indent {
padding-left: 15px;
}
.related-results .related-result-row p.result-indent-event {
padding-left: 15px;
margin-top: 0;
margin-bottom: 0;
color: #333333;
}
.related-results .related-result-row .label-search-tag {
background-color: #fff;
border: 1px solid #ccc;
text-decoration: none;
margin-bottom: 4px;
color: #333;
font-weight: normal;
}
.related-results .related-result-row .label-search-tag:hover {
background-color: #ebebeb;
border: 1px solid #ccc;
margin-bottom: 4px;
color: #333;
font-weight: normal;
text-decoration: none;
}
.related-results .related-results.search-divider hr {
width: 100%;
margin-top: 5px;
margin-bottom: 10px;
border: 1px solid #eeeeee;
}
.related-results .row.search-divider {
margin-left: 0;
margin-right: 0;
}
.related-results .related-result-row .hl-type .label, .hl-type-alt-2.label {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row .hl-type {
padding-bottom: 0px;
padding-left: 8px;
margin-top: -6px;
margin-right: 20px;
}
.related-results .related-result-row .hl-type-alt .label, .hl-type-alt-2 {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row a {
text-decoration: none;
}
.related-results .related-result-row a:hover {
text-decoration: underline;
}
.related-results .related-result-row a.focus-search {
font-weight: normal;
text-decoration: underline;
}
.related-results .related-result-row a.focus-search:hover {
font-weight: normal;
text-decoration: none;
}
.related-results .related-result-row .focus-search {
color: #666;
}
/*========== Non-Mobile First Method ==========*/
/* Large Devices, Wide Screens */
@media only screen and (max-width : 1200px) {
}
/* Medium Devices, Desktops */
@media only screen and (max-width : 992px) {
}
/* Small Devices, Tablets */
@media only screen and (max-width : 768px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
}
/* Extra Small Devices, Phones */
@media only screen and (max-width : 480px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
.related-results .pull-right.hl-type {
float: none !important;
margin-top: 0;
padding-bottom: 15px;
padding-left: 0;
text-align: left;
}
}
/* Custom, iPhone Retina */
@media only screen and (max-width : 320px) {
}
Related Content
Re: [ubl-ndrsc] Defining the logical model
Tim McGrath
Added 01-23-2004
Discussion Thread
1
26. Define policy reduction (partial evaluation) of a policy
Anne Anderson
Added 10-27-2003
Discussion Thread
1
Define consistent approach to Tuples and SIngletons Language-compatible Profiles
Toby Considine
Added 11-14-2018
Discussion Thread
1
defining terms -- microgrid
Anne Hendry
Added 03-19-2010
Discussion Thread
7
Fw: Defining topics
Michael Priestley
Added 11-24-2005
Discussion Thread
1
Contact Us
OASIS Open
400 TradeCenter, Suite 5900
Woburn, MA 01801
USA
Phone
+1 781 425 5073
Membership
Get Involved
Join an Open Project
Join a Technical Committee
Privacy & Terms
About Us
Privacy