authorizeStreamRead
authorizeStreamRead(
options,token,path,now):Promise<GateDecision>
Defined in: packages/server/src/circuits/edge.ts:140
Authorize one read of one stream path.
Two checks, and they are not redundant. The token is a capability bounded by its TTL, which is the only bound available when a hit-serving CDN sits in front and the request never reaches us. The entitlement lookup is live, and bounds revocation by propagation latency instead whenever the request does reach us. Which one binds is a property of the deployment, not of this code.
A private-tier grant has no scope to check, so the token is the whole authorization and its TTL is the whole revocation bound. That is the same bound a CDN-fronted shared read has, and it is worth stating rather than leaving to be inferred.
Parameters
Section titled “Parameters”options
Section titled “options”string | null
string
number
Returns
Section titled “Returns”Promise<GateDecision>