Capability, permission, origin
Whether an “Edit” button appears depends on three answers, and each comes from somewhere else. Whoever shortens them to one check either builds buttons that lead nowhere or hides rights that would be there.
Capability: what the data source can do
The core of the DataInterface reads and observes. Everything beyond that is a capability (spec 03): writing (isWritable), managing groups (hasGroups), signing in (isAuthenticatable), Relation Eine gerichtete Beziehung zwischen Items mit Prädikat und Ziel. Rückverweise zeigen sie aus der Gegenrichtung. GlossarRelation A directed link between items with predicate and target. Back-references show it from the opposite direction. Glossary, activity, notifications. A Connector Die Implementierung des DataInterface für eine konkrete Datenquelle, ergänzt um unterstützte Capabilities. Die Steckstelle des Stacks nach unten. GlossarConnector The implementation of the DataInterface for one data source, plus the capabilities it supports. The stack's socket downward. Glossary has it or not; the interface asks instead of assuming.
Inside the frame this is taken care of: reading hooks answer empty without the capability, writing ones fail on the call, not on render, and surfaces hide what the connector cannot do. The same garden with a connector that can only read:
The same garden without write capability: no plus button, no edit, but everything readable. The sample data is fictional. Changes last only for this session.
The check every writing surface makes before it shows a button. The sample data is fictional. Changes last only for this session.
Permission: what I may do here
That a connector can write does not mean I may change this item. The permission hangs on me and on the item: am I a Mitglied Vorgeschlagen: wer zu einem Space gehört. Die Anwendungsschicht liest Mitgliedschaft über den Connector und konstruiert sie nicht selbst; wie sie gespeichert und belegt wird, entscheidet der jeweilige Connector (der lokale Connector hält sie in groupMembers, der RLTP-Connector leitet sie aus Gruppen-Log und Schlüssel ab). GlossarMember Proposed: who belongs to a space. The application layer reads membership through the connector and does not construct it; how it is stored and proven is decided by the connector in use (the local connector keeps it in groupMembers, the RLTP connector derives it from the group log and key). Glossary of the Space Der gemeinsame Arbeits-, Mitgliedschafts- und Sichtbarkeitskontext. Im Datenvertrag heißt er Group. GlossarSpace The shared context for work, membership and visibility. In the data contract it is called Group. Glossary, am I the author, what does the group allow? useItemPermissions(item) answers this for the interface as {canEdit, canDelete}, both false without the capability.
The direction matters: the interface shows matching actions, but the write path enforces the rule. Hiding a button is not authorisation. Where a server exists, it is the boundary: with Supabase the row rule rejects foreign changes. In the Web of Trust there is no such boundary for ordinary items today: every member holds the space key and can write the document directly; the author check on write is a convention that keeps honest clients honest, not protection against other members. Signatures there verify only what is signed, such as relation records (spec 08) and mirror snapshots (spec 09). Whoever has the rule only in the interface has none.
Origin: where the item is at home
An item has exactly one home space. If it appears in another one, it is a Spiegel Ein schreibgeschützter Schnappschuss eines Items in einem anderen Space als seinem Home. Er erscheint dort als gewöhnliches Item mit der Relation mirrorOf auf das Original; bearbeitet wird immer das Home. Dieselbe Form gilt für alle Connectoren: mit Signaturidentität (RLTP) sind die Schnappschüsse vom Autor signiert und werden vor der Anzeige geprüft, ohne Signaturidentität kommen sie ohne JWS aus einer Vertrauensdomäne. GlossarMirror A read-only snapshot of an item in a space other than its home. There it appears as an ordinary item with the relation mirrorOf pointing at the original; editing always opens the home. The same form holds for every connector: with a signing identity (RLTP) the snapshots are author-signed and verified before they are shown, without one they come without a JWS from a single trust domain. Glossary there (spec 09): readable, with a hint to its origin, but not to be edited there, because the truth lives in the home space. A person’s Personenprofil Die fachliche Darstellung einer Person als Item nach Profilvertrag. Die User-Identität ist ein eigener Begriff. GlossarPerson profile The domain representation of a person as an item under the profile contract. The user identity is a separate term. Glossary is the first item that travels this way: it lives in the personal space and is mirrored into every group the person releases it to (spec 12).
So the origin does not decide writability on its own; it says where a change belongs. The interface shows it as a badge (ItemScopeBadge: group, colour, private), from one derivation for all surfaces (useItemPresentation).
Trust is a fourth question
Whether a statement is true, who confirmed it and how much I trust the source is neither a permission nor a capability. Spec 05 separates claims, confirmations and trust levels; in the resonance module only statements whose signature has been verified count (useVerifiedRelationRecords). A connector without signature verification delivers empty counts, not wrong ones.
Where to go next
Spec 03 capabilities, Spec 09 mirror and bridge, the hooks of the group Permissions and capabilities. The last concept page takes apart the surface where the three answers meet: One detail view for all items.