[ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/pubinfo", "@graph": [ { "@id": "https://orcid.org/0000-0002-1267-0234", "http://xmlns.com/foaf/0.1/name": [ { "@value": "Tobias Kuhn" } ] }, { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ", "http://purl.org/dc/terms/created": [ { "@value": "2026-08-18T12:31:56Z", "@type": "http://www.w3.org/2001/XMLSchema#dateTime" } ], "http://purl.org/dc/terms/creator": [ { "@id": "https://orcid.org/0000-0002-1267-0234" } ], "http://purl.org/dc/terms/license": [ { "@id": "https://creativecommons.org/licenses/by/4.0/" } ], "http://purl.org/nanopub/x/embeds": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/list-space-non-approved" } ], "http://purl.org/nanopub/x/supersedes": [ { "@id": "https://w3id.org/np/RAPo1zp27YZjyO3wp8Mg6sIdBKUuYXlS_VVplq-lHjf6w" } ], "http://www.w3.org/2000/01/rdf-schema#label": [ { "@value": "List space non-approved role claims (ref-scoped)" } ], "https://w3id.org/np/o/ntemplate/wasCreatedFromProvenanceTemplate": [ { "@id": "https://w3id.org/np/RA7lSq6MuK_TIC6JMSHvLtee3lpLoZDOqLJCLXevnrPoU" } ], "https://w3id.org/np/o/ntemplate/wasCreatedFromPubinfoTemplate": [ { "@id": "https://w3id.org/np/RACJ58Gvyn91LqCKIO9zu1eijDQIeEff28iyDrJgjSJF8" }, { "@id": "https://w3id.org/np/RAukAcWHRDlkqxk7H2XNSegc1WnHI569INvNr-xdptDGI" } ], "https://w3id.org/np/o/ntemplate/wasCreatedFromTemplate": [ { "@id": "https://w3id.org/np/RAEFAt-QcFK0ZhqfvlsmS10BnzGJA0xwOICZXkO-ai87k" } ] }, { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/sig", "http://purl.org/nanopub/x/hasAlgorithm": [ { "@value": "RSA" } ], "http://purl.org/nanopub/x/hasPublicKey": [ { "@value": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCwUtewGCpT5vIfXYE1bmf/Uqu1ojqnWdYxv+ySO80ul8Gu7m8KoyPAwuvaPj0lvPtHrg000qMmkxzKhYknEjq8v7EerxZNYp5B3/3+5ZpuWOYAs78UnQVjbHSmDdmryr4D4VvvNIiUmd0yxci47dTFUj4DvfHnGd6hVe5+goqdcwIDAQAB" } ], "http://purl.org/nanopub/x/hasSignature": [ { "@value": "VUlKP8XvU+KFmxAxs0daj1l7/0gTHp6VG5LMoOAH34S96bbuX8snx2GCS/hbS1lqG9CvZGJ8OIg26SOduwgAfC7XzsVymLCa0YkodBYI4s3c2DHFmMS5/MDTHHRipB/UxgN88EPSrq+vE4K/mQjpa28/Drpi8E3+TIgztJL7dxw=" } ], "http://purl.org/nanopub/x/hasSignatureTarget": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ" } ], "http://purl.org/nanopub/x/signedBy": [ { "@id": "https://orcid.org/0000-0002-1267-0234" } ] } ] }, { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/Head", "@graph": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ", "http://www.nanopub.org/nschema#hasAssertion": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/assertion" } ], "http://www.nanopub.org/nschema#hasProvenance": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/provenance" } ], "http://www.nanopub.org/nschema#hasPublicationInfo": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/pubinfo" } ], "@type": [ "http://www.nanopub.org/nschema#Nanopublication" ] } ] }, { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/assertion", "@graph": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/list-space-non-approved", "http://purl.org/dc/terms/description": [ { "@value": "Lists the non-approved role claims of a given space ref (space IRI + root definition): agents who hold a higher-tier role instantiation (admin/maintainer/member) that is NOT in the trust-validated current state, i.e. a self-assigned or otherwise ungranted claim awaiting approval by an equal-or-higher-tier member. Pass the ref's root nanopub (root_np). Observer-tier roles are excluded: they are self-assignable, so a self-declared observer needs no approval and is shown by list-space-observers instead. The higher-tier test is generic — the built-in admin property (gen:hasAdmin) OR a RoleDeclaration whose npa:hasRoleType is gen:AdminRole/gen:MaintainerRole/gen:MemberRole — but because the live spaces repo currently materialises every declaration as gen:ObserverRole, only admin claims are detectable today; maintainer/member claims appear automatically once real tier subclasses exist. Per (member, role) only the latest role-instantiation nanopub is returned (by dct:created). Returns the claimed tier, the role-assignment grant nanopub(s) with the claimed role's label (role_assignments_multi_iri + role_assignments_label_multi), and the role-assignment template (for the approve action, which re-asserts the same triple), plus a hidden agent_iri column the approve action maps into the template's agent placeholder. v2: adds the role_assignments columns. v3: resolves owl:sameAs space aliases (via the ref's validated npa:sameAsSpace edges in the current-state graph), so a higher-tier claim made against an alias IRI of the space is detected. v4: the invalidation filter now honours an npx:invalidates edge only when the invalidating nanopub shares a signing pubkey (npa:hasValidSignatureForPublicKeyHash) with the grant it