Nanopublication

< Home

ID

https://w3id.org/np/RAxalHKqqmcBFOWdbRk-93jpm9lRh6Q2M537MR436QyV0

Formats

.trig | .trig.txt | .jelly | .jelly.txt | .jsonld | .jsonld.txt | .nq | .nq.txt | .xml | .xml.txt

Content

@prefix this: <https://w3id.org/np/RAxalHKqqmcBFOWdbRk-93jpm9lRh6Q2M537MR436QyV0> .
@prefix sub: <https://w3id.org/np/RAxalHKqqmcBFOWdbRk-93jpm9lRh6Q2M537MR436QyV0/> .
@prefix np: <http://www.nanopub.org/nschema#> .
@prefix grlc: <https://w3id.org/kpxl/grlc/> .
@prefix dct: <http://purl.org/dc/terms/> .
@prefix nt: <https://w3id.org/np/o/ntemplate/> .
@prefix npx: <http://purl.org/nanopub/x/> .
@prefix xsd: <http://www.w3.org/2001/XMLSchema#> .
@prefix rdfs: <http://www.w3.org/2000/01/rdf-schema#> .
@prefix prov: <http://www.w3.org/ns/prov#> .

sub:Head {
  this: a np:Nanopublication;
    np:hasAssertion sub:assertion;
    np:hasProvenance sub:provenance;
    np:hasPublicationInfo sub:pubinfo .
}

sub:assertion {
  sub:list-space-non-approved a grlc:grlc-query;
    dct:description "Lists the non-approved role claims of a given space ref (space IRI + root definition): agents who hold a higher-tier role instantiation (admin/maintainer/member) that is NOT in the trust-validated current state, i.e. a self-assigned or otherwise ungranted claim awaiting approval by an equal-or-higher-tier member. Pass the ref's root nanopub (root_np). Observer-tier roles are excluded: they are self-assignable, so a self-declared observer needs no approval and is shown by list-space-observers instead. The higher-tier test is generic — the built-in admin property (gen:hasAdmin) OR a RoleDeclaration whose npa:hasRoleType is gen:AdminRole/gen:MaintainerRole/gen:MemberRole — but because the live spaces repo currently materialises every declaration as gen:ObserverRole, only admin claims are detectable today; maintainer/member claims appear automatically once real tier subclasses exist. Per (member, role) only the latest role-instantiation nanopub is returned (by dct:created). Returns the claimed tier, the role-assignment grant nanopub(s) with the claimed role's label (role_assignments_multi_iri + role_assignments_label_multi), and the role-assignment template (for the approve action, which re-asserts the same triple), plus a hidden agent_iri column the approve action maps into the template's agent placeholder. v2: adds the role_assignments columns. v3: resolves owl:sameAs space aliases (via the ref's validated npa:sameAsSpace edges in the current-state graph), so a higher-tier claim made against an alias IRI of the space is detected. v4: the invalidation filter now honours an npx:invalidates edge only when the invalidating nanopub shares a signing pubkey (npa:hasValidSignatureForPublicKeyHash) with the grant it targets, so a foreign-key retraction can no longer suppress another agent's claim (issue #487 / same gate as the materializer's #112). v5: BUGFIX — the v3/v4 space-alias resolution used a `{ bind(?spaceIri as ?inSpace) } union { ... npa:sameAsSpace ... }` pattern, but RDF4J does not propagate the outer ?spaceIri into a BIND inside a UNION branch, so ?inSpace was left unbound and the query returned ZERO rows for every space (no pending claim could ever surface). Replaced with a non-union `filter( ?inSpace = ?spaceIri || exists { ... npa:sameAsSpace ... } )` that binds ?inSpace from the role-instantiation triple, restoring detection while keeping alias resolution. Returns an approve_np column holding the granting nanopublication for each pending row, so an approve action can re-publish that same grant under the approver's key. This works for every tier: the previous version bound an assignment template only for admin grants, which left maintainer- and member-tier rows with an empty required value and therefore no approve button.";
    dct:license <http://www.apache.org/licenses/LICENSE-2.0>;
    rdfs:label "List space non-approved role claims (ref-scoped)";
    grlc:endpoint <https://w3id.org/np/l/nanopub-query-1.1/repo/spaces>;
    grlc:sparql """prefix rdfs: <http://www.w3.org/2000/01/rdf-schema#>
prefix dct: <http://purl.org/dc/terms/>
prefix np: <http://www.nanopub.org/nschema#>
prefix npa: <http://purl.org/nanopub/admin/>
prefix npx: <http://purl.org/nanopub/x/>
prefix gen: <https://w3id.org/kpxl/gen/terms/>
prefix schema: <http://schema.org/>

