[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: The <any/> element: bane of security or savior of versioni

  • From: noah_mendelsohn@u...
  • To: "Stephen Green" <stephengreenubl@g...>
  • Date: Fri, 19 Oct 2007 16:06:31 -0400

Re:  The <any/> element: bane of security or savior of versioni
Stephen Green writes:

> Interestingly, in UBL the 'any' is inside an optional construct
> so parties concerned it might pose some problems for software 
> weaknesses or security can just impose a subsetting profile 
> which eliminates its use from their transactions.

I haven't looked at the UBL language lately, and don't remember the 
details, but during our discussions of XSD 1.1 I suggested a design goal 
which I think got some serious attention:  whatever constructs we provide 
for versioning should scale to the case where there are many revisions. 
Question:  if the content within that optional construct is later revised, 
does that second revision get wrapped in yet another such construct?  If 
there are 50 revisions, can you wind up with 49 nested "extension" 
elements, and the requirement to know how deep down each such extension 
goes?

This is not a critique of UBL.  My impression is that it has been designed 
with great care and insight.  I have seen other more naive proposals for 
"extension" elements.  They tend to have the advantage that you know where 
the extension content is, and the disadvantages that a) they are somewhat 
clumsy in the instance (would you want to wrap your HTML <img> tags in 
<extension> elements? and b) as noted above, it's not always clear how to 
scale them to multiple revisions.  Overall, I tend to prefer various 
flavors of open content.

Noah

--------------------------------------
Noah Mendelsohn 
IBM Corporation
One Rogers Street
Cambridge, MA 02142
1-617-693-4036
--------------------------------------






[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.