W3C home > Mailing lists > Public > public-ws-addressing@w3.org > December 2004

xml:id and opacity of refp's

From: Rich Salz <rsalz@datapower.com>
Date: Tue, 21 Dec 2004 19:15:49 -0500 (EST)
To: public-ws-addressing@w3.org
Message-ID: <Pine.LNX.4.44L0.0412211858520.27892-100000@smtp.datapower.com>

Dims posted a message ("just thinking out loud here...") that included a
snippet of an EPR with a DSIG in it.  It just brought to mind an issue.

One of XML's validity constraints is that attributes of type ID have
unique values.  In order to not generate invalid XML, a program that uses
the refp's from an EPR must scan them to make sure that the ID attributes
that *it* generates are unique.  This violates opacity, but without that
violation a client cannot be sure of generating valid messages.

Further, while xml:id is useful, there are still many ID attributes in
other namespaces.  This requires even deeper knowledge and inspection
by the EPR recipient, further ripping away opacity.  It's a hard problem,
of course, since there is no guarantee that the EPR recipient will even
*know* what the ID attributes are inside a refp.

Short of probabilistic values for ID attributes (viz., MIME separators for
multipart), opacity must be broken.
Rich Salz                  Chief Security Architect
DataPower Technology       http://www.datapower.com
XS40 XML Security Gateway  http://www.datapower.com/products/xs40.html
XML Security Overview      http://www.datapower.com/xmldev/xmlsecurity.html
Received on Wednesday, 22 December 2004 00:15:52 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 19:28:22 UTC