hexBinarySetEquals Function Description

Description

This method returns true if both sets of attribute values of type hexBinary are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c].

hexBinarySetEquals belongs to the ALFA function reference's Set functions category. It maps to the XACML function identifier urn:oasis:names:tc:xacml:1.0:function:hexBinary-set-equals, takes 2 arguments and returns a value of type boolean.

Property Value
Category Set functions
# Arguments 2
Arguments
  • A bag of type hexBinary
  • A bag of type hexBinary
Return Value boolean
Expressed As pre-fix
Representation ALFA short name
Allowed In Target false
ALFA Shorthand None
Commutative true

Example

/**
* Permit if the set of values hexValue is in the set of allowedHexValues and if there are no more values
* in the allowedHexValues set.
*/            
rule hexBinarySetEqualsExample{
    permit
    condition hexBinarySetEquals(hexValue, allowedHexValues)
}

In this example, access is permitted if all the hex values are also all the allowed hex values, no more no less.