MenuSpaces & records

Record

group.opensocial.permissions

Binds roles to actions and bounds role.assign.

The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.

Record key
"self"
Lives in
members

Fields

bindingsarray of #bindingrequired
createdAtstring · datetimerequired

Definitions

#binding object

rolestringrequired

A role id: the record key of a group.opensocial.role record.

≤ 64 bytes
actionsarray of #actionrequired
assignablearray of string

For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none.

≤ 64 bytes
repoCollectionsarray of string

Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead.

#action string

mod.readmod.resolvelabeltakedowninviteadmitejectrole.assignspace.createspace.configurespace.deletegroup.configure

Schema

Lexicon JSON
{
  "lexicon": 1,
  "id": "group.opensocial.permissions",
  "defs": {
    "main": {
      "type": "record",
      "key": "literal:self",
      "description": "The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.",
      "record": {
        "type": "object",
        "required": [
          "bindings",
          "createdAt"
        ],
        "properties": {
          "bindings": {
            "type": "array",
            "items": {
              "type": "ref",
              "ref": "#binding"
            }
          },
          "createdAt": {
            "type": "string",
            "format": "datetime"
          }
        }
      }
    },
    "binding": {
      "type": "object",
      "required": [
        "role",
        "actions"
      ],
      "properties": {
        "role": {
          "type": "string",
          "maxLength": 64,
          "description": "A role id: the record key of a group.opensocial.role record."
        },
        "actions": {
          "type": "array",
          "items": {
            "type": "ref",
            "ref": "#action"
          }
        },
        "assignable": {
          "type": "array",
          "items": {
            "type": "string",
            "maxLength": 64,
            "description": "A role id: the record key of a group.opensocial.role record."
          },
          "description": "For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none."
        },
        "repoCollections": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead."
        }
      }
    },
    "action": {
      "type": "string",
      "knownValues": [
        "mod.read",
        "mod.resolve",
        "label",
        "takedown",
        "invite",
        "admit",
        "eject",
        "role.assign",
        "space.create",
        "space.configure",
        "space.delete",
        "group.configure"
      ]
    }
  }
}

← All spaces and records