Skip to content

DENY_ALL_PREDICATE

const DENY_ALL_PREDICATE: Predicate

Defined in: packages/contracts/src/config.ts:732

The deny-all predicate: a customPredicate returns this to make no rows visible (e.g. an unauthenticated request), the counterpart to returning null (which bypasses filtering — all rows visible).

An empty OR rather than a synthetic always-false comparison: the engine evaluates it as FALSE by construction (Or starts at FALSE and only TRUE dominates), it needs no column to name, and it cannot be made accidentally true by a NULL cell the way col <> col can.

The control plane recognises it by reference identity and declines to create the shape at all, so a denied subject holds no handle and no stream is materialised — a stronger outcome than an empty stream, and the reason this is a frozen singleton rather than a shape a caller might reconstruct. A structurally equal but distinct { or: [] } is still correct on the wire; it just costs an empty shape instead of a refusal.