Re: [Geopriv] question on presrules
Jonathan Rosenberg <[email protected]>
| Newsgroups | gmane.ietf.simple,gmane.ietf.geopriv |
|---|---|
| Message-ID | <[email protected]> |
Enrique Izaguirre wrote:
> Hi,
>
> according to RFC5025 there could be scenarios where the transformations
> within a matching ruled whose action=block may filter the presence
> document showed to the requestor.
>
> E.g. this can happen when there are two matching rules, one that is
> blocking and the other is allowing, and they have different
> transformation elements. If RFC4745 is applied, the combined action is
> "allow" and the combined transformation is a superset of both
> "transformations".
Right. That is a possibility.
>
> So, is the assumption that clients are smart enough so they will never
> fall into the above case? or should a presence server prevent clients
> from not doing such combination of rules?
Its a job of the UI on the client to prevent this. Normally its not a
problem. The spec has this to say:
A consequence of this design is that the results of combining several
authorization documents can be non-obvious to end users. For
example, if one authorization document grants permission for all
users from the example.com domain to see their presence, and another
document blocks [email protected], the combination of these will still
provide presence to [email protected]. Designers of user interfaces
are encouraged to carefully pay attention to the results of combining
multiple rules.
-Jonathan R.
--
Jonathan D. Rosenberg, Ph.D. 499 Thornall St.
Cisco Fellow Edison, NJ 08837
Cisco, Voice Technology Group
[email protected]
http://www.jdrosen.net PHONE: (408) 902-3084
http://www.cisco.com