# Attachments and AuthAccount capabilities preview release

**URL:** <https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239>\
**Category:** 🏄🏻‍♀️ Cadence\
**Created:** [February 1, 2023, 6:21pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239 "2023-02-01T18:21:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [February 1, 2023, 6:21pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/1 "2023-02-01T18:21:30Z")

</div>

The Cadence team is excited to share a first preview release of two new features:

- [Attachments](https://github.com/onflow/flips/blob/main/cadence/2022-09-21-attachments.md). This feature has been accepted as a FLIP. The Cadence team hopes to  
release it in the next Flow spork and is looking for feedback on the  
current implementation. Please [report bugs](https://github.com/onflow/cadence/issues/new?assignees=turbolent%2C+SupunS%2C+dsainati1&labels=Bug%2CFeedback&template=bug-report.yaml) if you encounter them!
- [AuthAccount capabilities](https://github.com/onflow/flips/pull/53). This feature is currently being proposed as a FLIP

Note that this preview release does not imply the features will be released in production – the Cadence team is working with the wider community to address the feedback received so far and will make the decision aligned with community consensus. To learn more about potential changes discussed the the AuthAccount capabilities feature see this forum post: [http://forum.flow.com/t/super-user-account/4088](http://forum.flow.com/t/super-user-account/4088)

## Preview release installation

You can install this CLI preview release using the following update command:

```auto
sh -ci "$(curl -fsSL https://raw.githubusercontent.com/onflow/flow-cli/master/install.sh)" -- v0.45.1-cadence-attachments-3

```

Please start evaluating the features using this preview release. The Cadence team is eager to receive your feedback!

---

<div class="post-metadata">

**Author:** ![tsnakejake](https://avatars.discourse-cdn.com/v4/letter/t/f4b2a3/32.png) [@tsnakejake](https://forum.flow.com/u/tsnakejake)\
**Post date:** [February 1, 2023, 7:06pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/2 "2023-02-01T19:06:34Z")

</div>

Hi! Thank you bastian for all the work you’ve put in to these updates 🙏

Few comments from me:

1. I have read through the AuthAccount capabilities discussion in full, and still do not see any code examples of why this would be used. From what I see, I stand by my point that although this is simply adding “sugar” (this feature is currently possible with contracts), it absolutely makes hacking into accounts easier. Without knowing why someone would want to link their AuthAccount, it’s hard to see the benefit of this. Would it be allowed to be linked to public path? Or only to private path to allow for account delegation? Lots of ideas but not sure what to think

I guess my question is: What is an example (with code) where someone would want to use this feature?

1. For attachments, I love that we are exploring the ability to add more data to a type without just slapping a dictionary inside of it to be able to add more stuff in the future. However, although cool, attachments seems to overcomplicate the end goal. If we want to be able to “attach” more data to a type, why not discuss allowing contract updates to add more variables to a resource/struct?

Thanks again, and hope my feedback is somewhat helpful 😃

~ Jacob T

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [February 1, 2023, 7:48pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/3 "2023-02-01T19:48:48Z")

</div>

Thank you for your feedback Jacob!

For this preview release the Cadence team is mostly looking for feedback on the implementation, i.e. if it works as expected, or if there are any problems you encounter.

Feedback regarding the features themselves are best targeted to the FLIPs, as that is where the discussion around them happens and design feedback is incorporated.

> [@tsnakejake](#):
>
> 1. I have read through the AuthAccount capabilities discussion in full, and still do not see any code examples of why this would be used. From what I see, I stand by my point that although this is simply adding “sugar” (this feature is currently possible with contracts), it absolutely makes hacking into accounts easier. Without knowing why someone would want to link their AuthAccount, it’s hard to see the benefit of this. Would it be allowed to be linked to public path? Or only to private path to allow for account delegation? Lots of ideas but not sure what to think
> 
> I guess my question is: What is an example (with code) where someone would want to use this feature?

