ALFA Functions
Use functions to compare and manipulate attributes in policies. If, for instance, you want to compare the role attribute to the value 'manager', you'd use the string equality function.
There are different kinds of functions:
- Higher order bag functions
- Logical functions
- Set functions
- Bag functions
- Equality predicates
- Non-numeric comparison functions
- Arithmetic function
- Numeric comparision functions
- Numeric datatype conversion function
- Special match function
- String conversion function
- Regular-expression-based functions
- String functions
- Date and time arithmetic functions
- XPath-based functions
ALFA comes with hundreds of functions you can use in Target or Condition elements.
Function List
| Name | Category | Description |
|---|---|---|
| allOf | higher order bag functions | This function applies a boolean function which takes n parameters between n-1 atomic values and a bag of values. It returns "True" if and only if the predicate is "True" for every element of the bag. |
| allOfAll | higher order bag functions | This function applies a Boolean function between the elements of two bags. The expression SHALL be "True" if and only if the supplied predicate is "True" between each and every element of the first bag collectively against all the elements of the second bag. |
| allOfAny | higher order bag functions | This function applies a Boolean function between the elements of two bags. The expression SHALL be “True” if and only if the supplied predicate is “True” between each element of the first bag and any element of the second bag. |
| andFunction | logical functions | This function SHALL return "True" if it has no arguments and SHALL return "False" if one of its arguments evaluates to "False". The order of evaluation SHALL be from first argument to last. The evaluation SHALL stop with a result of "False" if any argument evaluates to "False", leaving the rest of the arguments unevaluated. |
| anyOf | higher order bag functions | This function applies a Boolean function between specific atomic values and a bag of values, and SHALL return "True" if and only if the predicate is "True" for at least one element of the bag. Using this function with the relevant typeEquals function is equivalent to using the shortcut function typeIsIn e.g. stringIsIn(). |
| anyOfAll | higher order bag functions | This function applies a Boolean function between the elements of two bags. The expression SHALL be “True” if and only if the supplied predicate is “True” between each element of the second bag and any element of the first bag. This function is exactly the same as allOfAny with the 2nd and 3rd parameters inverted. |
| anyOfAny | higher order bag functions | This function applies a Boolean function on each tuple from the cross product on all bags arguments, and returns "True" if and only if the predicate is "True" for at least one inside-function call. This function is commonly combined with the equality function e.g. to prove that there is at least one attribute value in the first bag equal to a value in another bag. Several datatypes have a shortcut method typeAtLeastOneMemberOf (e.g. stringAtLeastOneMemberOf) which can be used instead of using the anyOfAny higher order function. |
| anyURIAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of anyURI and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| anyURIBag | Bag functions | This function takes in n atomic anyURI values and returns a bag containing those values. This function is seldom used on its. It would be used in conjunction with another function e.g. anyURIIsIn. |
| anyURIBagSize | Bag functions | This function takes in a single parameter of type bag of anyURI and returns an integer representing the size or number of values in the bag. The bag may contain duplicate values and they will all be counted individually. |
| anyURIContains | String functions | |
| anyURIEndsWith | String functions | |
| anyURIEqual | equality predicates | The anyURIEqual function compares two atomic values of type anyURI and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the anyURI type. |
| anyURIFromString | String functions | |
| anyURIIntersection | Set functions | This function takes in two parameters of type bag of anyURI and returns a bag of anyURI values such that it contains only elements that are common between the two bags. |
| anyURIIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type anyURI are compared using the anyURIEqual function. |
| anyURIOneAndOnly | Bag functions | This function takes in a bag of attributes of type anyURI and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| anyURIRegexpMatch | Regular-expression-based functions | |
| anyURISetEquals | Set functions | This method returns true if both sets of attribute values of type anyURI are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| anyURIStartsWith | String functions | |
| anyURISubSet | Set functions | |
| anyURISubString | String functions | |
| anyURIUnion | Set functions | This function takes two or more arguments that are both a bag of anyURI values. It returns a bag of anyURI such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| base64BinaryAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of base64Binary and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| base64BinaryBag | Bag functions | |
| base64BinaryBagSize | Bag functions | This function allows users to measure the size of a bag of type base64Binary. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| base64BinaryEqual | equality predicates | The base64BinaryEqual function compares two atomic values of type base64Binary and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the base64Binary type. |
