Audience
The set of principals a grant speaks about, written as one of five kinds, everyone, a key, a group, a bearer secret, or the readers of another node.
Fetching schema…

Part of Stem. This page defines audience, the field of a Grant that names who receives access. It is a union of five closed structs discriminated by kind.

An audience is a rule for deciding whether a principal is in a set, evaluated by the peer at read time.

Variants

kind

page

the set is

everyone

everyone

every peer, authenticated or not

key

key

one principal

group

group

the live members of a Group

bearer

bearer

whoever presents the secret whose hash is stored

readers

readers

whoever can read another node, now

Rules

An audience never appears on its own; it is always the audience of a grant, and a node's readers are the union of the audiences of the live grants that cover it, plus the owner and admins, plus whatever the node's access mode adds. Membership of group and readers audiences is late-bound: it is recomputed whenever the graph changes, so removing someone from a group or narrowing a document's readers takes effect everywhere at once. everyone is how content becomes public, and a space that has no everyone grant on its root is private by default. The word audience in HM24 named the server a short-lived authentication capability was addressed to; Stem uses it only in this sense.

Today (HM24)

Two hard-coded audiences exist: everyone (visibility empty, a blob_visibility row with space 0) and the owner-plus-root-writers of a space (visibility Private). Sharing with one outsider or by link cannot be said. The five kinds here are the generalisation the permissions investigation called "everything is a grant".

Example

{"kind": "readers", "of": {"space": {"/": {"bytes": "7QEE...Starlight"}}, "node": "bafyreiujzdegxdncf32epf3dhodzdocis2jhtlgmxgedn73u55xtplpft7"}}

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime