The subject is the named node and, unless exact is true, every node in its subtree now and later; naming no node means the space root, which covers the whole space.
Fields
Rules
Subtree coverage is evaluated against the placement tree at evaluation time, so authority follows moves. exact exists for sharing one page out of a folder without its children. A node's own grants and the grants on its ancestors together form its covering grants, which the readers and write checks consume. Because a node id is the CID of a blob that already exists, a grant can only name a node that has been created; an invitation to content that does not exist yet is a grant on the parent under which it will be created, or on the space root.
A grant with write on a node is what lets a key that does not own the space create nodes under it: the new Node blob names the owner in space and this grant in proof.
Today (HM24)
The path of a Capability, covering the path and everything beneath it by segment. The is_exact and no_recursive flags were declared and never implemented; exact is their replacement, defined against ids.
Example
The whole space:
{"kind": "node", "space": {"/": {"bytes": "7QEE...Starlight"}}}One document and its subtree:
{"kind": "node", "space": {"/": {"bytes": "7QEE...Starlight"}}, "node": "bafyreiujzdegxdncf32epf3dhodzdocis2jhtlgmxgedn73u55xtplpft7"}Do you like what you are reading? Subscribe to receive updates.
Unsubscribe anytime