WebAC authorization Fedora module is an implementation of the still evolving draft by the W3C that proposes a decentralized authorization mechanism. See WebAccessControl specifications at the W3C website.
W3C's definition of WebAccessControl
WebAccessControl is a decentralized system for allowing different users and groups various forms of access to resources where users and groups are identified by HTTP URIs.
The WebAC module will enforce access control based on the Access Control List (ACL) RDF resource associated with the requested resource. In WebAC, an Access Control List (ACL) consists of a set of Authorizations. An Authorization is a single rule for access, such as "users alice and bob may write to resource foo", described with a set of RDF properties. Authorizations have the RDF type http://www.w3.org/ns/auth/acl#Authorization (for the remainder of this document, the http://www.w3.org/ns/auth/acl# namespace will be abbreviated with the prefix acl:).
The properties that may be used on an acl:Authorization are:
Property
Meaning
acl:accessTo
the URI of the protected resource
acl:agent
the user
acl:mode
the type of access (WebAC defines several modes: acl:Read, acl:Write, acl:Append, and acl:Control)
acl:accessToClass
an RDF class of protected resources (N.B., not implemented in the first version of this module)
acl:agentClass
an RDF class of users (N.B., not implemented in the first version of this module)
In Fedora 4, an ACL is a ldp::BasicContainer resource with the additional RDF type of http://fedora.info/definitions/v4/webac#Acl. This class is part of the Fedora WebAC ontology. Its children should each be resources of type acl:Authorization.
Protecting Resources
A resource specifies the location of its ACL using the acl:accessControl property. If a resource itself does not specify an ACL, its parent containers are inspected, and the first specified ACL found is used as the ACL for the requested resource. If no ACLs are found, the default policy is to deny access to the requested resource.
Steps in determining the effective authorization
Finding the ACL:
Get the ACL of the requested resource, if exists, else.
Get the ACL of the next ancestor recursively (using either ldp:contains or fedora:hasParent), if exists, else.
If no more ancestor exist (root node reached) and no ACL is found: Deny access.
Finding the effective authorization:
Find union of authorizations that specify access for the requesting user. This includes:
authorizations that specify accessTo to the requested resource.
authorizations that specify accessToClass of the requested resource type.
If authorizations exist for user, go to step 6, else go to next step.
Find union of authorizations that specify access for the requesting user's group. This includes:
authorizations that specify accessTo to the requested resource.
authorizations that specify accessToClass of the requested resource type.
If authorizations exist for group, go to step 6, else go to next step.
Find union of authorizations that specify access for the requesting user. This includes:
authorizations that specify accessToto the requested resource's ancestor.
authorizations that specify accessToClass of to the requested resource's ancestor type.
If authorizations exist for user, go to step 6, else go to next step.
Find union of authorizations that specify access for the requesting user's group. This includes:
authorizations that specify accessTo to the requested resource's ancestor.
authorizations that specify accessToClass ofto the requested resource's ancestor type.
If authorizations exist for group, go to step 6, else go to next step.
If no authorization exists for user or group: Deny Access.
Use the most permissive from the set of authorizations found.
if the authorizations permit requested access mode: Grant access.
if the authorizations do not permit requested access mode: Deny access.
Example Request Authorization Flow
Gliffy Macro Error
An error occurred while rendering this diagram. Please contact your administrator.
Only the ex:publicImage type objects in the container http://localhost:8080/rest/mixedCollection are viewable by anyone, all others are only viewable by the group Admins.
Using the three "files" below to create our Authorization and ACL resources.
Acl.ttl
@prefix webac: <http://fedora.info/definitions/v4/webac#> .
<> a webac:Acl .