Skip to content

Return 'wac-allowed' HTTP header with GET & HEAD responses #246

Description

@dmitrizagidulin

Problem/Motivation

There is currently no easy way for solid client code to determine if the current user has read/write/delete etc access to a given resource (short of reading and parsing the ACL chain, which is both discouraged, and not always possible due to ACL limitations on the .acl files themselves). (See solid/#45 - No way to find out if user is authorized to write to a container for context.)

Proposed Solution

An easy solution to this would be to add support to LDNode for the following:

With every response, the server should include an additional WAC-Allowe: header in the HTTP response.

For example, doing an unauthenticated HEAD request on a public read-only resource, would yield:

WAC-Allow: user="read", public="read"

Doing an HEAD request (while authenticated) to a resource you have full read/write/control access to:

WAC-Allow: user="read;write;control", public=""

(Note the public="" part -- the empty string denotes no access.)

Activity

  1. dmitrizagidulin commented on Feb 24, 2016

    @dmitrizagidulin
    ContributorAuthor

    Updated issue to use Allow: header instead of CORS Allow-Methods

  2. changed the title [-]Support `Access-Control-*-Methods` semantics for pre-flight requests[/-] [+]Implement ACL checks for the `Allow:` header[/+] on Feb 24, 2016
  3. rhiaro commented on Apr 7, 2016

    @rhiaro

    +1

  4. changed the title [-]Implement ACL checks for the `Allow:` header[/-] [+]Return 'wac-modes-allowed' HTTP header with GET & HEAD responses[/+] on Jan 4, 2017
  5. dmitrizagidulin commented on Jan 4, 2017

    @dmitrizagidulin
    ContributorAuthor

    Updated to use a custom WAC-Modes-Allowed HTTP header instead of Allow (which sounds like isn't appropriate for authentication-related matters).

  6. dmitrizagidulin commented on Feb 6, 2017

    @dmitrizagidulin
    ContributorAuthor

    Updated it to reflect today's design discussion; return both the permissions of the user, and public permissions.

  7. changed the title [-]Return 'wac-modes-allowed' HTTP header with GET & HEAD responses[/-] [+]Return 'wac-allowed' HTTP header with GET & HEAD responses[/+] on Aug 16, 2017
  8. added this to the 4.0.0 milestone on Aug 16, 2017
  9. added a commit that references this issue on Aug 17, 2017
    e2824fb
  10. RubenVerborgh commented on Aug 17, 2017

    @RubenVerborgh
    Contributor

    Implemented by #550.

  11. added 5 commits that reference this issue on Aug 17, 2017
    3cb4933
    e7e7911
    b792b9a
    250e513
    4b6a381
  12. added a commit that references this issue on Aug 18, 2017
    2b8f18b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions