[
https://issues.jboss.org/browse/SECURITY-590?page=com.atlassian.jira.plug...
]
Dan Gradl edited comment on SECURITY-590 at 11/15/11 11:32 PM:
---------------------------------------------------------------
At first look, I believed that this example is creating an invalid context, because an
Attribute requires an AttributeValue according to the XACML context schema. A subject,
resource, and action are required as well. So I at first concluded that the
ParseException was simply misleading as it was truly an invalid request context. If this
request was an XML request with an empty Attribute and it was validated against the schema
it would fail. However building it via the object model is providing a convenience.
The RequestAttributeFactory is built to allow you to create Date/Time/DateTime attributes
with no value provided and it will take the current system time. There is in fact an
issue with the default value it is setting.
was (Author: dgradl):
comment withdrawn
RequestAttributeFactory.createTimeAttributeType(attName, issuer) API
call causes a parsing exception
----------------------------------------------------------------------------------------------------
Key: SECURITY-590
URL:
https://issues.jboss.org/browse/SECURITY-590
Project: PicketBox (JBoss Security and Identity Management)
Issue Type: Bug
Security Level: Public(Everyone can see)
Components: JBossXACML
Environment: Version was 2.0.6.Final
Reporter: Asankha Perera
Assignee: Anil Saldhana
Priority: Minor
Using the API call RequestAttributeFactory.createTimeAttributeType(attName, issuer)
causes a "ParsingException: couldn't create
http://www.w3.org/2001/XMLSchema#time
attribute based on DOM node"
Note that with the above API call, we do not supply any time string, but assume that the
current time is used. As a comparison the similar API call
RequestAttributeFactory.createDateTimeAttributeType(attName, issuer) works without any
issues - hence it seems logical that the createTimeAttributeType() contains a possible bug
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators:
https://issues.jboss.org/secure/ContactAdministrators!default.jspa
For more information on JIRA, see:
http://www.atlassian.com/software/jira