<?xml version="1.0" encoding="UTF-8"?>
<PolicySet PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:deny-overrides" 
    PolicySetId="urn:elga:bes:2013:1.2.3.2.2" xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="urn:oasis:names:tc:xacml:2.0:policy:schema:os http://docs.oasis-open.org/xacml/
    access_control-xacml-2.0-policy-schema-os.xsd">
    <Description>The individual policy, which contains information about reOptIn for services and deny for documents</Description>
    <Target/>
   <!--reOptIn Zeitstempel fuer den Service "eBefunde" -->
    <Policy PolicyId="urn:elga:bes:2013:1.2.3.2.2.2.1" 
        RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:first-applicable">
        <Target/>
        <Rule Effect="Deny" RuleId="urn:elga:bes:2013:1.2.3.2.2.2.1.1">
            <Target>
                <Resources>
                    <Resource>
                        <ResourceMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">101</AttributeValue>
                            <ResourceAttributeDesignator AttributeId="urn:elga:bes:2013:service" 
                                DataType="http://www.w3.org/2001/XMLSchema#string"/>
                        </ResourceMatch>
                    </Resource>
                </Resources>
            </Target>
            <Condition>
                <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:dateTime-less-than-or-equal">
                    <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:dateTime-one-and-only">
                        <ResourceAttributeDesignator AttributeId="urn:elga:bes:2013:xds-document-creation-date" 
                            DataType="http://www.w3.org/2001/XMLSchema#dateTime"/>
                    </Apply>
                    <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#dateTime">
                        2014-01-21T23:00:00.000Z</AttributeValue>
                </Apply>
            </Condition>
        </Rule>
        <Rule Effect="Permit" RuleId="urn:elga:bes:2013:permitrule"/>
    </Policy>
    <!-- Zeitstempel des Loeschens fuer den Service "eMedikation" -->
    <Policy PolicyId="urn:elga:bes:2013:1.2.3.2.2.2.2" RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:first-applicable">
        <Target/>
        <Rule Effect="Deny" RuleId="urn:elga:bes:2013:1.2.3.2.2.2.2.1">
            <Target>
                <Resources>
                    <Resource>
                        <ResourceMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                            <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">102</AttributeValue>
                            <ResourceAttributeDesignator AttributeId="urn:elga:bes:2013:service" 
                               DataType="http://www.w3.org/2001/XMLSchema#string"/>
                        </ResourceMatch>
                    </Resource>
                </Resources>
            </Target>
            <Condition>
                <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:dateTime-less-than-or-equal">
                    <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:dateTime-one-and-only">
                        <ResourceAttributeDesignator AttributeId="urn:elga:bes:2013:xds-document-creation-date" 
                            DataType="http://www.w3.org/2001/XMLSchema#dateTime"/>
                    </Apply>
                    <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#dateTime">
                        2014-05-02T18:00:00.000Z</AttributeValue>
                </Apply>
            </Condition>
        </Rule>
        <Rule Effect="Permit" RuleId="urn:elga:bes:2013:permitrule"/>
    </Policy>
    <!-- Auflistung aller Dokumente mittels setId, die ausgeblendet werden sollen -->
    <Policy PolicyId="urn:elga:bes:2013:1.2.3.2.2.2" 
        RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining- algorithm:permit-overrides" 
        xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os">
        <Target/>
        <Rule Effect="Deny" RuleId="urn:elga:bes:2013:denyrule">
            <Condition>
                <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-subset">
                    <ResourceAttributeDesignator AttributeId="urn:elga:bes:2013:xds:document-id" 
                        DataType="http://www.w3.org/2001/XMLSchema#string"/>
                    <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-bag">
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">
                            urn:uuid:24c8d24b-2afa-4458-b350-c81cd281b081^^^&amp;1.2.40.0.34.99.111.1.1&amp;ISO^
                                urn:elga:iti:xds:2014:ownDocument_setId^&amp;1.2.40.0.34.99.999&amp;ISO</AttributeValue>
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">
                            urn:uuid:25c8d24b-2afa-4458-b350-c81cd281b082^^^&amp;1.2.40.0.34.99.111.1.1&amp;ISO^
                                urn:elga:iti:xds:2014:ownDocument_setId^&amp;1.2.40.0.34.99.999&amp;ISO</AttributeValue>
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">
                            urn:uuid:26c8d24b-2afa-4458-b350-c81cd281b083^^^&amp;1.2.40.0.34.99.111.1.1&amp;ISO^
                                urn:elga:iti:xds:2014:ownDocument_setId^&amp;1.2.40.0.34.99.999&amp;ISO</AttributeValue>
                    </Apply>
                </Apply>
            </Condition>
        </Rule>
    </Policy>
    <!-- Auflistung aller Dokumente mittels setId, die geloescht werden/wurden -->
    <Policy PolicyId=" urn:elga:bes:2013:1.2.3.2.2.3"
        RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining- algorithm:permit-overrides" 
        xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os">
        <Target/>
        <Rule Effect="Deny" RuleId="urn:elga:bes:2013:denyrule">
            <Condition>
                <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-subset">
                    <ResourceAttributeDesignator AttributeId="urn:elga:bes:2013:xds:document-id" 
                        DataType="http://www.w3.org/2001/XMLSchema#string"/>
                    <Apply FunctionId="urn:oasis:names:tc:xacml:1.0:function:string-bag">
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">
                            urn:uuid:27c8d24b-2afa-4458-b350-c81cd281b084^^^&amp;1.2.40.0.34.99.111.1.1&amp;ISO^
                                urn:elga:iti:xds:2014:ownDocument_setId^&amp;1.2.40.0.34.99.999&amp;ISO</AttributeValue>
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">
                            urn:uuid:28c8d24b-2afa-4458-b350-c81cd281b085^^^&amp;1.2.40.0.34.99.111.1.1&amp;ISO^
                                urn:elga:iti:xds:2014:ownDocument_setId^&amp;1.2.40.0.34.99.999&amp;ISO</AttributeValue>
                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">
                            urn:uuid:29c8d24b-2afa-4458-b350-c81cd281b086^^^&amp;1.2.40.0.34.99.111.1.1&amp;ISO^
                                urn:elga:iti:xds:2014:ownDocument_setId^&amp;1.2.40.0.34.99.999&amp;ISO</AttributeValue>
                    </Apply>
                </Apply>
            </Condition>
        </Rule>
    </Policy>
</PolicySet>
