diff --git a/docs/open-wiki-plan.md b/docs/open-wiki-plan.md index edaeb58..1b7f56a 100644 --- a/docs/open-wiki-plan.md +++ b/docs/open-wiki-plan.md @@ -161,4 +161,18 @@ Owner/admin-only (`canManage`): 4. **Scope of "open":** only **public** wikis. **Confirmed.** 5. **Approvers:** owner + members with `admin` role (i.e. existing `canManage`). **Confirmed.** 6. **OAuth scope / lexicons:** verify no extra `wiki.lichen.permissions` scope change is needed - for the two new record types (check with `discover_permission_sets` before the lexicon work). \ No newline at end of file + for the two new record types (check with `discover_permission_sets` before the lexicon work). + +## 10. Dev/PoC OAuth scope (live instance) + +The two new record types (`wiki.lichen.contribution`, `wiki.lichen.contributionApproval`) were +added to `wiki.lichen.permissions`, but **the PDS did not honor the expanded permission-set** — +fresh logins still threw `ScopeMissingError` for `repo:wiki.lichen.contribution`. As a **dev-mode +escape hatch only**, the running instance requests **`transition:generic`** (full PDS write scope) +via `OAUTH_SCOPE` in `src/lib/collections.ts`, with a code comment marking it as dev-only. + +**Required before shipping / taking off the sandbox:** +- Publish the `wiki.lichen.permissions` permission-set properly so the PDS grants the granular + `repo:wiki.lichen.contribution?...` / `repo:wiki.lichen.contributionApproval?...` scopes, **and/or** +- Restrict the client to the minimal granular scopes instead of `transition:generic`. +- Remove `transition:generic` from `OAUTH_SCOPE` and confirm scopes via `discover_permission_sets`. \ No newline at end of file