<?xml version=“1.0” encoding=“UTF-8”?> <Policy xmlns=“urn:oasis:names:tc:xacml:1.0:policy”

xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
PolicyId="deny-d-objects-and-datastreams"
RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:first-applicable">
<Description>Deny access to any objects or datastreams in the "D" deleted state</Description>
<Target>
  <Subjects>
      <AnySubject/>
  </Subjects>
  <Resources>
    <Resource>
      <ResourceMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">D</AttributeValue>
        <ResourceAttributeDesignator DataType="http://www.w3.org/2001/XMLSchema#string"
          AttributeId="urn:fedora:names:fedora:2.1:resource:object:state" MustBePresent="false"/>
      </ResourceMatch>
    </Resource>
    <Resource>
      <ResourceMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">D</AttributeValue>
        <ResourceAttributeDesignator DataType="http://www.w3.org/2001/XMLSchema#string"
          AttributeId="urn:fedora:names:fedora:2.1:resource:datastream:state" MustBePresent="false"/>
      </ResourceMatch>
    </Resource>
  </Resources>
  <Actions>
    <AnyAction/>
  </Actions>
</Target>
<Rule RuleId="1" Effect="Deny"/>

</Policy>