AuthzForce XACML3.0返回Indeterminate异常问题求助
Hey there! Let's figure out why you're hitting that Indeterminate response with AuthzForce XACML 3.0.
Root Cause Analysis
Looking at your exception stack trace, the core issue jumps right out:
org.ow2.authzforce.core.pdp.api.IndeterminateEvaluationException: Function urn:oasis:names:tc:xacml:1.0:function:integer-one-and-only: Invalid arg #0: empty bag or bag size > 1. Required: one and only one value in bag.
The integer-one-and-only function is designed to pull a single unique value from an attribute bag (collection of values). But in your request, you've passed two values for the urn:oasis:names:tc:xacml:2.0:conformance-test:age attribute (45 and 46), creating a bag with two elements. This directly violates the function's requirement, leading to the Indeterminate evaluation.
Here's the problematic snippet from your request:
<Attribute IncludeInResult="false" AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:age"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#integer">45</AttributeValue> </Attribute> <Attribute IncludeInResult="false" AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:age"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#integer">46</AttributeValue> </Attribute>
In XACML, repeating the same AttributeId within a category creates a multi-value bag, not a single attribute with multiple values.
Solutions
You have two clear paths to fix this, depending on your business needs:
1. Adjust the Request: Pass a Single Age Value
If your use case expects only one age per user, simply remove the duplicate age attribute entry from your request:
<Attributes Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject"> <Attribute IncludeInResult="false" AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">Julius Hibbert</AttributeValue> </Attribute> <Attribute IncludeInResult="false" AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:age"> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#integer">45</AttributeValue> </Attribute> </Attributes>
Now integer-one-and-only can safely retrieve the single age value, compare it to 45, and return a Permit decision as expected.
2. Modify the Policy: Support Multi-Value Attributes
If your scenario allows multiple age values (e.g., historical records) and you want to permit access if any of the ages equals 45, replace integer-one-and-only with the integer-any-of function, which is built for multi-value bags:
<Rule Effect="Permit" RuleId="urn:oasis:names:tc:xacml:2.0:conformance-test:IIA1:rule"> <Description> Anyone who has an age of 45 integer years old may perform any action on any resource. </Description> <Condition> <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:integer-any-of"> <Function FunctionId="urn:oasis:names:tc:xacml:1.0:function:integer-equal"/> <AttributeDesignator AttributeId="urn:oasis:names:tc:xacml:2.0:conformance-test:age" Category="urn:oasis:names:tc:xacml:1.0:subject-category:access-subject" DataType="http://www.w3.org/2001/XMLSchema#integer" MustBePresent="false" /> <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#integer">45</AttributeValue> </Apply> </Condition> </Rule>
integer-any-of checks if any value in the bag meets the integer-equal condition, so even with two age values, it will return true if 45 is present, resulting in a Permit decision.
Verify the Fix
After implementing either solution, resubmit your request, and AuthzForce should return the expected Permit decision instead of Indeterminate.
内容的提问来源于stack exchange,提问作者Nishant

