RE: Security Question

It's interesting to see what SOAP 1.2 says in this area. Section 1.2
addresses the relationship with XML Schema, and explicitly says that
evaluation of the Post Schema Validation Infoset is not required for filling
out default and fixed values. BUT that only applies to items belonging to
the SOAP 1.2 namespace, so that PSVI could be required for items belonging
to other application specific namespaces included in the SOAP envelope.

By the way, the latest decision of the WS-I Basic Profile in this area is to
require PSVI evaluation on the receiving side. (But it is still rather
controversial within the working group).


-----Original Message-----
From: Mark Baker []
Sent: Tuesday, August 06, 2002 7:04 AM
To: Cutler, Roger (RogerCutler)
Subject: Re: Security Question

On Mon, Aug 05, 2002 at 12:17:18PM -0700, Cutler, Roger (RogerCutler) wrote:
> I think my example was not a good one.  Basically, I am concerned that
> schema validation may add to the data in an XML document and thus that
> are two linked "things" -- so how is that linkage made reliable?

IMO, making the meaning of a message depend on something external to a
message is a bad idea for lots of reasons.

FWIW, I contributed this to the ietf-xml-use work;

4.13 External References

   When using XML in the context of a stateless protocol, be it the
   protocol itself (e.g., SOAP), or simply as content transferred by an
   existing protocol (e.g., XML/HTTP), care must be taken to not make
   the meaning of a message depend on information outside the message
   itself.  XML provides external entities (see Section 4.12), which are
   an easy way to make the meaning of a message depend on something
   external.  Using schema languages that can change the Infoset, like
   XML Schema, is another way.


So my answer would be; don't do that. 8-)

Mark Baker, CTO, Idokorro Mobile (formerly Planetfred)
Ottawa, Ontario, CANADA.     

Received on Tuesday, 6 August 2002 13:47:22 UTC