diff --git a/src/possum/oauth/permission.gleam b/src/possum/oauth/permission.gleam deleted file mode 100644 index 5c58fa5..0000000 --- a/src/possum/oauth/permission.gleam +++ /dev/null @@ -1,108 +0,0 @@ -//// Control over atproto resources is described and granted using "permissions". -//// A group of a permissions related to a specific Lexicon namespace -//// (record types and API endpoints) can be bundled together as a "permission set". -//// Both are used in the context of OAuth to grant client software access -//// to account resources on a PDS. For example, the ability to write records -//// of specific types to the user's public repository, or make authenticated -//// API requests to remote services. Developers declare the permissions their -//// app requires to function, and end users are shown the permissions -//// when granting access to the app. -//// -//// Each resource type has a defined set of parameters that can attenuate -//// the permission. A permission can be represented in a string format -//// (for direct use as an OAuth scope), or as a JSON object -//// (for use in permission sets). Permission sets are published as public -//// lexicon schemas, and are constrained in scope to named resources under -//// the same NSID hierarchy as the NSID of the permission set itself. -//// -//// Docs: [Permissions](https://atproto.com/specs/permission) - -import gleam/option - -/// Permissions relate to user owned resources on PDS instances -pub type Resource { - /// Write access to records in the account's public repository. - /// Can be limited to specific record types (collections) or actions (eg update vs delete). - /// - /// ## Examples - /// - /// ```gleam - /// import possum/oauth/permission - /// - /// // Full permission (create, update, delete) on a single record type - /// // > repo:app.example.profile - /// permission.Repo(collection: ["app.example.profile"], action: []) - /// - /// // Same as above, with actions being explicit - /// // > repo:app.example.profile?action=create&action=update&action=delete - /// permission.Repo( - /// collection: ["app.example.profile"], - /// action: ["create", "update", "delete"] - /// ) - /// - /// // Full permissions on multiple record types - /// // > repo?collection=app.example.profile&collection=app.example.post - /// permission.Repo( - /// collection: ["app.example.profile", "app.example.post"], - /// action: ["create", "update", "delete"] - /// ) - /// ``` - Repo( - /// NSID of record types. - /// Namespaced IDentifiers, an identifier format used in the Atmosphere - /// to identify Lexicon schemas. Partial wildcards are not supported - collection: List(String), - /// Allowed values are `create`, `update`, `delete`. - /// If empty, all operations are allowed. - action: List(String), - ) - - /// Service Authentication (API calls to external services) - Rpc( - /// Remote endpoint (lxm, short for "Lexicon Method") - lxm: List(String), - /// Audience of API requests. - /// As a DID service reference: DID followed by required service type fragment, - /// eg did:web:api.example.com#srvtype). - aud: String, - /// Only used inside permission sets. - /// If true, an aud value will be inherited from the include: invocation, - /// and the `aud` field is not required on the permission. - inherit_aud: option.Option(Bool), - ) - - /// Ability to upload media files (blobs) to PDS. - /// Permissions of this type can not be included in permission sets, - /// and must be requested directly by client apps. - /// - /// MIME types or partial MIME type glob patterns (\*/\* or text/\* for example). - /// Same syntax as the accept field in the blob lexicon type. - /// - /// ## Examples - /// - /// ```gleam - /// // Upload any type of blob - /// permission.Blob(accept: ["*/*"]) - /// - /// - /// // Upload video or html - /// permission.Blob(accept: ["video/*", "text/html"]) - /// ``` - Blob(accept: List(String)) - - // TODO: - Account - - /// Control over network identity, meaning the account DID document and handle. - /// - /// ## Examples - /// - /// ```gleam - /// // Update account handle - /// permission.Identity(attr: "handle") - /// - /// // Full control over DID Document - /// permission.Identity(attr: "*") - /// ``` - Identity(attr: String) -}