From: Adam R. <ada...@de...> - 2007-06-13 10:33:01
|
Everything you have described can be done with just XQuery. Any particular reason for wanting to use XACML? Thanks adam. On Wed, 2007-06-13 at 12:56 +0530, Hemant Goyal wrote: > Hi, > > I thought I'd continue asking my queries related to eXist and XACML > within this thread only, for other people's benefit as well. > > I have figured out the basics of Xquery. > > What I really want to do now is: > > 1. Allow a person to log in to the system through a webpage. > 2. Then enforce Access Control using XACML based on attribute > values in the database. Considering an example : > 1. I have two roles doctor and patient. > 2. There is a field called doctor_refer_id for each > patient. > 3. The doctor can view the info of a particular patient > only if his ID is mentioned against the > doctor_refer_id in the patient's xml file > I read the documentation here > [http://exist.sourceforge.net/xacml-features.html], but could not > exactly figure out how to proceed with such a scenario. The > documentation talks about access control to Xquery modules. > > Is such a feature of retrieving attributes from XML documents and then > enforcing access to the information possible with the XACML feature? > > Also can anyone please explain what this means: > > 1.2. Intermediaries > There is no support yet for access control based on the route > taken to the resource. This type of control would allow, for > example, a user to use a library module library.xqm by running > query.xql but not through a query passed directly in the HTTP > request. > > > > Also any idea when the documentation here > [http://exist.sourceforge.net/xacml-dev.html#N1016B] will get > completed? > > Sorry for so many question :\ > > Thanks, > Hemant Goyal > > ------------------------------------------------------------------------- > This SF.net email is sponsored by DB2 Express > Download DB2 Express C - the FREE version of DB2 express and take > control of your XML. No limits. Just data. Click to get it now. > http://sourceforge.net/powerbar/db2/ > _______________________________________________ Exist-open mailing list Exi...@li... https://lists.sourceforge.net/lists/listinfo/exist-open -- Adam Retter Principal Developer Devon Portal Project Room 310 County Hall Topsham Road Exeter EX2 4QD t: 01392 38 3683 f: 01392 38 2966 e: ada...@de... w: www.devonline.gov.uk |