Skip to content

RowFilterSpec

Defined in: packages/contracts/src/config.ts:690

optional columns?: string[]

Defined in: packages/contracts/src/config.ts:706

Column projection for the shape URL (e.g. [“id”, “source_text”]).


optional customPredicate?: (claims, params?) => Predicate | null

Defined in: packages/contracts/src/config.ts:704

The PRIVATE-TIER row filter (ADR-0055): the predicate fused with the caller’s claims, compiled into the shape at subscribe. null bypasses filtering (all rows); DENY_ALL_PREDICATE denies.

Authored with the p.* builders over real Drizzle column objects, so a comparison is checked against the column’s own TypeScript type — a mistyped enum label, a null against a NOT NULL column, or a jsonb/Date column with no scalar wire form are all compile errors rather than silently-wrong filters.

Must be pure: it is called fresh per shape creation, and probed with empty claims to detect claims-dependence (ADR-0039 — isClaimsDependentRowFilter).

{[key: string]: unknown; roles?: string[]; } = ...

string[] = ...

string = ...

Record<string, unknown>

Predicate | null


optional revision?: string | number

Defined in: packages/contracts/src/config.ts:714

An opaque version tag for the part of this filter the fingerprint cannot see — the customPredicate body (you cannot hash a closure; only its presence is fingerprinted). Bump this (any new string/number) whenever you change that logic so the fingerprint shifts and the local read cache rebuilds + the shape subscription resets. Leaving it unchanged after a customPredicate authorization change would silently serve the stale shape.