RPC: Access
Explains what access a principal has to a scope and through which grants, using the same evaluator that gates every read and write.
Fetching schema…

Part of Stem. This page defines the Access method of the sync RPC specification. It makes the authority graph inspectable.

The formal schema is attached as the schemaDefinition of this page: a struct {key, input, output} with key pinned to Access.

Explains what access a principal has to a scope and through which grants. The same evaluator that gates every read and write answers this call.

Input

field

type

required

meaning

scope

data/scope

yes

What to check.

principal

principal

no

Who to check. Omitted means an unauthenticated peer.

Output

The output is rpc/type/access-report.

Rules

    Evaluates the authority graph for scope's node and returns the live level of principal (null for none) and the chain of Grant CIDs that gives it, from the grant signed by the owner down to the one naming the principal or a group it belongs to.

    With no principal, evaluates an unauthenticated peer: level is read when the node is readable by everyone, else null.

    public reports whether the node's readers include everyone, independent of the principal.

    The method reads the local index only; it does not contact peers and does not count as a disclosure.

    A client may call it for any principal, including one that does not exist; the answer is then null.

Today (HM24)

HM24 exposes AccessControl.ListCapabilities and ListCapabilitiesForDelegate, which list raw capability blobs and leave the two-step authorization rule to the reader; the web ListDocumentCollaborators key derives members from capabilities and contacts. Nothing answers "why can this key read this" today.

Example

{"key": "Access", "input": {"scope": {"space": {"/": {"bytes": "7QEA…"}}, "node": "bafyrein6a6wfhym6l3vfz5zfkkibj5j6wjibagi3mnbqnspuq2idw52ijb", "depth": "subtree"}, "principal": {"/": {"bytes": "7QEC44…"}}}}
{"principal": {"/": {"bytes": "7QEC44…"}}, "scope": {"space": {"/": {"bytes": "7QEA…"}}, "node": "bafyrein6a6wfhym6l3vfz5zfkkibj5j6wjibagi3mnbqnspuq2idw52ijb", "depth": "subtree"}, "level": "write", "via": [{"/": "bafy…g0"}, {"/": "bafy…g1"}], "public": false}

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime