Skip to content

RegistryInvariantCell

Defined in: packages/contracts/src/registry-invariant.ts:54

One (entry × claims fixture) cell handed to a RegistryInvariantSpec.holds predicate.

claims: object

Defined in: packages/contracts/src/registry-invariant.ts:62

[key: string]: unknown

optional app_metadata?: object

[key: string]: unknown

optional roles?: string[]

optional sub?: string


entry: SyncTableEntry

Defined in: packages/contracts/src/registry-invariant.ts:57


fixtureName: string

Defined in: packages/contracts/src/registry-invariant.ts:61

The fixture’s name, as declared in RegistryInvariantSpec.claimsFixtures.


key: string

Defined in: packages/contracts/src/registry-invariant.ts:56

The entry’s key in the registry.


readPredicate: Predicate | null

Defined in: packages/contracts/src/registry-invariant.ts:76

The read predicate this entry resolves to FOR THESE CLAIMS — the real read pipeline’s output, exactly what the control plane compiles into the shape at subscribe.

null means unfiltered, and covers both ways that arises: the entry declares no shape/rowFilter at all, or its customPredicate returned null for these claims (the documented “bypass filtering, every row is visible” answer — e.g. an admin persona). Both are the same statement about what the client receives, which is what an invariant reasons about; distinguish them via entry.shape?.rowFilter if a predicate genuinely needs to.

An AST, not SQL text: an invariant matches on structure (deniesAllRows, the isXPredicate guards) rather than on a rendered string that could drift on formatting alone.


renderedPolicies: RenderedPolicy[]

Defined in: packages/contracts/src/registry-invariant.ts:78

Every RLS policy attached to the entry’s Postgres table, rendered to inline SQL text.


rowClass: string | undefined

Defined in: packages/contracts/src/registry-invariant.ts:59

The entry’s classification, or undefined when it carries none (possible only for a appliesTo predicate).