| <?xml version="1.0" encoding="UTF-8"?> |
| <!-- |
| Licensed to the Apache Software Foundation (ASF) under one or more |
| contributor license agreements. See the NOTICE file distributed with |
| this work for additional information regarding copyright ownership. |
| The ASF licenses this file to You under the Apache License, Version 2.0 |
| (the "License"); you may not use this file except in compliance with |
| the License. You may obtain a copy of the License at |
| |
| http://www.apache.org/licenses/LICENSE-2.0 |
| |
| Unless required by applicable law or agreed to in writing, software |
| distributed under the License is distributed on an "AS IS" BASIS, |
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| See the License for the specific language governing permissions and |
| limitations under the License. |
| --> |
| <Policy xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" |
| PolicyId="urn:oasis:names:tc:xacml:2.0:testapi:policy" |
| RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-overrides" Version="1.0" |
| xsi:schemaLocation=""> |
| <Description></Description> |
| <Target/> |
| <Rule RuleId="urn:oasis:names:tc:xacml:1.0:testapi:rule-1" Effect="Permit"> |
| <Description> |
| Julius Hibbert can read or write Bart Simpson's medical record. |
| </Description> |
| <Target> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Julius Hibbert</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" |
| AttributeId="my-namespace:subject-id" |
| DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">http://medico.com/record/patient/BartSimpson</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" |
| AttributeId="my-namespace:resource-id" |
| DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">read</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:attribute-category:action" |
| AttributeId="my-namespace:action-id" |
| DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">write</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:attribute-category:action" |
| AttributeId="my-namespace:action-id" |
| DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| </Target> |
| </Rule> |
| <Rule RuleId="urn:oasis:names:tc:xacml:1.0:testapi:rule-2" Effect="Permit"> |
| <Description /> |
| <Target> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Bob</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" |
| AttributeId="my-namespace:subject-id" |
| DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:anyURI-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#anyURI">/record/patient/Alice</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" |
| AttributeId="my-namespace:resource-id" |
| DataType="http://www.w3.org/2001/XMLSchema#anyURI" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:anyURI-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#anyURI">http://medical-records.com/</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:attribute-category:resource" |
| AttributeId="my-namespace:resource-location" |
| DataType="http://www.w3.org/2001/XMLSchema#anyURI" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| <AnyOf> |
| <AllOf> |
| <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> |
| <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">read</AttributeValue> |
| <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:attribute-category:action" |
| AttributeId="my-namespace:action-id" |
| DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="false"/> |
| </Match> |
| </AllOf> |
| </AnyOf> |
| </Target> |
| </Rule> |
| </Policy> |