select ?member
       (sample(?tierX) as ?tier)
       (group_concat(distinct ?latestNp; separator=\" \") as ?role_assignments_multi_iri)
       (sample(?latestNp) as ?approve_np)
       (group_concat(distinct ?roleLabel; separator=\"\\n\") as ?role_assignments_label_multi)
where {
  {
    select ?member ?roleProp
           (max(?val0) as ?val)
           (strafter(max(concat(coalesce(str(?dateNp),\"\"), \" \", str(?grantNp))), \" \") as ?latestNp)
           (sample(?member) as ?agentX)
           (sample(?tier0) as ?tierX)
           (sample(?rtmpl0) as ?rtmplX)
           (sample(?rl) as ?rlRaw)
    where {
      values ?_root_np_multi_iri {}
      graph npa:spacesGraph { ?ref npa:rootNanopub ?_root_np_multi_iri ; npa:spaceIri ?spaceIri . }
      graph npa:graph { npa:thisRepo npa:hasCurrentSpaceState ?g . }
      graph npa:spacesGraph {
        ?ri a gen:RoleInstantiation ; npa:forSpace ?inSpace ; npa:forAgent ?member ; npa:viaNanopub ?grantNp ;
            (npa:regularProperty|npa:inverseProperty) ?roleProp .
      }
      filter( ?inSpace = ?spaceIri || exists { graph ?g { ?inSpace npa:sameAsSpace ?ref } } )
      bind(?roleProp = gen:hasAdmin as ?isAdminProp)
      bind(exists { graph npa:spacesGraph { ?rdA a npa:RoleDeclaration ; npa:hasRoleType gen:AdminRole ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp } } as ?isAdminDecl)
      bind(exists { graph npa:spacesGraph { ?rdM a npa:RoleDeclaration ; npa:hasRoleType gen:MaintainerRole ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp } } as ?isMaint)
      bind(exists { graph npa:spacesGraph { ?rdMe a npa:RoleDeclaration ; npa:hasRoleType gen:MemberRole ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp } } as ?isMemb)
      filter(?isAdminProp || ?isAdminDecl || ?isMaint || ?isMemb)
      filter not exists { graph npa:graph { ?invNp npx:invalidates ?grantNp ; npa:hasValidSignatureForPublicKeyHash ?invpk . ?grantNp npa:hasValidSignatureForPublicKeyHash ?invpk . } }
      bind(if(exists { graph ?g { ?vri npa:forSpaceRef ?ref ; npa:forAgent ?member ; (npa:regularProperty|npa:inverseProperty) ?roleProp } }, 1, 0) as ?val0)
      optional { graph npa:graph { ?grantNp dct:created ?dateNp } }
      bind(if(?isAdminProp || ?isAdminDecl, \"Admin\", if(?isMaint, \"Maintainer\", \"Member\")) as ?tier0)
      bind(if(?isAdminProp, <https://w3id.org/np/RAsOQ7k3GNnuUqZuLm57PWwWopQJR_4onnCpNR457CZg8>, ?undefTmpl) as ?rtmpl0)
      optional {
        graph ?g { ?raRole a gen:RoleAssignment ; npa:forSpaceRef ?ref ; gen:hasRole ?role . }
        graph npa:spacesGraph { ?rd2 a npa:RoleDeclaration ; npa:role ?role ; (gen:hasRegularProperty|gen:hasInverseProperty) ?roleProp ; npa:viaNanopub ?roleNp . }
        graph npa:graph { ?roleNp np:hasAssertion ?role_a . }
        optional { graph ?role_a { ?role schema:name ?rlS } }
        optional { graph ?role_a { ?role rdfs:label ?rlA } }
        optional { graph ?role_a { ?role dct:title ?rlB } }
        bind(coalesce(?rlS, ?rlA, ?rlB) as ?rlResolved)
      }
      bind(if(?isAdminProp, \"admin\", ?rlResolved) as ?rl)
    }
    group by ?member ?roleProp
    having (max(?val0) = 0)
  }
  bind(coalesce(?rlRaw, \"role\") as ?roleLabel)
}
group by ?member
order by ?member""" .
}

