The rights an instance has to be asked about before a request is applied
scope_pairs.RdThe scope gate asks whether the person who filed a request may manage the
users of the project they filed it for. That question is about the
requester, not about the person the request is for, so it needs a state
read the channel does not otherwise make: module_state() answers for the
pairs it is given, and the pairs it is given are the grantees.
Value
A data frame with server, project_id and username, one row per
distinct triple. The requester travels under username because that is the
name module_state() expects in a pair.
Details
Rows with no server or no project are not asked about. There is nothing to
ask — and validate_request() already reports the project one. A row with no
requester is not asked about either, and is refused by scope_errors()
instead: an unattributable row cannot be answered by any instance.