stringSetEquals Function Description

Description

This method returns true if both sets of attribute values of type string are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c].

stringSetEquals belongs to the ALFA function reference's Set functions category. It maps to the XACML function identifier urn:oasis:names:tc:xacml:1.0:function:string-set-equals, takes 2 arguments and returns a value of type boolean.

Property Value
Category Set functions
# Arguments 2
Arguments
  • A bag of type string
  • A bag of type string
Return Value boolean
Expressed As pre-fix
Representation ALFA short name
Allowed In Target false
ALFA Shorthand None
Commutative true

Example

/**
* Allow access if the user names all the EU countries, not one more, not one less 
*/
rule stringSetEqualsExample{
    permit
    condition stringSetEquals(country, euCountries)
}

This example could serve as a quiz policy: access will be permitted if the user can provide the exact list of EU countries in the input bag, country.