You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从ABAC中的XACML策略获取匹配属性数与总检查属性数?

在AuthzForce的XACML策略中添加属性匹配统计返回

我是XACML和ABAC的初学者,已经在本地AuthzForce服务器部署了一份XACML策略,通过Postman测试请求可以正常运行。现在我想修改这个策略,让它除了返回Permit或Deny结果外,还能返回匹配的属性总数以及检查的属性总数(比如3个检查属性里有2个匹配,要在响应里拿到数值‘2’和‘3’)。请问能不能修改下面的策略?

原策略

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<PolicySet
xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17"
PolicySetId="root"
Version="0.1.37"
PolicyCombiningAlgId="urn:oasis:names:tc:xacml:3.0:policy-combining-algorithm:deny-unless-permit">
<Description>PolicySet for XACML model</Description>

<Target />

<Policy
PolicyId="EngineeringAppAccessPolicy"
Version="1.0"
RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-unless-permit">

<Description>Policy for controlling access to EngineeringApp by verifying attributes</Description>

<!-- Target specifies this policy applies to the resource "EngineeringApp" -->
<Target>
<AnyOf>
    <AllOf>
    <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
    <AttributeValue
    DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue>
    <AttributeDesignator
    Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource"
    AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id"
    DataType="http://www.w3.org/2001/XMLSchema#string"
    MustBePresent="true" />
    </Match>
    </AllOf>
</AnyOf>
</Target>

<!-- Rule specifies conditions for access -->
<Rule RuleId="AttributeBasedAccessRule" Effect="Permit">
<Description>Permit access to EngineeringApp if user role is Engineer and action is access</Description>

<Target>
    <AnyOf>
    <AllOf>
    <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
    <AttributeValue
        DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue>
    <AttributeDesignator
        Category="urn:oasis:names:tc:xacml:3.0:action-category:action"
        AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
        DataType="http://www.w3.org/2001/XMLSchema#string"
        MustBePresent="true" />
    </Match>
    </AllOf>
    </AnyOf>
</Target>

<!-- Condition verifies the user role -->
<Condition>
    <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:any-of">
    <Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal" />
    <AttributeValue
    DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue>
    <AttributeDesignator
    AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role"
    DataType="http://www.w3.org/2001/XMLSchema#string"
    MustBePresent="true"
    Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" />
    </Apply>
</Condition>
</Rule>

</Policy>
</PolicySet>

当前测试请求

<?xml version="1.0" encoding="UTF-8"?>
<Request xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" ReturnPolicyIdList="true" CombinedDecision="false">
<Attributes Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject">
    <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" IncludeInResult="false">
    <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue>
    </Attribute>
</Attributes>
<Attributes Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource">
    <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id" IncludeInResult="false">
    <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue>
    </Attribute>
</Attributes>
<Attributes Category="urn:oasis:names:tc:xacml:3.0:action-category:action">
    <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" IncludeInResult="false">
    <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue>
    </Attribute>
</Attributes>
</Request>

解决方案

可以通过XACML 3.0的**Obligations(义务)**特性实现需求,AuthzForce完全支持该特性。核心思路是将每个属性检查的布尔结果转换为整数,求和得到匹配总数,再通过义务将统计值附加到决策结果中。

修改后的策略

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<PolicySet
xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17"
PolicySetId="root"
Version="0.1.37"
PolicyCombiningAlgId="urn:oasis:names:tc:xacml:3.0:policy-combining-algorithm:deny-unless-permit">
<Description>PolicySet for XACML model with attribute match statistics</Description>

<Target />

<Policy
PolicyId="EngineeringAppAccessPolicy"
Version="1.0"
RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-unless-permit">

<Description>Policy for controlling access to EngineeringApp by verifying attributes with match stats</Description>

<Target>
<AnyOf>
    <AllOf>
    <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
    <AttributeValue
    DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue>
    <AttributeDesignator
    Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource"
    AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id"
    DataType="http://www.w3.org/2001/XMLSchema#string"
    MustBePresent="true" />
    </Match>
    </AllOf>
</AnyOf>
</Target>

