# Programmatically adjust ACL

**URL:** <https://forum.solidproject.org/t/programmatically-adjust-acl/3232>\
**Category:** General Discussion\
**Created:** [June 20, 2020, 3:25pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232 "2020-06-20T15:25:47Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [June 20, 2020, 3:25pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/1 "2020-06-20T15:25:48Z")

</div>

What is the state of the art way of adjusting resource ACL nowadays? Are we still supposed to do low level operations with solid-auth-client, or is there some library that can do the following:

> 1. Create new ACL for `file.ttl`, applying all permissions from parent ACL
> 2. Add public append permission to `file.ttl` keeping everything else as is.

---

<div class="post-metadata">

**Author:** ![Smag0](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/smag0/32/310_2.png) [@Smag0](https://forum.solidproject.org/u/Smag0)\
**Post date:** [June 22, 2020, 9:32am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/2 "2020-06-22T09:32:58Z")

</div>

The more advanced & friendly I saw is @A_A  
[https://github.com/Otto-AA/solid-acl-parser](https://github.com/Otto-AA/solid-acl-parser)

---

<div class="post-metadata">

**Author:** ![A\_A](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/a_a/32/786_2.png) [@A\_A](https://forum.solidproject.org/u/A_A)\
**Post date:** [June 22, 2020, 10:00am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/3 "2020-06-22T10:00:34Z")

</div>

You could use the libraries I’ve written for that, but keep in mind that they are not maintained (at least by me). Also the documentation isn’t that good and doesn’t reflect everything it can do iirc.

With [solid-acl-parser](https://github.com/Otto-AA/solid-acl-parser) you can read turtle strings into an object, modify it there with a simple API, and parse it back to turtle. Here’s a simple example (more documentation is [here](https://otto-aa.github.io/solid-acl-parser/#/quickstart)):

```javascript
  // Parse the turtle to an AclDoc object which we can modify
  const parser = new AclParser({ aclUrl, fileUrl })
  const doc = await parser.turtleToAclDoc(turtleString)

  // Give the webId WRITE and CONTROL permissions
  doc.addRule([WRITE, CONTROL], webId)
// or in your case: doc.addRule(APPEND, Agents.PUBLIC)

  // Parse it back to turtle so we can store it in the pod
  const newTurtle = await parser.aclDocToTurtle(doc)

```

And if you also don’t want to manually fetch and save the acl file, I’ve written a wrapper [solid-acl-utils](https://github.com/Otto-AA/solid-acl-utils) which does that for you:

```javascript
const aclApi = new AclApi(fetch, { autoSave: false }) // create one per acl file you want to modify
const acl = aclApi.loadFromFileUrl('https://pod.example.org/file.ttl')

acl.addRule([READ, WRITE], webId)
acl.addRule(READ, Agents.PUBLIC)

await acl.saveToPod()

```

These should make it rather simple to modify acl files, but as said above: I’m not going to maintain it, some things may be broken (though I’ve written tests for everything which came into my mind).

---

<div class="post-metadata">

**Author:** ![Smag0](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/smag0/32/310_2.png) [@Smag0](https://forum.solidproject.org/u/Smag0)\
**Post date:** [June 22, 2020, 10:06am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/4 "2020-06-22T10:06:42Z")

</div>

Even if not maintained, that’s a good starting point that helped me to understand & deal with Acl 👍💪😊

@aveltens how I use it for inbox for example

> <https://github.com/scenaristeur/agora/blob/master/src/views/config-get-view.js>

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [June 23, 2020, 7:04am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/5 "2020-06-23T07:04:56Z")

</div>

This looks really great and seams to do what I was looking for. Will give it a try.

Sad to hear, that you are not going to maintain it. Perhaps we should move it to the solid github org and ensure it is maintained by the community?

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [June 23, 2020, 7:08am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/6 "2020-06-23T07:08:45Z")

</div>

> <https://github.com/scenaristeur/agora/blob/master/src/views/config-get-view.js#L32>

Looks like you are assuming a specific WebID structure here, which will bring problems to people with different URI structure.

