ai:skills › d3-f-consent · version 1 ·
name
d3-f-consent
description
Consent — the screen every person agrees to before using d2, the fine print, a project's own consent topic, versions, records, and why an AI never consents. Get skills only from /api/v2/skills/d3.
feature
cons-ui
concepts
[consent, agreement, gate]
tags
#skill #feature #d3skill #wip

d3-f-consent✎ edit

Intro✎ edit

The consent screen a person agrees to — never an AI's to give.

Every person agrees to a consent screen before using d2 — the project's own if it has one, else base d2's — with d2's fine print always under it. Agreements are recorded on the person's profile; raising a consent's version asks everyone again. Only the person consents, never an AI. Spec: SpecUi › ui-consent.

Essentials✎ edit

  • R-consent-1 Consent is given by the person, never by an AI: NEVER try to agree for them (POST /consent with a token is E_SCOPE).
  • R-consent-2 Tokens aren't gated: you act for your person, who agrees in their own session.
  • R-consent-3 If your person's pages keep landing on /consent, tell them to tick the box there.
  • R-consent-4 To people, name the platform by its primary domain (aiputty.com terms), not d2.

Concepts✎ edit

The text a person agrees to. Also called: terms, agreement screen. Fields: a topic with frontmatter version (an integer); base d2's Template:consent (default) and Template:consentFinePrint (always shown, always read from base d2; a project can't remove or change it).

  • Summary: the person ticks the box on /consent; an AI never does.
  • When: the person's session is sent to /consent.
  • Needs: the person, in their own session.
  • Call: POST /consent (person's session) → back to next.
  • Rules: R-consent-1, R-consent-3.
  • Errors: E_CONSENT (400) → the box wasn't ticked · E_SCOPE (403) → an AI token.
  • Gotchas: —
  • Summary: a project names its own consent topic in Settings:PROJECT.
  • When: a project wants its own terms.
  • Needs: the topic, with a version.
  • Call: consent: <topic name> in Settings:PROJECT (e.g. ClubRules) — a topic name, never a URL.
  • Rules: A missing topic or a bad value falls back to base d2's Template:consent, with a red note on the project's Settings page.
  • Errors: —
  • Gotchas: —
  • Summary: raising version asks everyone again; a typo fix without it doesn't.
  • When: the terms change in substance.
  • Needs: —
  • Call: raise the consent topic's frontmatter version.
  • Rules: Everyone is asked again on their next visit; earlier agreements stay on record.
  • Errors: —
  • Gotchas: —

agreement✎ edit

A person's record of agreeing. Fields: consents: [{project, topic, version, finePrint, at}] on the person's profile (appended). Audit U_CONSENT on each (event diesel.user.on.consented).

agreement_list✎ edit

  • Summary: a person's agreements, each with the text as agreed.
  • When: checking what or when they agreed.
  • Needs: —
  • Call: GET /api/v2/me/consents Also: people: Settings → Agreements, each with View (/consent/view?project=&version=).
  • Rules: —
  • Errors: —
  • Gotchas: —

gate✎ edit

The check on every page request of a signed-in session: an agreement for the applying consent at its current version and the fine print at its current version, else 303 /consent?next=<where they were going>. Exempt: /consent, /login, /logout, /signup, /sso/*, the landing, static assets, /help. Right after signup the person lands on /consent. next returns only to the same host. A fresh test account agrees first.

Errors✎ edit

  • E_CONSENT (400) — the box wasn't ticked → tick it. see #consent_agree
  • E_SCOPE (403) on POST /consent — an AI token → only the person agrees. see #consent_agree
  • U_CONSENT (audit) — an agreement recorded. see #agreement_list