sub:provenance {
  sub:assertion prov:wasAttributedTo <https://w3id.org/np/RA0SDqJIc3dtX2AihcvcSzBR7QIWfVl5lwk6U_MbH5RoA/nanopub-ecosystem-paper-bot>;
    prov:wasDerivedFrom <https://w3id.org/np/RA-yP1hmDE4Txn6LL6z-r9q12X9bnyKrOsHruAG5f3CcY> .
}

sub:pubinfo {
  this: dct:created "2026-08-18T12:16:26Z"^^xsd:dateTime;
    dct:creator <https://w3id.org/np/RA0SDqJIc3dtX2AihcvcSzBR7QIWfVl5lwk6U_MbH5RoA/nanopub-ecosystem-paper-bot>;
    dct:license <https://creativecommons.org/licenses/by/4.0/>;
    npx:embeds sub:list-space-non-approved;
    rdfs:label "List space non-approved role claims (ref-scoped)";
    nt:wasCreatedFromProvenanceTemplate <http://purl.org/np/RAmRxSMXuHZWtDXqTXqTK_aM1KBPauATJg4_KqixamLiE>;
    nt:wasCreatedFromPubinfoTemplate <https://w3id.org/np/RA0J4vUn_dekg-U1kK3AOEt02p9mT2WO03uGxLDec1jLw>,
      <https://w3id.org/np/RAukAcWHRDlkqxk7H2XNSegc1WnHI569INvNr-xdptDGI>;
    nt:wasCreatedFromTemplate <https://w3id.org/np/RAEFAt-QcFK0ZhqfvlsmS10BnzGJA0xwOICZXkO-ai87k> .
  
  sub:sig npx:hasAlgorithm "RSA";
    npx:hasPublicKey "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxxo+arlpyxYYoHYYVTNSOWe/es90yVMBA8vaDyaAQk4pnOjTlpPptP5IkGg6zuCRIlm11QrHKkiU536witBT6gdh9kP9ay3S6m7wZ3iM7YcPMfhVHUXN6TBnuiKHHyJdVeK6RxMZlfXRKEz9HYcND+PGCXMVp8BofpKBKke3y4m8FTt+8aMEcgVcFBHFdrkWXoIIvkMlodtXkMgSwuGK8yXt/9lXqChIWpsbzu2juuX6pktMkfexkfQTwIH7oNSr/ma4KzZXERuLrCSO6IH5SfWXwjQUery6rKHiEMyie58mgBf0ssKh+uJoaZOqgbmj0f+EDwTIzq0dNsPA0A+n2QIDAQAB";
    npx:hasSignature "f/WdOPOmAFa+QQKfhjOA9H7hpXIkXc/y4vRT4bBMaJdtKhNqkOYqx9Urm4DGLB8/crmMGBS0XIez24WZZ6WyOC94i1cf7ooYwU3FijGNT5c9M22IVgp/hT+u2BMqicBHYbAvxprGMvNJ5XW8uprY1046GwHMnxiYsyQubALXdYF16pB02lyBmCazBDGpscYPYEunWa2lfLH1C7Kkxc1BproYqdPRWed9K51MuMc6vqUEkWgVhHFPO37X6LxxiXAPmpIt9arwINENOWHQvneFelcJtEHR61a+Qsr5ijSGo+ubd4aov5/hzupt3QiGbiB6s9yzp5D/wXKRes/EEgkjvQ==";
    npx:hasSignatureTarget this:;
    npx:signedBy <https://w3id.org/np/RA0SDqJIc3dtX2AihcvcSzBR7QIWfVl5lwk6U_MbH5RoA/nanopub-ecosystem-paper-bot> .
}