{
"$type": "site.standard.document",
"bskyPostRef": {
"$type": "com.atproto.repo.strongRef",
"cid": "bafyreicdjnph2sprob4gn7ul5bzw4t7wlgxxyunnjun5mqz6zyxqkuix5e",
"uri": "at://did:plc:eob75vcjtmbaef2tn4evc4sl/app.bsky.feed.post/3mp3l5rgojf2b"
},
"content": {
"$type": "at.unthread.content",
"content": "this make me think of a question when it comes to permissioned data/spaces. \n\njust because a user decides to allow an app to create a specific type of data, this doesnt mean they would want to give other apps the ability to read this data.\n\nlets say a user gives offprint access to write/read `site.standard.graph.emailSubscription` (this doesnt exist, just for the sake of an example). since it uses stansite, its interopable. but that doesn't mean that same user wants to give standard-reader.app access to that just because they use it and its (in this hypothetical future) part of their requested scopes to use the app.\n\nemail and legacy platforms (think substack/ghost) has come along with *some* basic understanding that even if this data isn't private from the app owners, its private from other users and other integrated apps.\n\nthis isn't a fully formed thought, but im curious what you all think about this. how do we reconcile this expected understanding from decades of legacy apps making specific things *feel* private, and wanting a future of interopability, but being someone that cares deeply about my own and my users privacy.. idk.",
"reply": {
"parent": {
"$type": "com.atproto.repo.strongRef",
"cid": "bafyreiftvcyhbfmcuigkyz2pswq36lbqajvlosgfcag2vsiqtaotkscy7a",
"uri": "at://did:plc:eob75vcjtmbaef2tn4evc4sl/app.bsky.feed.post/3mp3kj4qsi22j"
},
"root": {
"$type": "com.atproto.repo.strongRef",
"cid": "bafyreia5zjzkq2j7s4kxf7ipsgqetxax5qcfexffi5dhumgyeqdol646ea",
"uri": "at://did:plc:xbtmt2zjwlrfegqvch7fboei/app.bsky.feed.post/3mp2j4mbwik2q"
}
}
},
"createdAt": "2026-06-25T04:18:07.009Z",
"path": "/@aka.dad/3mp3l5jat7h23",
"publishedAt": "2026-06-25T04:18:07.009Z",
"site": "https://unthread.at",
"textContent": "this make me think of a question when it comes to permissioned data/spaces. \n\njust because a user decides to allow an app to create a specific type of data, this doesnt mean they would want to give other apps the ability to read this data.\n\nlets say a user gives offprint access to write/read site.standard.graph.emailSubscription (this doesnt exist, just for the sake of an example). since it uses stansite, its interopable. but that doesn't mean that same user wants to give standard-reader.app access to that just because they use it and its (in this hypothetical future) part of their requested scopes to use the app.\n\nemail and legacy platforms (think substack/ghost) has come along with some basic understanding that even if this data isn't private from the app owners, its private from other users and other integrated apps.\n\nthis isn't a fully formed thought, but im curious what you all think about this. how do we reconcile this expected understanding from decades of legacy apps making specific things feel private, and wanting a future of interopability, but being someone that cares deeply about my own and my users privacy.. idk.",
"title": "Continue reading on Unthread"
}