Skip to content

createBarrierHandler

createBarrierHandler(options): (request) => Promise<Response>

Defined in: packages/server/src/circuits/subscribe.ts:799

The convergence-barrier route (ADR-0056 decision 4).

Proxied rather than exposed: the engine’s control plane is unauthenticated by design and is not client-reachable, so surfacing the barrier on our own authenticated endpoint costs nothing and keeps the trust boundary intact.

maxAgeSeconds may cache the answer briefly, but only a HEALTHY one. For the pendingFlips term staleness is safe in exactly one direction — it moves the barrier backwards, so a stale reading can only DELAY an alignment, never satisfy one falsely. flipFailures inverts that: a cached pre-degradation zero would let a group align against an engine that has already lost membership effects, which is precisely the alignment the term exists to refuse. So a degraded reading is never cached and never served from cache, and the cache window is exactly the bound on how long a client may align against a freshly-degraded engine — which is why the default is 0.

{ createShape: Promise<CircuitsShapeHandle>; releaseShape: Promise<void>; replicationState: Promise<CircuitsReplicationState>; }

number

(request) => {[key: string]: unknown; app_metadata?: {[key: string]: unknown; roles?: string[]; }; sub?: string; } | Promise<{[key: string]: unknown; app_metadata?: {[key: string]: unknown; roles?: …[]; }; sub?: string; } | null> | null

(request) => Promise<Response>