As pointed out in the FLIP for AuthAccount capabilities, the main use case is “walletless onboarding”. The Flow team just published a blog post explaining it: [Overcoming barriers to mainstream Web3 adoption with walletless onboarding on Flow](https://flow.com/post/flow-blockchain-mainstream-adoption-easy-onboarding-wallets). As discussed in the FLIP, the feature is indeed not adding any new functionality: “child accounts” can be implemented today, the proposal is mainly just making it explicit. The proposal is not making anything possible that is not already possible today – it does not make “hacking into accounts” easier. But this concern, that nothing is proposed to make it harder, was raised in the FLIP too, and is the main reason why the community is working on/discussing such improvements, as linked above, in this topic: [Super User Account](http://forum.flow.com/t/super-user-account/4088).

> [@tsnakejake](#):
>
> For attachments, I love that we are exploring the ability to add more data to a type without just slapping a dictionary inside of it to be able to add more stuff in the future. However, although cool, attachments seems to overcomplicate the end goal. If we want to be able to “attach” more data to a type, why not discuss allowing contract updates to add more variables to a resource/struct?

The purpose of the attachments feature is to allow third-parties to extend existing types and values with additional functionality and data, which enables composability: Developers can build on other developers’ code, _without needing the original author’s approval_ – users can freely choose how their data can be used/extended.

Allowing contract authors to update contracts is a related, but separate feature, and is already being discussed in this FLIP: [FLIP: Cadence - Enable new fields on existing resource and struct definitions by austinkline · Pull Request #1097 · onflow/flow · GitHub](https://github.com/onflow/flow/pull/1097).

---

<div class="post-metadata">

**Author:** ![tsnakejake](https://avatars.discourse-cdn.com/v4/letter/t/f4b2a3/32.png) [@tsnakejake](https://forum.flow.com/u/tsnakejake)\
**Post date:** [February 1, 2023, 8:05pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/4 "2023-02-01T20:05:44Z")

</div>

Awesome reply! Thanks bastian, will move further feedback to the FLIPs

---

<div class="post-metadata">

**Author:** ![C-3PFLO](https://avatars.discourse-cdn.com/v4/letter/c/90db22/32.png) [@C-3PFLO](https://forum.flow.com/u/C-3PFLO)\
**Post date:** [February 9, 2023, 6:07pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/5 "2023-02-09T18:07:31Z")

</div>

What access is required to attach or remove an attachment from a resource?

Also, is there a way to restrict removal even from the owner of the resource. If you think of an NFT where you “drink a potion” to transform the NFT and do so with an attachment, can the attachment contract prevent users from later removing the attachment?

---

<div class="post-metadata">

**Author:** ![sainati](https://avatars.discourse-cdn.com/v4/letter/s/f1d935/32.png) [@sainati](https://forum.flow.com/u/sainati)\
**Post date:** [February 13, 2023, 6:35pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/6 "2023-02-13T18:35:24Z")

</div>

> [@C-3PFLO](#):
>
> What access is required to attach or remove an attachment from a resource?

Only the owner of a resource (i.e. the person who has the actual resource value as opposed to a reference to it) is able to add or remove attachments from it. Anybody who possesses a reference (with the proper type) can access the attachments on a resource however.

> Also, is there a way to restrict removal even from the owner of the resource.

This was a feature that was discussed but was not included in the initial release of the attachments feature. If there’s a compelling use case for restricting removal we can consider adding it though.

---

<div class="post-metadata">

**Author:** ![C-3PFLO](https://avatars.discourse-cdn.com/v4/letter/c/90db22/32.png) [@C-3PFLO](https://forum.flow.com/u/C-3PFLO)\
**Post date:** [March 20, 2023, 7:35pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/7 "2023-03-20T19:35:49Z")

</div>

Curious if there is any update on Attachments. Are they likely to go forward? Is there a tentative timeline for a Testnet release?

I built [a simple dApp using attachments](https://github.com/C-3PFLO/flow-rpg) for the hackathon but curious if there is a future for this or not.

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [April 14, 2023, 4:30pm UTC](https://forum.flow.com/t/attachments-and-authaccount-capabilities-preview-release/4239/8 "2023-04-14T16:30:46Z")

</div>

Attachments are now available on Testnet. There is still a design blocker for releasing it to Mainnet which we are working on to resolve. We hope to release it to Mainnet latest with the Stable Cadence release.
