createBarrierHandler
createBarrierHandler(
options): (request) =>Promise<Response>
Defined in: packages/server/src/circuits/subscribe.ts:799
The convergence-barrier route (ADR-0056 decision 4).
Proxied rather than exposed: the engine’s control plane is unauthenticated by design and is not client-reachable, so surfacing the barrier on our own authenticated endpoint costs nothing and keeps the trust boundary intact.
maxAgeSeconds may cache the answer briefly, but only a HEALTHY one. For the pendingFlips term
staleness is safe in exactly one direction — it moves the barrier backwards, so a stale reading can
only DELAY an alignment, never satisfy one falsely. flipFailures inverts that: a cached
pre-degradation zero would let a group align against an engine that has already
lost membership effects, which is precisely the alignment the term exists to refuse. So a degraded
reading is never cached and never served from cache, and the cache window is exactly the bound on
how long a client may align against a freshly-degraded engine — which is why the default is 0.
Parameters
Section titled “Parameters”options
Section titled “options”engine
Section titled “engine”{ createShape: Promise<CircuitsShapeHandle>; releaseShape: Promise<void>; replicationState: Promise<CircuitsReplicationState>; }
engine.createShape
Section titled “engine.createShape”engine.releaseShape
Section titled “engine.releaseShape”engine.replicationState
Section titled “engine.replicationState”maxAgeSeconds?
Section titled “maxAgeSeconds?”number
resolveAuthClaims?
Section titled “resolveAuthClaims?”(request) => {[key: string]: unknown; app_metadata?: {[key: string]: unknown; roles?: string[]; }; sub?: string; } | Promise<{[key: string]: unknown; app_metadata?: {[key: string]: unknown; roles?: …[]; }; sub?: string; } | null> | null
Returns
Section titled “Returns”(request) => Promise<Response>