| <?xml version="1.0" encoding="UTF-8"?> |
| <!-- |
| Licensed to the Apache Software Foundation (ASF) under one or more |
| contributor license agreements. See the NOTICE file distributed with |
| this work for additional information regarding copyright ownership. |
| The ASF licenses this file to You under the Apache License, Version 2.0 |
| (the "License"); you may not use this file except in compliance with |
| the License. You may obtain a copy of the License at |
| |
| http://www.apache.org/licenses/LICENSE-2.0 |
| |
| Unless required by applicable law or agreed to in writing, software |
| distributed under the License is distributed on an "AS IS" BASIS, |
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| See the License for the specific language governing permissions and |
| limitations under the License. |
| --> |
| |
| <?xml version="1.0" encoding="UTF-8" standalone="no"?> |
| <PolicySet xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:first-applicable" PolicySetId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset" Version="1.0" xsi:schemaLocation="urn:oasis:names:tc:xacml:3.0:policy:schema:os access_control-xacml-2.0-policy-schema-os.xsd"> |
| <Description> |
| Policy for Conformance Test IIIA023. |
| Purpose: test Obligations on Policies, Case: NotApplicable: PolicyCombiningAlgorithm FirstApplicable |
| </Description> |
| <Target/> |
| <Policy PolicyId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1" RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:first-applicable" Version="1.0"> |
| <Description> |
| Policy1 for Conformance Test IIIA023. |
| </Description> |
| <Target/> |
| <Rule Effect="Deny" RuleId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:rule1"> |
| <Description> |
| A subject whose name is J. Hibbert may not |
| read Bart Simpson's medical record. NOTAPPLICABLE |
| </Description> |
| <Target> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">J. Hibbert</AttributeValue> |
| <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| </Target> |
| </Rule> |
| <ObligationExpressions> |
| <ObligationExpression FulfillOn="Permit" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:obligation-1"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Permit" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:obligation-2"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Deny" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:obligation-3"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Deny" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:obligation-4"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy1:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| </ObligationExpressions> |
| </Policy> |
| <Policy PolicyId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2" RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:first-applicable" Version="1.0"> |
| <Description> |
| Policy2 for Conformance Test IIIA023. |
| </Description> |
| <Target/> |
| <Rule Effect="Permit" RuleId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:rule2"> |
| <Description> |
| A subject who is at least 55 years older than Bart |
| Simpson may read Bart Simpson's medical record. NOT-APPLICABLE. |
| </Description> |
| <Condition> |
| <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:integer-greater-than-or-equal"> |
| <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:integer-subtract"> |
| <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:integer-one-and-only"> |
| <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:age" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" DataType="http://www.w3.org/2001/XMLSchema#integer" MustBePresent="false"/> |
| </Apply> |
| <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:integer-one-and-only"> |
| <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:bart-simpson-age" Category="urn:oasis:names:tc:xacml:3.0:attribute-category:environment" DataType="http://www.w3.org/2001/XMLSchema#integer" MustBePresent="false"/> |
| </Apply> |
| </Apply> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#integer">55</AttributeValue> |
| </Apply> |
| </Condition> |
| </Rule> |
| <ObligationExpressions> |
| <ObligationExpression FulfillOn="Permit" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:obligation-1"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Permit" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:obligation-2"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Deny" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:obligation-3"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Deny" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:obligation-4"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policy2:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| </ObligationExpressions> |
| </Policy> |
| <ObligationExpressions> |
| <ObligationExpression FulfillOn="Permit" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:obligation-1"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Permit" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:obligation-2"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Deny" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:obligation-3"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| <ObligationExpression FulfillOn="Deny" ObligationId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:obligation-4"> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment1"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment1</AttributeValue> |
| </AttributeAssignmentExpression> |
| <AttributeAssignmentExpression AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIIA023:policyset:assignment2"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">assignment2</AttributeValue> |
| </AttributeAssignmentExpression> |
| </ObligationExpression> |
| </ObligationExpressions> |
| </PolicySet> |