Example Dynamic role PEP
Dynamic role Enforcement Point
Policy set
We define a policy set that will apply to users who have been assigned a specific role.
That policy set has three policies, one for each operation that we want to manage.
Policies
We can define a policy for each operation, to permit or deny access
Policy1
We define a policy to permit or deny access to query users.
Rules
&&TODO&& sustituir la imagen cuando se arregle el label de Attribute selector
That rule allow to the end-user to query users who belong to the same primary group that the end-user.
That rule denies access to query users
Policy2
Rules
Download XML
You can download a XML file with the example: policy-TestDynamicPEP.xml