<?xml version="1.0" encoding="UTF-8"?><PolicySet xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os" PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:deny-overrides" PolicySetId="demoFolder" Version="1">
  <Description>Policies for demoFolder</Description>
  <PolicySetDefaults>
    <XPathVersion>http://www.w3.org/TR/1999/Rec-xpath-19991116</XPathVersion>
  </PolicySetDefaults>
  <Target>
    <Subjects>
      <Subject>
        <SubjectMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">SOFFID_ADMIN@soffid</AttributeValue>
          <SubjectAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:2.0:subject:role" DataType="http://www.w3.org/2001/XMLSchema#string"/>
        </SubjectMatch>
      </Subject>
    </Subjects>
    <Resources>
      <Resource>
        <ResourceMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
          <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">/vault/demoFolder</AttributeValue>
          <ResourceAttributeDesignator AttributeId="urn:com:soffid:xacml:resource:vault" DataType="http://www.w3.org/2001/XMLSchema#string"/>
        </ResourceMatch>
      </Resource>
    </Resources>
  </Target>
  <Obligations>
    <Obligation FulfillOn="Permit" ObligationId="urn:soffid:obligation:bpm">
      <AttributeAssignment AttributeId="process" DataType="http://www.w3.org/2001/XMLSchema#string">Grant account</AttributeAssignment>
    </Obligation>
    <Obligation FulfillOn="Permit" ObligationId="urn:soffid:obligation:message">
      <AttributeAssignment AttributeId="text" DataType="http://www.w3.org/2001/XMLSchema#string">This is a protected system. Do not enter without authorization, please.</AttributeAssignment>
    </Obligation>
  </Obligations>
  <Policy PolicyId="TimeToAccess" RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:permit-overrides" Version="1">
    <Description>Time to access to the resources</Description>
    <PolicyDefaults>
      <XPathVersion>http://www.w3.org/TR/1999/Rec-xpath-19991116</XPathVersion>
    </PolicyDefaults>
    <Target/>
    <Rule Effect="Permit" RuleId="LabourTime">
      <Description>Labour Time</Description>
      <Target/>
      <Condition>
        <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:and">
          <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:time-greater-than">
            <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:time-one-and-only">
              <EnvironmentAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:environment:current-time" DataType="http://www.w3.org/2001/XMLSchema#time"/>
            </Apply>
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#time">6:00:00</AttributeValue>
          </Apply>
          <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:time-less-than">
            <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:time-one-and-only">
              <EnvironmentAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:environment:current-time" DataType="http://www.w3.org/2001/XMLSchema#time"/>
            </Apply>
            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#time">20:00:00</AttributeValue>
          </Apply>
        </Apply>
      </Condition>
    </Rule>
    <Rule Effect="Deny" RuleId="Other">
      <Description>Other Deny</Description>
      <Target/>
    </Rule>
  </Policy>
  <Policy PolicyId="UsersRestrictions" RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:deny-overrides" Version="1">
    <Description>Users Restrictions</Description>
    <PolicyDefaults>
      <XPathVersion>http://www.w3.org/TR/1999/Rec-xpath-19991116</XPathVersion>
    </PolicyDefaults>
    <Target/>
    <Rule Effect="Deny" RuleId="DenyBob">
      <Description>Deny access</Description>
      <Target>
        <Subjects>
          <Subject>
            <SubjectMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
              <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">bob</AttributeValue>
              <SubjectAttributeDesignator AttributeId="urn:com:soffid:xacml:subject:user" DataType="http://www.w3.org/2001/XMLSchema#string"/>
            </SubjectMatch>
          </Subject>
        </Subjects>
      </Target>
    </Rule>
    <Rule Effect="Permit" RuleId="Other">
      <Description>Permit access</Description>
      <Target/>
    </Rule>
  </Policy>
</PolicySet>
