In the call today, George brought up UMA as the authorization manager 
for an XRD file.

This intrigued me because this is not a simple binary protection. It 
wasn't about either granting or denying access to an XRD. It was about 
modulating the XRD file for certain users. That is, Bob may get one set 
of resources in the XRD and Sally gets a different set of links in the 
XRD sent to her.

Dynamically generating an XRD isn't particularly hard... it is the same 
as any dynamically generated web resource.

But we, the UMA work group, haven't really discussed how an AM might 
participate in modulating dynamic generation of resources. We have 
presumed access is all or nothing.

I'm guessing this is a "deferred" use case, as it is intriguing, but 
probably extending the scope beyond what we want to address in UMA 1.0.



