Public links

Design of record for MeshWeaver#4306. A page that lives in a space can be read only by whoever the space's grants admit. Sharing it used to mean copying it somewhere else and granting there — two copies that drift, and a grant wider than intended. A link shares the page itself.

Two shapes, one node type

Essentials/Link carries LinkContent { target, publicId?, audience?, expiresAt?, note, delegatedBy, approvedBy, governedBy, revokedAt, revokedBy }. A public link's node is readable by its audience, so the governed executor writes no note on it: the proposal's rationale stays on the activity its governedBy names.

Global link Public link
Where anywhere a person can write — a home, a space, a course l/{publicId}, the platform-owned l partition — so the URL is /l/{publicId} and no route exists for it
Written by anyone ONLY the governed executor CreateLink (link.publish)
Who opens it whoever can read the link node its audience: anonymous, signed-in (Public) or a group path
What it shows a link through to the target's own page — opened from the TARGET's hub, as the viewer the target node itself — its name and markdown body — read on the LINK's hub as System after the checks below
Grants none one Viewer grant for the audience, on the link node only

The delegated read

A public link is a read that outlives the session that created it, so every clause of it is checked where it is served — LinkProjection (the data half; LinkLayoutAreas is the template bound to it), at every render and on every change of the target:

  1. The link node was written by the platform (lastModifiedBy = System). The l partition grants nobody write access, and a person's write would restamp the author — so a link node a person managed to write serves nothing, whatever it says.
  2. It is neither revoked nor expired. An expiry is required and capped at 366 days.
  3. The person whose read it delegates (delegatedBy, the proposer) STILL holds Read on the target. Losing that right ends the link at the next render. The target's grants are never touched.
  4. The VIEWER still holds Read on the link node itself. The audience grant (a group membership above all) is what admitted the viewer, and the target is read as System, so this is a live input like the delegator's right: a viewer removed from the audience while the page is open loses it at once, and the System read of the target closes for that viewer.
  5. Only then is the target read, and only the target node: no child, no satellite. Its markdown body is made INERT first — an executable fence (--execute / --render) becomes a plain code block, because the target's author wrote it and the view would otherwise run it on the visitor's first render AS THE VISITOR (LinkProjection.Inert, which fails closed: a body in which any fence would still execute is not shown). An area embedded in the body is fetched by the visitor's own client as the visitor, resolved against the TARGET's path — the projection writes every relative reference and link absolute under the target (LinkProjection.Anchored), so the page is a template emitted at once and nothing in it can resolve under the link — and it is refused to anyone the target's grants do not admit.

Every refusal the link page decides — expired, the delegator's right lapsed, not issued by the platform — renders the same line, so a visitor cannot tell those apart. A REVOKED link has its audience grant deleted, so the visitor is refused before the page renders at all — exactly as for a link that never existed. (A visitor who saw the page already knows its expiry from the byline, so revoked-versus-expired was never a secret worth keeping the grant for.)

Governed creation and revocation

Org-wide audiences: `Groups/

Group memberships resolve GLOBALLY — the permission evaluator reads every GroupMembership in the mesh and expands the viewer's transitive groups (core PermissionEvaluator, "Group access is resolved GLOBALLY"), so a group defined in one partition is honoured on a grant in another. An org-wide audience therefore needs no new access rule, only a home for the org's group: the Groups partition, one Group node per organisation (Groups/{org}). The governed standard group.org-create creates it: one signature by a GLOBAL ADMIN (re-checked by CreateOrgGroup), then the platform-owned Groups root, the Group node and an Admin grant on that group node alone for the proposer, who then adds members as GroupMembership children. A public link whose audience is Groups/{org} grants that group Viewer on the link node, exactly like any other audience.

group.org-create CREATES a group and never adds a manager to an existing one: a proposal for an org whose group someone else already administers is refused naming the grants, because Admin on a group edits its memberships and those reach every grant that names the group. Only a group nobody administers yet (a create whose manager grant was never written) or the proposer's own (a repeated run) is taken up, and its node is not rewritten.

An org id is 1–64 ASCII letters, digits, - or _, and never SATELLITE-shaped (an underscore followed by an upper-case letter): Groups/_Policy and Groups/_Access are the partition's own governance slots, and the platform files every id of that shape as a satellite of Groups rather than as a group. The same shape is excluded from a link's public id — such a draw is discarded and drawn again — because a link filed as a satellite of l would leave the main-node listings the audit of published links reads.

Where it lives