PDP中XACML请求属性与Attribute Provider校验相关技术问询
Hey there! Glad to hear your AuthzForce Core PDP is running stably with XACML requests—great start. First, let's recap your working code for context:
//My request and pdp configuration files File confLocation = new File("D:/docs/XACML/AuthZForce/IIA001/pdp.xml");//pdp.xml tells the pdp where the policies xml files are File requestFile = new File("D:/docs/XACML/AuthZForce/IIA001/Request.xml"); //I instantiate the pdp engine and the xacml parser final PdpEngineConfiguration pdpEngineConf = PdpEngineConfiguration.getInstance(confLocation, null, null); PdpEngineInoutAdapter<Request, Response> pdp = PdpEngineAdapters.newXacmlJaxbInoutAdapter(pdpEngineConf); XmlUtils.XmlnsFilteringParser xacmlParserFactory = XacmlJaxbParsingUtils.getXacmlParserFactory(false).getInstance(); //I parse the request file Object request = xacmlParserFactory.parse(requestFile.toURI().toURL()); if (request instanceof Request) { //At this point I could access all request attributes or alter them //I let the PDP evaluate the request Response response = pdp.evaluate((Request) request); //I check the results inside the response for (Result result : response.getResults()) { if (result.getDecision() == DecisionType.PERMIT) { //it's permitted! } else { //denied! } } }
Now let's tackle your technical questions one by one:
1. 请求与Attribute Provider的校验工作属于PDP还是其他实体的职责?
Per the XACML architecture, attribute validation via Attribute Providers is primarily the PDP's responsibility. That said, you can do basic format checks at the PEP (Policy Enforcement Point) before sending the request to the PDP. But the critical work of verifying attribute authenticity (e.g., cross-checking a patient's DOB against a trusted database) belongs in the PDP. This ensures your authorization decisions are based on trusted, source-of-truth attributes, rather than potentially tampered values from the initial request.
2. OASIS对此问题是否有具体规范,如工作流或配置文件语法?
Yes! The OASIS XACML 3.0 specification explicitly defines Attribute Retrieval mechanisms, which cover how PDPs can fetch or validate attributes from external sources. AuthzForce Core, being a compliant XACML engine, adheres to these standards. For configuration, you can define Attribute Providers directly in your pdp.xml file—for example, setting up a JDBC provider to connect to your patient database, with queries to pull and validate attributes automatically during policy evaluation.
3. 是否可让我的PDP引擎感知Attribute Provider?
Absolutely! AuthzForce Core is built to support Attribute Providers out of the box. You don't need to write custom validation code in your application; instead, configure your pdp.xml to define the providers (e.g., JDBC, LDAP, or custom implementations). The PDP will then automatically retrieve trusted attributes from these sources during evaluation—either replacing untrusted request attributes or cross-checking them against the source of truth to ensure validity.
4. 是否应在执行Response response = pdp.evaluate((Request) request);前自行校验请求?
If you've properly configured Attribute Providers in AuthzForce, you don't need to manually validate attributes before calling pdp.evaluate(). The PDP will handle attribute retrieval and validation as part of its evaluation workflow. Manual pre-validation is redundant at best, and risky at worst—it could lead to inconsistencies between your pre-check logic and the PDP's actual decision-making rules. For basic structural checks (e.g., ensuring the request is a valid XACML document), those can be handled at the PEP layer, but leave attribute authenticity checks to the PDP's configured providers.
内容的提问来源于stack exchange,提问作者OneWorld