| base64BinaryIntersection | Set functions | |
| base64BinaryIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type base64Binary are compared using the base64BinaryEqual function. |
| base64BinaryOneAndOnly | Bag functions | This function takes in a bag of attributes of type base64Binary and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| base64BinarySetEquals | Set functions | This method returns true if both sets of attribute values of type base64Binary are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| base64BinarySubSet | Set functions | |
| base64BinaryUnion | Set functions | This function takes two or more arguments that are both a bag of base64Binary values. It returns a bag of base64Binary such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| booleanAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of boolean and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| booleanBag | Bag functions | |
| booleanBagSize | Bag functions | This function allows users to measure the size of a bag of type boolean. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| booleanEqual | equality predicates | The booleanEqual function compares two atomic values of type boolean and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the boolean type. |
| booleanFromString | String functions | |
| booleanIntersection | Set functions | |
| booleanIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type boolean are compared using the booleanEqual function. |
| booleanOneAndOnly | Bag functions | This function takes in a bag of attributes of type boolean and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| booleanSetEquals | Set functions | This method returns true if both sets of attribute values of type boolean are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| booleanSubSet | Set functions | |
| booleanUnion | Set functions | This function takes two or more arguments that are both a bag of boolean values. It returns a bag of boolean such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| dateAddYearMonthDuration | Date and time arithmetic functions | |
| dateAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of date and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| dateBag | Bag functions | |
| dateBagSize | Bag functions | This function allows users to measure the size of a bag of type date. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| dateEqual | equality predicates | The dateEqual function compares two atomic values of type date and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the date type. |
| dateFromString | String functions | |
| dateGreaterThan | Non-numeric comparison functions | |
| dateGreaterThanOrEqual | Non-numeric comparison functions | |
| dateIntersection | Set functions | |
| dateIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type date are compared using the dateEqual function. |
| dateLessThan | Non-numeric comparison functions | |
| dateLessThanOrEqual | Non-numeric comparison functions | |
| dateOneAndOnly | Bag functions | This function takes in a bag of attributes of type date and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| dateSetEquals | Set functions | This method returns true if both sets of attribute values of type date are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| dateSubSet | Set functions | |
| dateSubtractYearMonthDuration | Date and time arithmetic functions | |
| dateTimeAddDayTimeDuration | Date and time arithmetic functions | |
| dateTimeAddYearMonthDuration | Date and time arithmetic functions | |
| dateTimeAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of dateTime and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| dateTimeBag | Bag functions | |
| dateTimeBagSize | Bag functions | This function allows users to measure the size of a bag of type dateTime. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| dateTimeEqual | equality predicates | The dateTimeEqual function compares two atomic values of type dateTime and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the dateTime type. |
| dateTimeFromString | String functions | |
| dateTimeGreaterThan | Non-numeric comparison functions | |
| dateTimeGreaterThanOrEqual | Non-numeric comparison functions | |
| dateTimeIntersection | Set functions | |
| dateTimeIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type dateTime are compared using the dateTimeEqual function. |
| dateTimeLessThan | Non-numeric comparison functions | |
| dateTimeLessThanOrEqual | Non-numeric comparison functions | |
| dateTimeOneAndOnly | Bag functions | This function takes in a bag of attributes of type dateTime and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| dateTimeSetEquals | Set functions | This method returns true if both sets of attribute values of type dateTime are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| dateTimeSubSet | Set functions | |
| dateTimeSubtractDayTimeDuration | Date and time arithmetic functions | |
| dateTimeSubtractYearMonthDuration | Date and time arithmetic functions | |
| dateTimeUnion | Set functions | This function takes two or more arguments that are both a bag of dateTime values. It returns a bag of dateTime such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| dateUnion | Set functions | This function takes two or more arguments that are both a bag of date values. It returns a bag of date such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| dayTimeDurationAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of dayTimeDuration and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| dayTimeDurationBag | Bag functions | |