---

<div class="post-metadata">

**Author:** ![Smag0](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/smag0/32/310_2.png) [@Smag0](https://forum.solidproject.org/u/Smag0)\
**Post date:** [June 23, 2020, 7:12am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/7 "2020-06-23T07:12:06Z")

</div>

You are right ,thxxs it just a copy/paste from an Acl file to start something but can be improved

---

<div class="post-metadata">

**Author:** ![A\_A](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/a_a/32/786_2.png) [@A\_A](https://forum.solidproject.org/u/A_A)\
**Post date:** [June 23, 2020, 11:56am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/8 "2020-06-23T11:56:16Z")

</div>

> [@aveltens](#):
>
> Sad to hear, that you are not going to maintain it. Perhaps we should move it to the solid github org and ensure it is maintained by the community?

Sure, if somebody wants to keep it up to date and fix things when issues arise, I think it would be good to transfer it. I just don’t have the time to maintain this project, but I’d be happy if someone else forks it and takes care about it. I could also remove the solid-acl-parser on npm in favor of newer versions.

If this is done, it would probably also make sense to look if the databrowser could use it too. Currently it uses its own implementation iirc. Merging them to one would probably make sense

---

<div class="post-metadata">

**Author:** ![A\_A](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/a_a/32/786_2.png) [@A\_A](https://forum.solidproject.org/u/A_A)\
**Post date:** [June 23, 2020, 12:04pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/9 "2020-06-23T12:04:44Z")

</div>

I also want to note, that my implementation is just one way of doing this. It parses the whole acl file into an object, modifies it, and parses it back. Another way would be to use a library to directly manipulate the turtle (e.g. with SPARQL statements)

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [June 30, 2020, 7:16pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/10 "2020-06-30T19:16:28Z")

</div>

Hey @A_A I had some time to try your lib and it is exactly what I was looking for. Thank you very much.

I am encountering just a small problem, perhaps you have an idea:

> Couldn’t retrieve the acl location from the link header

This occurs, if I try to add an ACL to a container and there is now ACL except the root acl. If at least one of the parent containers has an ACL everything works fine. But the root ACL cannot be discovered somehow. Might as well be a bug in NSS, not sure.

With curl I can get a link to the ACL file from a Pod root:

```auto
▶ curl -s -I https://solid-groups.solid.community/ | grep Link:
Link: <.acl>; rel="acl", <.meta>; rel="describedBy", <http://www.w3.org/ns/ldp#Resource>; rel="type"

```

But in the browser dev tools it is actually not to be found in the response of the OPTIONS request to the Pod root:

```auto
Link: <https://solid-groups.solid.community/.well-known/solid>; rel="service", <https://solid.community>; rel="http://openid.net/specs/connect/1.0/issuer"

```

Any ideas?

---

<div class="post-metadata">

**Author:** ![A\_A](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/a_a/32/786_2.png) [@A\_A](https://forum.solidproject.org/u/A_A)\
**Post date:** [July 1, 2020, 9:43am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/11 "2020-07-01T09:43:34Z")

</div>

Apparently node-solid-server only sets the link header for GET but not for OPTIONS requests on the root. Here’s a simple script to reproduce it from the browser console when logged in to your pod:

```javascript
fetch('/', { method: 'GET' }).then(res => console.log(res.headers.get('link')))
// <.acl>; rel="acl", <.meta>; rel="describedBy", <http://www.w3.org/ns/ldp#Resource>; rel="type"
fetch('/', { method: 'OPTIONS' }).then(res => console.log(res.headers.get('link')))
// <https://otman.solid.community/.well-known/solid>; rel="service", <https://solid.community>; rel="http://openid.net/specs/connect/1.0/issuer"

```

So I believe that it’s an issue of node-solid-server not adding `rel="acl"` to the link header.

EDIT: For HEAD it works fine. I’m not that familiar with the difference between HEAD and OPTIONS, so probably that should be used instead. If you know more about it just let me know and I’ll change it

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [July 1, 2020, 10:31am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/12 "2020-07-01T10:31:45Z")

</div>

I think a HEAD request would be correct as stated in [2.4.3.1. Discovery of Auxiliary Resources](https://solid.github.io/specification/#ar-discovery)

> To discover the auxiliary resources directly associated with a given Solid resource, a Solid client MUST issue a `HEAD` or `GET` request to the target resource URL and inspect the `Link` headers in the response.

---

<div class="post-metadata">

**Author:** ![A\_A](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/a_a/32/786_2.png) [@A\_A](https://forum.solidproject.org/u/A_A)\
**Post date:** [July 1, 2020, 1:31pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/13 "2020-07-01T13:31:07Z")

</div>

I’ve updated it to use HEAD, can you try it with this version?