<Rule RuleId="AttributeBasedAccessRule" Effect="Permit">
<Description>Permit access to EngineeringApp if user role is Engineer and action is access, return match stats</Description>

<Condition>
    <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:and">
        <!-- 检查action是否为access -->
        <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue>
            <AttributeDesignator
                Category="urn:oasis:names:tc:xacml:3.0:action-category:action"
                AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
                DataType="http://www.w3.org/2001/XMLSchema#string"
                MustBePresent="true" />
        </Apply>
        <!-- 检查subject role是否为Engineer -->
        <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:any-of">
            <Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal" />
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue>
            <AttributeDesignator
                AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role"
                DataType="http://www.w3.org/2001/XMLSchema#string"
                MustBePresent="true"
                Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" />
        </Apply>
    </Apply>
</Condition>

<!-- 添加义务返回统计信息 -->
<Obligations>
    <!-- 返回匹配的属性总数 -->
    <Obligation ObligationId="urn:example:obligation:matched-attributes-count" FulfillOn="Permit">
        <AttributeAssignment
            AttributeId="urn:example:attribute:matched-count"
            DataType="http://www.w3.org/2001/XMLSchema#integer">
            <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:sum">
                <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:integer-from-boolean">
                    <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue>
                        <AttributeDesignator
                            Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource"
                            AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id"
                            DataType="http://www.w3.org/2001/XMLSchema#string"
                            MustBePresent="true" />
                    </Apply>
                </Apply>
                <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:integer-from-boolean">
                    <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue>
                        <AttributeDesignator
                            Category="urn:oasis:names:tc:xacml:3.0:action-category:action"
                            AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
                            DataType="http://www.w3.org/2001/XMLSchema#string"
                            MustBePresent="true" />
                    </Apply>
                </Apply>
                <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:integer-from-boolean">
                    <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:any-of">
                        <Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal" />
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue>
                        <AttributeDesignator
                            AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role"
                            DataType="http://www.w3.org/2001/XMLSchema#string"
                            MustBePresent="true"
                            Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" />
                    </Apply>
                </Apply>
            </Apply>
        </AttributeAssignment>
    </Obligation>
    <!-- 返回检查的属性总数 -->
    <Obligation ObligationId="urn:example:obligation:total-attributes-count" FulfillOn="Permit">
        <AttributeAssignment
            AttributeId="urn:example:attribute:total-count"
            DataType="http://www.w3.org/2001/XMLSchema#integer">3</AttributeAssignment>
    </Obligation>
</Obligations>
</Rule>

</Policy>
</PolicySet>

关键修改说明

  1. 统计逻辑实现:使用integer-from-boolean将每个属性检查的结果(true/false)转为1/0,再通过sum函数求和得到匹配总数。
  2. 义务配置:定义两个义务,分别返回匹配总数和固定的检查总数(这里为3),FulfillOn指定为Permit表示仅在授权通过时返回,若需要拒绝时也返回,可改为Both。
  3. 规则逻辑保留:原有访问控制逻辑保持不变,仅新增统计和返回逻辑。

响应示例

当所有属性匹配时,响应会包含以下内容:

<Result>
    <Decision>Permit</Decision>
    <Obligations>
        <Obligation ObligationId="urn:example:obligation:matched-attributes-count">
            <AttributeAssignment AttributeId="urn:example:attribute:matched-count" DataType="http://www.w3.org/2001/XMLSchema#integer">3</AttributeAssignment>
        </Obligation>
        <Obligation ObligationId="urn:example:obligation:total-attributes-count">
            <AttributeAssignment AttributeId="urn:example:attribute:total-count" DataType="http://www.w3.org/2001/XMLSchema#integer">3</AttributeAssignment>
        </Obligation>
    </Obligations>
</Result>

内容的提问来源于stack exchange,提问作者Saurabh Kulkarni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 09:57:33