Why these permissions
These are the existing Forge scopes already granted at install. This page explains why Shell needs each one. We are not adding or changing scopes.
| Scope | Why Shell needs it | Used by (commands) |
|---|---|---|
read:confluence-space.summary / read:space:confluence | List spaces and navigate the site tree | ls, cd, tab completion at / |
write:confluence-space | Create folders that become pages/structures where space writes apply | mkdir / space-adjacent writes as already shipped |
search:confluence | CQL-backed discovery | find (-name, -mtime, -prune, …) |
read:page:confluence | Read page metadata and bodies | ls, ls -l, cat, tree, less, pipes |
read:content-details:confluence | Richer page detail where needed | detailed listing / history-related reads |
write:page:confluence / write:confluence-content | Create/update/move/copy pages | touch, mv, cp, chmod writes |
delete:page:confluence | Move pages to trash / remove | rm / del (and moves that Confluence models as delete+create where applicable) |
read:attachment:confluence | List page attachments | attach ls |
write:attachment:confluence / delete:attachment:confluence | Rename / trash attachments | attach mv -y, attach rm -y |
mv and cp stay same-space only (at most 100 sources). This is not a cross-space bulk migrator.
chmod lists or changes explicit page restrictions. Space-level permission admin is out of scope.