From e3f6db78279600a78cca35af59f5125dd7a0d174 Mon Sep 17 00:00:00 2001 From: Lichen Dev Agent Date: Sun, 23 Aug 2026 01:31:39 +0000 Subject: [PATCH] Plan: document dev-only transition:generic scope + production requirement --- docs/open-wiki-plan.md | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/docs/open-wiki-plan.md b/docs/open-wiki-plan.md index edaeb58..1b7f56a 100644 --- a/docs/open-wiki-plan.md +++ b/docs/open-wiki-plan.md @@ -161,4 +161,18 @@ Owner/admin-only (`canManage`): 4. **Scope of "open":** only **public** wikis. **Confirmed.** 5. **Approvers:** owner + members with `admin` role (i.e. existing `canManage`). **Confirmed.** 6. **OAuth scope / lexicons:** verify no extra `wiki.lichen.permissions` scope change is needed - for the two new record types (check with `discover_permission_sets` before the lexicon work). \ No newline at end of file + for the two new record types (check with `discover_permission_sets` before the lexicon work). + +## 10. Dev/PoC OAuth scope (live instance) + +The two new record types (`wiki.lichen.contribution`, `wiki.lichen.contributionApproval`) were +added to `wiki.lichen.permissions`, but **the PDS did not honor the expanded permission-set** — +fresh logins still threw `ScopeMissingError` for `repo:wiki.lichen.contribution`. As a **dev-mode +escape hatch only**, the running instance requests **`transition:generic`** (full PDS write scope) +via `OAUTH_SCOPE` in `src/lib/collections.ts`, with a code comment marking it as dev-only. + +**Required before shipping / taking off the sandbox:** +- Publish the `wiki.lichen.permissions` permission-set properly so the PDS grants the granular + `repo:wiki.lichen.contribution?...` / `repo:wiki.lichen.contributionApproval?...` scopes, **and/or** +- Restrict the client to the minimal granular scopes instead of `transition:generic`. +- Remove `transition:generic` from `OAUTH_SCOPE` and confirm scopes via `discover_permission_sets`. \ No newline at end of file -- 2.51.2