x500NameSetEquals Function Description

Description

This method returns true if both sets of attribute values of type x500Name are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c].

x500NameSetEquals belongs to the ALFA function reference's Set functions category. It maps to the XACML function identifier urn:oasis:names:tc:xacml:1.0:function:x500Name-set-equals, takes 2 arguments and returns a value of type boolean.

Property Value
Category Set functions
# Arguments 2
Arguments
  • A bag of type x500Name
  • A bag of type x500Name
Return Value boolean
Expressed As pre-fix
Representation ALFA short name
Allowed In Target false
ALFA Shorthand None
Commutative true

Example

/**
* Allow if all the team members are internal users and all internal users are team members
*/
rule x500NameSetEqualsExample{
    permit
    condition x500NameSetEquals(team.members, internalUsers)
}

Permit if all the team members are internal users and all the internal users are team members. In other words, both populations are identical.