assertShapeFilterIsEnforceable
assertShapeFilterIsEnforceable(
shape):void
Defined in: packages/contracts/src/config.ts:495
Refuse a shape whose rowFilter cannot actually filter.
The control plane compiles a private-tier shape from customPredicate alone, so a filter that does
not supply one is created with no subject test and streams every row to whoever subscribed. That
is the precise shape of a silent authorization bypass: the registry says “filtered”, the wire says
“all rows”, and nothing anywhere reports a discrepancy.
The way to land there is a rowFilter that filters nothing at all — no predicate and no column
allow-list — so it asserts a restriction it does not carry. (A filter holding only columns is
legitimate: that is how defineReadProjection narrows a projection’s wire columns without
restricting its rows.)
Refused at DEFINITION time, not at the first subscribe: declaring a rowFilter asserts that these
rows are not for everyone, and there is no input for which a filter that cannot run could later turn
out to be fine. A shape that genuinely serves every row omits rowFilter entirely — the difference
between “no filter” and “a filter that does nothing” is exactly what this keeps expressible.
Parameters
Section titled “Parameters”Returns
Section titled “Returns”void