targets, so a foreign-key retraction can no longer suppress another agent's claim (issue #487 / same gate as the materializer's #112). v5: BUGFIX — the v3/v4 space-alias resolution used a `{ bind(?spaceIri as ?inSpace) } union { ... npa:sameAsSpace ... }` pattern, but RDF4J does not propagate the outer ?spaceIri into a BIND inside a UNION branch, so ?inSpace was left unbound and the query returned ZERO rows for every space (no pending claim could ever surface). Replaced with a non-union `filter( ?inSpace = ?spaceIri || exists { ... npa:sameAsSpace ... } )` that binds ?inSpace from the role-instantiation triple, restoring detection while keeping alias resolution. Adds an approve_np column holding the granting nanopublication for each pending row, so an approve action can re-publish that same grant under the approver's key and thereby work for every tier, not only for admin grants. All previously returned columns are kept, so existing consumers are unaffected." } ], "http://purl.org/dc/terms/license": [ { "@id": "http://www.apache.org/licenses/LICENSE-2.0" } ], "@type": [ "https://w3id.org/kpxl/grlc/grlc-query" ], "http://www.w3.org/2000/01/rdf-schema#label": [ { "@value": "List space non-approved role claims (ref-scoped)" } ], "https://w3id.org/kpxl/grlc/endpoint": [ { "@id": "https://w3id.org/np/l/nanopub-query-1.1/repo/spaces" } ], "https://w3id.org/kpxl/grlc/sparql": [ { "@value": "prefix rdfs: \nprefix dct: \nprefix np: \nprefix npa: \nprefix npx: \nprefix gen: \nprefix schema: \n\nselect ?member\n (sample(?agentX) as ?agent_iri)\n (sample(?tierX) as ?tier)\n (group_concat(distinct ?latestNp; separator=\" \") as ?role_assignments_multi_iri)\n (sample(?latestNp) as ?approve_np)\n (group_concat(distinct ?roleLabel; separator=\"\\n\") as ?role_assignments_label_multi)\n (sample(?rtmplX) as ?roleAssignmentTemplate)\nwhere {\n {\n select ?member ?roleProp\n (max(?val0) as ?val)\n (strafter(max(concat(coalesce(str(?dateNp),\"\"), \" \", str(?grantNp))), \" \") as ?latestNp)\n (sample(?member) as ?agentX)\n (sample(?tier0) as ?tierX)\n (sample(?rtmpl0) as ?rtmplX)\n (sample(?rl) as ?rlRaw)\n where {\n values ?_root_np_multi_iri {}\n graph npa:spacesGraph { ?ref npa:rootNanopub ?_root_np_multi_iri ; npa:spaceIri ?spaceIri . }\n graph npa:graph { npa:thisRepo npa:hasCurrentSpaceState ?g . }\n graph npa:spacesGraph {\n ?ri a gen:RoleInstantiation ; npa:forSpace ?inSpace ; npa:forAgent ?member ; npa:viaNanopub ?grantNp ;\n (npa:regularProperty|npa:inverseProperty) ?roleProp .\n }\n filter( ?inSpace = ?spaceIri || exists { graph ?g { ?inSpace npa:sameAsSpace ?ref } } )\n bind(?roleProp = gen:hasAdmin as ?isAdminProp)\n bind(exists { graph npa:spacesGraph { ?rdA a npa:RoleDeclaration ; npa:hasRoleType gen:AdminRole ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp } } as ?isAdminDecl)\n bind(exists { graph npa:spacesGraph { ?rdM a npa:RoleDeclaration ; npa:hasRoleType gen:MaintainerRole ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp } } as ?isMaint)\n bind(exists { graph npa:spacesGraph { ?rdMe a npa:RoleDeclaration ; npa:hasRoleType gen:MemberRole ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp } } as ?isMemb)\n filter(?isAdminProp || ?isAdminDecl || ?isMaint || ?isMemb)\n filter not exists { graph npa:graph { ?invNp npx:invalidates ?grantNp ; npa:hasValidSignatureForPublicKeyHash ?invpk . ?grantNp npa:hasValidSignatureForPublicKeyHash ?invpk . } }\n bind(if(exists { graph ?g { ?vri npa:forSpaceRef ?ref ; npa:forAgent ?member ; (npa:regularProperty|npa:inverseProperty) ?roleProp } }, 1, 0) as ?val0)\n optional { graph npa:graph { ?grantNp dct:created ?dateNp } }\n bind(if(?isAdminProp || ?isAdminDecl, \"Admin\", if(?isMaint, \"Maintainer\", \"Member\")) as ?tier0)\n bind(if(?isAdminProp, , ?undefTmpl) as ?rtmpl0)\n optional {\n graph ?g { ?raRole a gen:RoleAssignment ; npa:forSpaceRef ?ref ; gen:hasRole ?role . }\n graph npa:spacesGraph { ?rd2 a npa:RoleDeclaration ; npa:role ?role ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp ; npa:viaNanopub ?roleNp . }\n graph npa:graph { ?roleNp np:hasAssertion ?role_a . }\n optional { graph ?role_a { ?role schema:name ?rlS } }\n optional { graph ?role_a { ?role rdfs:label ?rlA } }\n optional { graph ?role_a { ?role dct:title ?rlB } }\n bind(coalesce(?rlS, ?rlA, ?rlB) as ?rlResolved)\n }\n bind(if(?isAdminProp, \"admin\", ?rlResolved) as ?rl)\n }\n group by ?member ?roleProp\n having (max(?val0) = 0)\n }\n bind(coalesce(?rlRaw, \"role\") as ?roleLabel)\n}\ngroup by ?member\norder by ?member" } ] } ] }, { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/provenance", "@graph": [ { "@id": "https://w3id.org/np/RAhSqdJ6w_dpbVwlCLQyp5rqOWGSnG47EL_hULHkspehQ/assertion", "http://www.w3.org/ns/prov#wasAttributedTo": [ { "@id": "https://orcid.org/0000-0002-1267-0234" } ] } ] } ]