jabed morshed
jabed morshed

Reputation: 19

XACML Policy for dynamic attributes

I want that if the requester and the policy owner are in the same room (here location is dynamic attribute) then the requester will get the access to the resource. How can I write it in XACML policy?

Upvotes: 2

Views: 296

Answers (1)

David Brossard
David Brossard

Reputation: 13834

What you want to do can be implemented using a XACML condition.

The Axiomatics Question of the Week series has an article on this topic which you can read here.

With a condition you can implement a relationship. The relationship, in your case, will compare the requester's location and the policy owner's location.

In ALFA, your policy might look like the following:

policy allow{
    apply firstApplicable
    rule allow{
        permit
        condition requesterLocation == policyOwnerLocation
    }
}  

This generates the following XML:

<?xml version="1.0" encoding="UTF-8"?>
 <!--This file was generated by the ALFA Plugin for Eclipse from Axiomatics AB (http://www.axiomatics.com). 
 Any modification to this file will be lost upon recompilation of the source ALFA file-->
<xacml3:Policy xmlns:xacml3="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17"
    PolicyId="http://axiomatics.com/alfa/identifier/example.allow"
    RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:first-applicable"
    Version="1.0">
    <xacml3:Description />
    <xacml3:PolicyDefaults>
        <xacml3:XPathVersion>http://www.w3.org/TR/1999/REC-xpath-19991116</xacml3:XPathVersion>
    </xacml3:PolicyDefaults>
    <xacml3:Target />
    <xacml3:Rule 
            Effect="Permit"
            RuleId="http://axiomatics.com/alfa/identifier/example.allow.allow">
        <xacml3:Description />
        <xacml3:Target />
        <xacml3:Condition>
            <xacml3:Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:any-of-any">
                <xacml3:Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal"/>
                <xacml3:AttributeDesignator 
                    AttributeId="com.axiomatics.example.requesterLocation"
                    DataType="http://www.w3.org/2001/XMLSchema#string"
                    Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"
                    MustBePresent="false"
                />
                <xacml3:AttributeDesignator 
                    AttributeId="com.axiomatics.example.policyOwnerLocation"
                    DataType="http://www.w3.org/2001/XMLSchema#string"
                    Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource"
                    MustBePresent="false"
                />
            </xacml3:Apply>
        </xacml3:Condition>
    </xacml3:Rule>
</xacml3:Policy>

Upvotes: 1

Related Questions