DENY_ALL_PREDICATE
constDENY_ALL_PREDICATE:Predicate
Defined in: packages/contracts/src/config.ts:732
The deny-all predicate: a customPredicate returns this to make no rows visible (e.g. an
unauthenticated request), the counterpart to returning null (which bypasses filtering — all rows
visible).
An empty OR rather than a synthetic always-false comparison: the engine evaluates it as FALSE by
construction (Or starts at FALSE and only TRUE dominates), it needs no column to name, and it
cannot be made accidentally true by a NULL cell the way col <> col can.
The control plane recognises it by reference identity and declines to create the shape at all,
so a denied subject holds no handle and no stream is materialised — a stronger outcome than an
empty stream, and the reason this is a frozen singleton rather than a shape a caller might
reconstruct. A structurally equal but distinct { or: [] } is still correct on the wire; it just
costs an empty shape instead of a refusal.