| dayTimeDurationBagSize | Bag functions | This function allows users to measure the size of a bag of type dayTimeDuration. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| dayTimeDurationEqual | equality predicates | The dayTimeDurationEqual function compares two atomic values of type dayTimeDuration and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the dayTimeDuration type. |
| dayTimeDurationFromString | String functions | |
| dayTimeDurationIntersection | Set functions | |
| dayTimeDurationIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type dayTimeDuration are compared using the dayTimeDurationEqual function. |
| dayTimeDurationOneAndOnly | Bag functions | This function takes in a bag of attributes of type dayTimeDuration and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| dayTimeDurationSetEquals | Set functions | This method returns true if both sets of attribute values of type dayTimeDuration are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| dayTimeDurationSubSet | Set functions | |
| dayTimeDurationUnion | Set functions | This function takes two or more arguments that are both a bag of dayTimeDuration values. It returns a bag of dayTimeDuration such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| dnsNameBag | Bag functions | |
| dnsNameBagSize | Bag functions | This function allows users to measure the size of a bag of type dnsName. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| dnsNameFromString | String functions | |
| dnsNameOneAndOnly | Bag functions | This function takes in a bag of attributes of type dnsName and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| dnsNameRegexpMatch | Regular-expression-based functions | |
| doubleAbs | arithmetic function | |
| doubleAdd | arithmetic function | |
| doubleAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of double and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| doubleBag | Bag functions | |
| doubleBagSize | Bag functions | This function allows users to measure the size of a bag of type double. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| doubleDivide | arithmetic function | |
| doubleEqual | equality predicates | The doubleEqual function compares two atomic values of type double and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the double type. |
| doubleFromString | String functions | |
| doubleGreaterThan | numeric comparision functions | |
| doubleGreaterThanOrEqual | numeric comparision functions | |
| doubleIntersection | Set functions | |
| doubleIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type double are compared using the doubleEqual function. |
| doubleLessThan | numeric comparision functions | |
| doubleLessThanOrEqual | numeric comparision functions | |
| doubleMultiply | arithmetic function | |
| doubleOneAndOnly | Bag functions | This function takes in a bag of attributes of type double and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| doubleSetEquals | Set functions | This method returns true if both sets of attribute values of type double are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| doubleSubSet | Set functions | |
| doubleSubtract | arithmetic function | |
| doubleToInteger | numeric datatype conversion function | |
| doubleUnion | Set functions | This function takes two or more arguments that are both a bag of double values. It returns a bag of double such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| floor | arithmetic function | |
| hexBinaryAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of hexBinary and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| hexBinaryBag | Bag functions | |
| hexBinaryBagSize | Bag functions | This function allows users to measure the size of a bag of type hexBinary. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| hexBinaryEqual | equality predicates | The hexBinaryEqual function compares two atomic values of type hexBinary and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the hexBinary type. |
| hexBinaryIntersection | Set functions | |
| hexBinaryIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type hexBinary are compared using the hexBinaryEqual function. |
| hexBinaryOneAndOnly | Bag functions | This function takes in a bag of attributes of type hexBinary and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| hexBinarySetEquals | Set functions | This method returns true if both sets of attribute values of type hexBinary are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| hexBinarySubSet | Set functions | |
| hexBinaryUnion | Set functions | This function takes two or more arguments that are both a bag of hexBinary values. It returns a bag of hexBinary such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| integerAbs | arithmetic function | |
| integerAdd | arithmetic function | |
| integerAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of integer and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| integerBag | Bag functions | |
| integerBagSize | Bag functions | This function allows users to measure the size of a bag of type integer. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| integerDivice // integerDivide | arithmetic function | |
| integerEqual | equality predicates | The integerEqual function compares two atomic values of type integer and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the integer type. |
| integerFromString | String functions | |
| integerGreaterThan | numeric comparision functions | |
| integerGreaterThanOrEqual | numeric comparision functions | |
| integerIntersection | Set functions | |
| integerIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type integer are compared using the integerEqual function. |
| integerLessThan | numeric comparision functions | |
| integerLessThanOrEqual | numeric comparision functions | |
