如何从ABAC中的XACML策略获取匹配属性数与总检查属性数?
在AuthzForce的XACML策略中添加属性匹配统计返回
我是XACML和ABAC的初学者,已经在本地AuthzForce服务器部署了一份XACML策略,通过Postman测试请求可以正常运行。现在我想修改这个策略,让它除了返回Permit或Deny结果外,还能返回匹配的属性总数以及检查的属性总数(比如3个检查属性里有2个匹配,要在响应里拿到数值‘2’和‘3’)。请问能不能修改下面的策略?
原策略
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <PolicySet xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" PolicySetId="root" Version="0.1.37" PolicyCombiningAlgId="urn:oasis:names:tc:xacml:3.0:policy-combining-algorithm:deny-unless-permit"> <Description>PolicySet for XACML model</Description> <Target /> <Policy PolicyId="EngineeringAppAccessPolicy" Version="1.0" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-unless-permit"> <Description>Policy for controlling access to EngineeringApp by verifying attributes</Description> <!-- Target specifies this policy applies to the resource "EngineeringApp" --> <Target> <AnyOf> <AllOf> <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue> <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource" AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" /> </Match> </AllOf> </AnyOf> </Target> <!-- Rule specifies conditions for access --> <Rule RuleId="AttributeBasedAccessRule" Effect="Permit"> <Description>Permit access to EngineeringApp if user role is Engineer and action is access</Description> <Target> <AnyOf> <AllOf> <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue> <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:action-category:action" AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" /> </Match> </AllOf> </AnyOf> </Target> <!-- Condition verifies the user role --> <Condition> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:any-of"> <Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal" /> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue> <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" /> </Apply> </Condition> </Rule> </Policy> </PolicySet>
当前测试请求
<?xml version="1.0" encoding="UTF-8"?> <Request xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" ReturnPolicyIdList="true" CombinedDecision="false"> <Attributes Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"> <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" IncludeInResult="false"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue> </Attribute> </Attributes> <Attributes Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource"> <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id" IncludeInResult="false"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue> </Attribute> </Attributes> <Attributes Category="urn:oasis:names:tc:xacml:3.0:action-category:action"> <Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" IncludeInResult="false"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue> </Attribute> </Attributes> </Request>
解决方案
可以通过XACML 3.0的**Obligations(义务)**特性实现需求,AuthzForce完全支持该特性。核心思路是将每个属性检查的布尔结果转换为整数,求和得到匹配总数,再通过义务将统计值附加到决策结果中。
修改后的策略
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <PolicySet xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-17" PolicySetId="root" Version="0.1.37" PolicyCombiningAlgId="urn:oasis:names:tc:xacml:3.0:policy-combining-algorithm:deny-unless-permit"> <Description>PolicySet for XACML model with attribute match statistics</Description> <Target /> <Policy PolicyId="EngineeringAppAccessPolicy" Version="1.0" RuleCombiningAlgId="urn:oasis:names:tc:xacml:3.0:rule-combining-algorithm:deny-unless-permit"> <Description>Policy for controlling access to EngineeringApp by verifying attributes with match stats</Description> <Target> <AnyOf> <AllOf> <Match MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue> <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource" AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" /> </Match> </AllOf> </AnyOf> </Target> <Rule RuleId="AttributeBasedAccessRule" Effect="Permit"> <Description>Permit access to EngineeringApp if user role is Engineer and action is access, return match stats</Description> <Condition> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:and"> <!-- 检查action是否为access --> <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue> <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:action-category:action" AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" /> </Apply> <!-- 检查subject role是否为Engineer --> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:any-of"> <Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal" /> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue> <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" /> </Apply> </Apply> </Condition> <!-- 添加义务返回统计信息 --> <Obligations> <!-- 返回匹配的属性总数 --> <Obligation ObligationId="urn:example:obligation:matched-attributes-count" FulfillOn="Permit"> <AttributeAssignment AttributeId="urn:example:attribute:matched-count" DataType="http://www.w3.org/2001/XMLSchema#integer"> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:sum"> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:integer-from-boolean"> <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">EngineeringApp</AttributeValue> <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:resource-category:resource" AttributeId="urn:oasis:names:tc:xacml:1.0:resource:id" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" /> </Apply> </Apply> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:integer-from-boolean"> <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">access</AttributeValue> <AttributeDesignator Category="urn:oasis:names:tc:xacml:3.0:action-category:action" AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" /> </Apply> </Apply> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:integer-from-boolean"> <Apply FunctionId="urn:oasis:names:tc:xacml:3.0:function:any-of"> <Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-equal" /> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Engineer</AttributeValue> <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-role" DataType="http://www.w3.org/2001/XMLSchema#string" MustBePresent="true" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" /> </Apply> </Apply> </Apply> </AttributeAssignment> </Obligation> <!-- 返回检查的属性总数 --> <Obligation ObligationId="urn:example:obligation:total-attributes-count" FulfillOn="Permit"> <AttributeAssignment AttributeId="urn:example:attribute:total-count" DataType="http://www.w3.org/2001/XMLSchema#integer">3</AttributeAssignment> </Obligation> </Obligations> </Rule> </Policy> </PolicySet>
关键修改说明
- 统计逻辑实现:使用
integer-from-boolean将每个属性检查的结果(true/false)转为1/0,再通过sum函数求和得到匹配总数。 - 义务配置:定义两个义务,分别返回匹配总数和固定的检查总数(这里为3),
FulfillOn指定为Permit表示仅在授权通过时返回,若需要拒绝时也返回,可改为Both。 - 规则逻辑保留:原有访问控制逻辑保持不变,仅新增统计和返回逻辑。
响应示例
当所有属性匹配时,响应会包含以下内容:
<Result> <Decision>Permit</Decision> <Obligations> <Obligation ObligationId="urn:example:obligation:matched-attributes-count"> <AttributeAssignment AttributeId="urn:example:attribute:matched-count" DataType="http://www.w3.org/2001/XMLSchema#integer">3</AttributeAssignment> </Obligation> <Obligation ObligationId="urn:example:obligation:total-attributes-count"> <AttributeAssignment AttributeId="urn:example:attribute:total-count" DataType="http://www.w3.org/2001/XMLSchema#integer">3</AttributeAssignment> </Obligation> </Obligations> </Result>
内容的提问来源于stack exchange,提问作者Saurabh Kulkarni
相关产品推荐
相关产品推荐

