fyi.opensocial.permissions

lexicons.opensocial.fyi

Documentation

The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.

main record

The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.

Record Key literal:self Fixed literal value

Properties

bindings array of ref #binding Required

No description available.

createdAt string datetime Required

An RFC 3339 formatted timestamp.

View raw schema
{
  "description": "The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.",
  "key": "literal:self",
  "record": {
    "properties": {
      "bindings": {
        "items": {
          "ref": "#binding",
          "type": "ref"
        },
        "type": "array"
      },
      "createdAt": {
        "format": "datetime",
        "type": "string"
      }
    },
    "required": [
      "bindings",
      "createdAt"
    ],
    "type": "object"
  },
  "type": "record"
}
action string

No description available.

Known Values (other values may be valid)
mod.read mod.resolve label takedown invite admit eject role.assign space.create space.configure space.delete group.configure
View raw schema
{
  "knownValues": [
    "mod.read",
    "mod.resolve",
    "label",
    "takedown",
    "invite",
    "admit",
    "eject",
    "role.assign",
    "space.create",
    "space.configure",
    "space.delete",
    "group.configure"
  ],
  "type": "string"
}
binding object

No description available.

Properties

actions array of ref#action Required

No description available.

assignable array of string Optional

For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none.

repoCollections array of string Optional

Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead.

role string Required

A role id: the record key of a fyi.opensocial.role record.

maxLength: 64 bytes
View raw schema
{
  "properties": {
    "actions": {
      "items": {
        "ref": "#action",
        "type": "ref"
      },
      "type": "array"
    },
    "assignable": {
      "description": "For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none.",
      "items": {
        "description": "A role id: the record key of a fyi.opensocial.role record.",
        "maxLength": 64,
        "type": "string"
      },
      "type": "array"
    },
    "repoCollections": {
      "description": "Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead.",
      "items": {
        "type": "string"
      },
      "type": "array"
    },
    "role": {
      "description": "A role id: the record key of a fyi.opensocial.role record.",
      "maxLength": 64,
      "type": "string"
    }
  },
  "required": [
    "role",
    "actions"
  ],
  "type": "object"
}

Lexicon Garden

@