| integerMod | arithmetic function | |
| integerMultiply | arithmetic function | |
| integerOneAndOnly | Bag functions | This function takes in a bag of attributes of type integer and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| integerSetEquals | Set functions | This method returns true if both sets of attribute values of type integer are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| integerSubSet | Set functions | |
| integerSubtract | arithmetic function | |
| integerToDouble | numeric datatype conversion function | |
| integerUnion | Set functions | This function takes two or more arguments that are both a bag of integer values. It returns a bag of integer such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| ipAddressBag | Bag functions | |
| ipAddressBagSize | Bag functions | This function allows users to measure the size of a bag of type ipAddress. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| ipAddressFromString | String functions | |
| ipAddressOneAndOnly | Bag functions | This function takes in a bag of attributes of type ipAddress and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| ipAddressRegexpMatch | Regular-expression-based functions | |
| map | higher order bag functions | This function converts a bag of values to another bag of values. It applies another function to n atomic values and a bag to return a bag of the same size as the first bag. |
| nOf | logical functions | |
| not | logical functions | |
| orFunction | logical functions | |
| rfc822NameAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of rfc822Name and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| rfc822NameBag | Bag functions | |
| rfc822NameBagSize | Bag functions | This function allows users to measure the size of a bag of type rfc822Name. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| rfc822NameEqual | equality predicates | The rfc822NameEqual function compares two atomic values of type rfc822Name and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the rfc822Name type. |
| rfc822NameFromString | String functions | |
| rfc822NameIntersection | Set functions | |
| rfc822NameIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type rfc822Name are compared using the rfc822NameEqual function. |
| rfc822NameMatch | Special match function | |
| rfc822NameOneAndOnly | Bag functions | This function takes in a bag of attributes of type rfc822Name and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| rfc822NameRegexpMatch | Regular-expression-based functions | |
| rfc822NameSetEquals | Set functions | This method returns true if both sets of attribute values of type rfc822Name are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| rfc822NameSubSet | Set functions | |
| rfc822NameUnion | Set functions | This function takes two or more arguments that are both a bag of rfc822Name values. It returns a bag of rfc822Name such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| round | arithmetic function | |
| stringAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of string and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| stringBag | Bag functions | |
| stringBagSize | Bag functions | This function allows users to measure the size of a bag of type string. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| stringConcatenate | String functions | |
| stringContains | String functions | |
| stringEndsWith | String functions | |
| stringEqual | equality predicates | The stringEqual function compares two atomic values of type string and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the string type. |
| stringEqualIgnoreCase | equality predicates | The stringEqualIgnoreCase function compares two string values and returns true if and only if the lower case value of both of its arguments are of equal length and each lower case string is determined to be equal. |
| stringFromAnyURI | String functions | |
| stringFromBoolean | String functions | |
| stringFromDate | String functions | |
| stringFromDateTime | String functions | |
| stringFromDayTimeDuration | String functions | |
| stringFromDnsName | String functions | |
| stringFromDouble | String functions | |
| stringFromInteger | String functions | |
| stringFromIpAddress | String functions | |
| stringFromRfc822Name | String functions | |
| stringFromTime | String functions | |
| stringFromX500Name | String functions | |
| stringFromYearMonthDuration | String functions | |
| stringGreaterThan | Non-numeric comparison functions | |
| stringGreaterThanOrEqual | Non-numeric comparison functions | |
| stringIntersection | Set functions | |
| stringIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type string are compared using the stringEqual function. |
| stringLessThan | Non-numeric comparison functions | |
| stringLessThanOrEqual | Non-numeric comparison functions | |
| stringNormalizeSpace | string conversion function | |
| stringNormalizeToLowerCase | string conversion function | |
| stringOneAndOnly | Bag functions | This function takes in a bag of attributes of type string and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| stringRegexpMatch | Regular-expression-based functions | |
| stringSetEquals | Set functions | This method returns true if both sets of attribute values of type string are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| stringStartsWith | String functions | |
| stringSubSet | Set functions | |
| stringSubString | String functions | stringSubString takes in 3 parameters: a string s and 2 numbers start and end. The result is the substring that starts at index start and ends before index end. The first character of the string has position zero. The negative integer value -1 given for the third arguments indicates the end of the string. If the second or third arguments are out of bounds, then the function evaluates to Indeterminate with a status code of urn:oasis:names:tc:xacml:1.0:status:processing-error. |
