x500NameSetEquals Function Description
Description
This method returns true if both sets of attribute values of type x500Name are equal. Technically, it uses the subset function on the first and second arguments ANDed with the subset function and the second and first argument. Note that duplicate values have no impact on the comparison. For instance, the following 2 sets are equal: [a,a,c,b] and [b,c,a,c].
x500NameSetEquals belongs to the ALFA function reference's
Set functions category. It maps to the XACML function identifier
urn:oasis:names:tc:xacml:1.0:function:x500Name-set-equals, takes 2 arguments and returns a value of type boolean.
| Property | Value |
|---|---|
| Category | Set functions |
| # Arguments | 2 |
| Arguments |
|
| Return Value | boolean |
| Expressed As | pre-fix |
| Representation | ALFA short name |
| Allowed In Target | false |
| ALFA Shorthand | None |
| Commutative | true |
Example
/**
* Allow if all the team members are internal users and all internal users are team members
*/
rule x500NameSetEqualsExample{
permit
condition x500NameSetEquals(team.members, internalUsers)
}
Permit if all the team members are internal users and all the internal users are team members. In other words, both populations are identical.
Related Functions
Other functions in the Set functions category: