Record
group.opensocial.access
Who may read this space, and what each role may do as the group in it.
Who may read this space. Present in every space under the group. The group authority issues space credentials according to this record and nothing else.
- Record key
"self"- Lives in
every space
Fields
readableByarray of stringrequiredRole ids that may read the space, or the literal string 'public' meaning any authenticated requester.
credentialScopesarray of #roleScopesWhich OAuth scopes for the group DID each role may request in this space.
createdAtstring · datetimerequiredDefinitions
#roleScopes object
rolestringrequiredA role id: the record key of a group.opensocial.role record.
≤ 64 bytes
scopesarray of stringrequiredSchema
Lexicon JSON
{
"lexicon": 1,
"id": "group.opensocial.access",
"defs": {
"main": {
"type": "record",
"key": "literal:self",
"description": "Who may read this space. Present in every space under the group. The group authority issues space credentials according to this record and nothing else.",
"record": {
"type": "object",
"required": [
"readableBy",
"createdAt"
],
"properties": {
"readableBy": {
"type": "array",
"items": {
"type": "string"
},
"description": "Role ids that may read the space, or the literal string 'public' meaning any authenticated requester."
},
"credentialScopes": {
"type": "array",
"items": {
"type": "ref",
"ref": "#roleScopes"
},
"description": "Which OAuth scopes for the group DID each role may request in this space."
},
"createdAt": {
"type": "string",
"format": "datetime"
}
}
}
},
"roleScopes": {
"type": "object",
"required": [
"role",
"scopes"
],
"properties": {
"role": {
"type": "string",
"maxLength": 64,
"description": "A role id: the record key of a group.opensocial.role record."
},
"scopes": {
"type": "array",
"items": {
"type": "string"
}
}
}
}
}
}