Record
group.opensocial.permissions
Binds roles to actions and bounds role.assign.
The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.
- Record key
"self"- Lives in
members
Fields
createdAtstring · datetimerequiredDefinitions
#binding object
rolestringrequiredA role id: the record key of a group.opensocial.role record.
assignablearray of stringFor role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none.
repoCollectionsarray of stringCollections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead.
#action string
mod.readmod.resolvelabeltakedowninviteadmitejectrole.assignspace.createspace.configurespace.deletegroup.configure
Schema
Lexicon JSON
{
"lexicon": 1,
"id": "group.opensocial.permissions",
"defs": {
"main": {
"type": "record",
"key": "literal:self",
"description": "The group's authorization config. Binds each role to a set of standardized actions and bounds role.assign and eject. Roles compose by union; there are no deny rules.",
"record": {
"type": "object",
"required": [
"bindings",
"createdAt"
],
"properties": {
"bindings": {
"type": "array",
"items": {
"type": "ref",
"ref": "#binding"
}
},
"createdAt": {
"type": "string",
"format": "datetime"
}
}
}
},
"binding": {
"type": "object",
"required": [
"role",
"actions"
],
"properties": {
"role": {
"type": "string",
"maxLength": 64,
"description": "A role id: the record key of a group.opensocial.role record."
},
"actions": {
"type": "array",
"items": {
"type": "ref",
"ref": "#action"
}
},
"assignable": {
"type": "array",
"items": {
"type": "string",
"maxLength": 64,
"description": "A role id: the record key of a group.opensocial.role record."
},
"description": "For role.assign and eject: the roles this role may grant, revoke, or eject. Absent means none."
},
"repoCollections": {
"type": "array",
"items": {
"type": "string"
},
"description": "Collections a holder of this role may write in the group's public repo when acting as the group (signed in as it through an app). '*' for any. Absent means any for a role that holds group.configure, and none otherwise. Writes into the group's spaces are governed by each space's access record instead."
}
}
},
"action": {
"type": "string",
"knownValues": [
"mod.read",
"mod.resolve",
"label",
"takedown",
"invite",
"admit",
"eject",
"role.assign",
"space.create",
"space.configure",
"space.delete",
"group.configure"
]
}
}
}