Skip to content

assertShapeFilterIsEnforceable

assertShapeFilterIsEnforceable(shape): void

Defined in: packages/contracts/src/config.ts:495

Refuse a shape whose rowFilter cannot actually filter.

The control plane compiles a private-tier shape from customPredicate alone, so a filter that does not supply one is created with no subject test and streams every row to whoever subscribed. That is the precise shape of a silent authorization bypass: the registry says “filtered”, the wire says “all rows”, and nothing anywhere reports a discrepancy.

The way to land there is a rowFilter that filters nothing at all — no predicate and no column allow-list — so it asserts a restriction it does not carry. (A filter holding only columns is legitimate: that is how defineReadProjection narrows a projection’s wire columns without restricting its rows.)

Refused at DEFINITION time, not at the first subscribe: declaring a rowFilter asserts that these rows are not for everyone, and there is no input for which a filter that cannot run could later turn out to be fine. A shape that genuinely serves every row omits rowFilter entirely — the difference between “no filter” and “a filter that does nothing” is exactly what this keeps expressible.

ShapeSpec

void