| stringUnion | Set functions | This function takes two or more arguments that are both a bag of string values. It returns a bag of string such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| timeAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of time and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| timeBag | Bag functions | |
| timeBagSize | Bag functions | This function allows users to measure the size of a bag of type time. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| timeEqual | equality predicates | The timeEqual function compares two atomic values of type time and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the time type. |
| timeFromString | String functions | |
| timeGreaterThan | Non-numeric comparison functions | |
| timeGreaterThanOrEqual | Non-numeric comparison functions | |
| timeInRange | Non-numeric comparison functions | |
| timeIntersection | Set functions | |
| timeIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type time are compared using the timeEqual function. |
| timeLessThan | Non-numeric comparison functions | |
| timeLessThanOrEqual | Non-numeric comparison functions | |
| timeOneAndOnly | Bag functions | This function takes in a bag of attributes of type time and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| timeSetEquals | Set functions | This method returns true if both sets of attribute values of type time are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| timeSubSet | Set functions | |
| timeUnion | Set functions | This function takes two or more arguments that are both a bag of time values. It returns a bag of time such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| x500NameAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of x500Name and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| x500NameBag | Bag functions | |
| x500NameBagSize | Bag functions | This function allows users to measure the size of a bag of type x500Name. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| x500NameEqual | equality predicates | The x500NameEqual function compares two atomic values of type x500Name and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the x500Name type. |
| x500NameFromString | String functions | |
| x500NameIntersection | Set functions | |
| x500NameIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type x500Name are compared using the x500NameEqual function. |
| x500NameMatch | Special match function | |
| x500NameOneAndOnly | Bag functions | This function takes in a bag of attributes of type x500Name and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| x500NameRegexpMatch | Regular-expression-based functions | |
| x500NameSetEquals | Set functions | This method returns true if both sets of attribute values of type x500Name are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| x500NameSubSet | Set functions | |
| x500NameUnion | Set functions | This function takes two or more arguments that are both a bag of x500Name values. It returns a bag of x500Name such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |
| xpathNodeCount | XPath-based functions | |
| xpathNodeEqual | XPath-based functions | The xpathNodeEqual function compares two atomic values of type xpathNode and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the xpathNode type. |
| xpathNodeMatch | XPath-based functions | |
| yearMonthDurationAtLeastOneMemberOf | Set functions | This function takes in two parameters of type bag of yearMonthDuration and returns true if there is at least one value in the first bag equal to at least one value in the second bag. |
| yearMonthDurationBag | Bag functions | |
| yearMonthDurationBagSize | Bag functions | This function allows users to measure the size of a bag of type yearMonthDuration. Being able to determine the bag's size can help with use cases such as enforcing there be at least 1 value, for instance at least one citizenship. |
| yearMonthDurationEqual | equality predicates | The yearMonthDurationEqual function compares two atomic values of type yearMonthDuration and returns true if and only if the 2 arguments to the function are equal according to the equality rules defined by the yearMonthDuration type. |
| yearMonthDurationFromString | String functions | |
| yearMonthDurationIntersection | Set functions | |
| yearMonthDurationIsIn | Bag functions | Returns true if the value of the first parameter is in the bag of values of the second parameter. Attributes of type yearMonthDuration are compared using the yearMonthDurationEqual function. |
| yearMonthDurationOneAndOnly | Bag functions | This function takes in a bag of attributes of type yearMonthDuration and returns a single value. It only works if the bag contains a single value. If the bag contains zero values or more than 1 value than the function will trigger an error yielding Indeterminate. Use this function when you need to compare an attribute to a single value. See example below. |
| yearMonthDurationSetEquals | Set functions | This method returns true if both sets of attribute values of type yearMonthDuration are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c]. |
| yearMonthDurationSubSet | Set functions | |
| yearMonthDurationUnion | Set functions | This function takes two or more arguments that are both a bag of yearMonthDuration values. It returns a bag of yearMonthDuration such that it contains all elements of all the argument bags. The function gets rid of duplicates, as determined by the equality functions. |