Membership
Membership is two-sided. The group grants roles with a membership record, and the member confirms with an acceptance record of their own.
Membership is defined bidirectionally. The group creates a membership record in the members space, and the member in turn creates an acceptance record in the same space.
The group writes
membership
key = member's DID
roles: [member, …]
members space
Both halves → a member
The member writes
acceptance
key = self
from their own account
The group’s side: membership
Written by the group authority, keyed by the member’s DID, and listing the member’s roles. This is what grants access. Every read of a space, every role check and every permission to act as the group comes from this record.
It is written when someone is admitted, redeems an invite or joins an open group, and it is rewritten by assignRoles. It is deleted when the member leaves or is ejected.
The member’s side: acceptance
Written by the member, from their own account, into the group’s members space. It is the member agreeing that they belong. It gates whether the member appears in the roster, not what they can access.
A member whose membership exists but who hasn’t written an acceptance has full access. They just aren’t listed. And nobody can put someone on a group’s roster without that person’s consent.
Finding a person’s groups
The acceptance is stored where everything a person writes into a space is stored: on their own PDS. An app answers “which groups am I in?” by asking the person’s PDS which spaces of type group.opensocial.members they have records in. It doesn’t need to crawl groups or read a public roster.
No public roster
There is no public member list. Who is in a group is visible only to those who can read its members space, which is usually members.
Leaving and ejection
leaveGroup: a member removes themselves. No role needed.ejectMember: requireseject, limited to the roles in the caller’sassignablelist.
Both delete the membership record, which ends access. A member’s acceptance is theirs, and only they can delete it.