Change-Id: Id307fdc04ba7a74c9e81650c7b4ba272405cf6df Former-commit-id: 81d0249971d4004067b6aef672e00417ddb83b36
94 lines
4 KiB
XML
94 lines
4 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<PolicySet xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os"
|
|
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
|
xsi:schemaLocation="urn:oasis:names:tc:xacml:2.0:policy:schema:os
|
|
access_control-xacml-2.0-policy-schema-os.xsd"
|
|
PolicySetId="urn:oasis:names:tc:xacml:2.0:data-delivery:default-policySet"
|
|
PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:deny-overrides">
|
|
<Description>
|
|
Default access control policy set for accessing registry objects
|
|
</Description>
|
|
<Target />
|
|
|
|
<Policy xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os"
|
|
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
|
xsi:schemaLocation="urn:oasis:names:tc:xacml:2.0:policy:schema:os
|
|
access_control-xacml-2.0-policy-schema-os.xsd"
|
|
PolicyId="urn:oasis:names:tc:xacml:2.0:data-delivery:default-acp"
|
|
RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:deny-overrides">
|
|
<Description>
|
|
Default access control policy for accessing registry
|
|
objects
|
|
</Description>
|
|
<Target>
|
|
<Actions>
|
|
<Action>
|
|
<ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
|
|
<AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">create</AttributeValue>
|
|
<ActionAttributeDesignator
|
|
AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
|
|
DataType="http://www.w3.org/2001/XMLSchema#string" />
|
|
</ActionMatch>
|
|
</Action>
|
|
<Action>
|
|
<ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
|
|
<AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">read</AttributeValue>
|
|
<ActionAttributeDesignator
|
|
AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
|
|
DataType="http://www.w3.org/2001/XMLSchema#string" />
|
|
</ActionMatch>
|
|
</Action>
|
|
<Action>
|
|
<ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
|
|
<AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">update</AttributeValue>
|
|
<ActionAttributeDesignator
|
|
AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
|
|
DataType="http://www.w3.org/2001/XMLSchema#string" />
|
|
</ActionMatch>
|
|
</Action>
|
|
<Action>
|
|
<ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
|
|
<AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">delete</AttributeValue>
|
|
<ActionAttributeDesignator
|
|
AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
|
|
DataType="http://www.w3.org/2001/XMLSchema#string" />
|
|
</ActionMatch>
|
|
</Action>
|
|
<Action>
|
|
<ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
|
|
<AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">execute</AttributeValue>
|
|
<ActionAttributeDesignator
|
|
AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
|
|
DataType="http://www.w3.org/2001/XMLSchema#string" />
|
|
</ActionMatch>
|
|
</Action>
|
|
<Action>
|
|
<ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
|
|
<AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">GET</AttributeValue>
|
|
<ActionAttributeDesignator
|
|
AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
|
|
DataType="http://www.w3.org/2001/XMLSchema#string" />
|
|
</ActionMatch>
|
|
</Action>
|
|
<Action>
|
|
<ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
|
|
<AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">POST</AttributeValue>
|
|
<ActionAttributeDesignator
|
|
AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
|
|
DataType="http://www.w3.org/2001/XMLSchema#string" />
|
|
</ActionMatch>
|
|
</Action>
|
|
</Actions>
|
|
</Target>
|
|
<Rule RuleId="urn:oasis:names:tc:xacml:2.0:data-delivery:default-noop-rule"
|
|
Effect="Permit">
|
|
<Description>
|
|
Default access control policy for accessing registry
|
|
objects
|
|
</Description>
|
|
<Target/>
|
|
|
|
</Rule>
|
|
</Policy>
|
|
</PolicySet>
|
|
|