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [July 1, 2020, 4:17pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/14 "2020-07-01T16:17:58Z")

</div>

Awesome, it’s working 👍 Thanks a lot

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [July 5, 2020, 8:47am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/15 "2020-07-05T08:47:47Z")

</div>

Hi @A_A sorry to bother you again. Your library has no capability to set a `acl:default`, or am I missing something?

---

<div class="post-metadata">

**Author:** ![A\_A](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/a_a/32/786_2.png) [@A\_A](https://forum.solidproject.org/u/A_A)\
**Post date:** [July 5, 2020, 9:26am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/16 "2020-07-05T09:26:22Z")

</div>

You can use `addDefaultRule(...)` instead of `addRule(...)` to set the default.  
[https://otto-aa.github.io/solid-acl-parser/#/quickstart?id=working-with-default](https://otto-aa.github.io/solid-acl-parser/#/quickstart?id=working-with-default)

Basically you can use everything defined in [this map](https://github.com/Otto-AA/solid-acl-parser/blob/master/src/AclParser.ts#L17) and all methods defined in [this class](https://github.com/Otto-AA/solid-acl-parser/blob/master/src/AclDoc.ts). So if you don’t find a functionality in the documentation you can take a look there (and open a PR to add it to the documentation :))

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [July 5, 2020, 9:34am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/17 "2020-07-05T09:34:13Z")

</div>

Thanks a lot, sorry I should not have missed that!

---

<div class="post-metadata">

**Author:** ![tsojcanth](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/tsojcanth/32/627_2.png) [@tsojcanth](https://forum.solidproject.org/u/tsojcanth)\
**Post date:** [August 16, 2020, 8:27pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/18 "2020-08-16T20:27:49Z")

</div>

Hi @A_A, those libraries are great, as is your pod explorer.  
is there any change you can add support for the origin predicate? this would allow trusted apps.

---

<div class="post-metadata">

**Author:** ![tsojcanth](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/tsojcanth/32/627_2.png) [@tsojcanth](https://forum.solidproject.org/u/tsojcanth)\
**Post date:** [August 17, 2020, 10:10am UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/19 "2020-08-17T10:10:28Z")

</div>

@A_A the issue is that if I create an ACL for a file inheriting (defaulting to) an origin predicate, the subject still points to the default location).

For example, this is what happens to the acl for [https://gaia.solid.community/is.darcy/foo.txt](https://gaia.solid.community/is.darcy/foo.txt) after I load the default, amend it, and save it:

```auto
@prefix foaf: <http://xmlns.com/foaf/0.1/>.

<#trusted-apps> a acl:Authorization;
    acl:agent </profile/card#me>;
    acl:accessTo <./foo.txt>;
    acl:mode acl:Control, acl:Read, acl:Write.
<https://gaia.solid.community/is.darcy/.acl#trusted-apps> acl:origin <https://localhost>.
<#ControlReadWrite> a acl:Authorization;
    acl:agent </profile/card#me>, <mailto:gaia@foo.co.uk>;
    acl:accessTo <./foo.txt>;
    acl:mode acl:Control, acl:Read, acl:Write.
<#Read-0> a acl:Authorization;
    acl:agent <https://giulio.solid.community/profile/card#me>;
    acl:accessTo <./foo.txt>;
    acl:mode acl:Read.

```

You can see that the origin predicate still points to the parent.

I tried to bodge it by changing the structure just before saving it, but it does not have a setter, so I was wondering if you were inclined to add origin support.

---

<div class="post-metadata">

**Author:** ![Smag0](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/smag0/32/310_2.png) [@Smag0](https://forum.solidproject.org/u/Smag0)\
**Post date:** [August 17, 2020, 8:06pm UTC](https://forum.solidproject.org/t/programmatically-adjust-acl/3232/20 "2020-08-17T20:06:37Z")

</div>

You can take a look at the new inrupt lib too  
Seems quite easy to deal with Acl

[https://docs.inrupt.com/client-libraries/solid-client-js/tutorial/manage-access-control-list.html](https://docs.inrupt.com/client-libraries/solid-client-js/tutorial/manage-access-control-list.html)

[Next page](https://forum.solidproject.org/t/programmatically-adjust-acl/3232.md?page=2)
