In order to have a permissions system, you have to have permissions. For example: read:photos, write:photos, read:running_data, etc
In order to do that, there are a few hurdles:
- You have to define ACLs for every type of data stored in everyone’s POD.
- More complex is to define what parts of what data certain ACLs give access to. For example: I may want to provide heart rate data from my runs, workouts, and temperature data but not GPS. That’s getting very granular
- Since every app will have different or possibly new types of data, having a central standard for data types and ACLs will be tough.
- You’ll also need a mapping mechanism for where the data is stored and how it’s named and the formats that are being used. Even within a single app, you can denotmalize data and store it in multiple places for different purposes.
I like the principle of this but it seems very challenging to adopt. I look forward to seeing someone solve the above challenges.