code review planning
Rod Widdowson
rdw at steadingsoftware.com
Fri Jun 21 09:19:21 EDT 2013
> Hmm. It's schema valid, but I don't believe it's meant to be semantically
> valid. If you use that rule as a policy matcher, you need to specify
> attributeId. That's the intent anyway, and it's what the SP does, and I
> thought the current IdP code did.
As I recall, the current IdP is pretty much broken when "AttributeValue"
Matchers are fired into PolicyRequirementRules. Possibly the inverse is
true as well (so my first, weird, but meaningful example is broken too), I
cannot remember the details right now.
In V3 I followed the basic rule throughout that "If it's true for any
attribute its true". It is meaningless (but consistent) in this case, ISTR
that there are other cases when it makes more sense.
R
More information about the dev
mailing list