I attach a sample policy.
To make it work,
1. the resolution path of policy needs to be /lac/*
otherwise you need to change the regex in the policy
2. change the context variable lachost to your lac server hostname and port.
3. the simple policy doesn't url-encode the parameters, so when the client(such as a browser) send the request, it needs to be url-encoded, like this,