Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

IDDataTypeSourceIn Request?Notes
urn:oasis:names:tc:xacml:1.0:subject:subject-idstringuser principalYes 
urn:oasis:names:tc:xacml:1.0:subject:subject-id-qualifierstringTBD name-space for the subject-id
urn:oasis:names:tc:xacml:1.0:subject:request-time AuthZ delegateYestime when this action was requested
urn:oasis:names:tc:xacml:1.0:subject:session-start-time ModeShape sessionYestime when Fedora transaction began
urn:oasis:names:tc:xacml:2.0:subject:groupstringall principals except userYesextensible via Principal Factory
urn:oasis:names:tc:xacml:2.0:subject:rolestringeffective access rolesYesFedora access roles for this user/group†
urn:oasis:names:tc:xacml:1.0:subject:authn-locality:authentication-methodstringTBDYeswhat style of AuthN? (OAuth/Tomcat/Shibboleth)
urn:oasis:names:tc:xacml:1.0:subject:authn-locality:ip-addressstringTBDYesservlet request ip or X-forward headeraddress of authenticating agent:
  • OAuth authorization server
  • SSO server
  • fedora server (tomcat users)
urn:oasis:names:tc:xacml:1.0:subject:authn-locality:dns-namestringTBDYes??See above description of ip-address.

† Hydra rights metadata may be dynamically crosswalked to Fedora roles via a sequencer.

...