Policy framework (was: [Policy] [ACTION-152] Editor Updates to Policy Requirements and Policy Framework)

Le jeudi 08 avril 2010 à 18:58 +0200, Arribas, Laura, VF-Group a écrit :
> Please have a look at the current *draft* [1] and share any comments you may
> have.

I took a pass the fixing the examples in section 5 [2] to make them XML
well-formed (although there is an XML namespace prefix used in the
example and in the spec, "param:", for which I couldn't find an
associated namespace declaration).

I'm not very comfortable with the very large scope of that document; it
defines:
* a rules language (derived from but not exactly the same as XACML),
* an identity model,
* an environment model,
* a capabilities model,
* a policy-decision model,
each of which could be a spec of its own, requiring a non-negligible
amount of work.

I've tried to look at the reference implementation of the policy
framework in BONDI to get an idea of the work needed to implement all of
this, but have failed to find it so far; could someone point me to it?

(at a purely editorial level, I'm hoping we're not going to call this
the "DAP security" model/framework — I think this comes from a global
replace of "BONDI" with "DAP" in the submitted document, but I don't
think this works well as a name)

Thanks,

Dom

> [1] http://dev.w3.org/2009/dap/policy/Overview.html
2.
http://dev.w3.org/2009/dap/policy/Overview.html#example-abuse-policies

Received on Tuesday, 13 April 2010 15:14:52 UTC