createStreamGate
createStreamGate(
options): (request,path,now) =>Promise<Response>
Defined in: packages/server/src/circuits/edge.ts:295
The edge: gate, then proxy bytes — rewriting them only for the shapes that declare a rewrite.
There is no per-read FILTERING here at all, and no per-read rewriting for shapes that declare none. Predicates were resolved at shape creation, so what remains for almost every read is a decision and a copy — which is why this can sit in the TypeScript control-plane process without CPU being the axis that decides where it belongs.
A shape that declares serverProjection.rowTransform is the one exception: it is rewritten HERE,
per request, with the subject taken from the stream token, and answered private, no-store. This
is the rewriting origin ADR-0055 decision 5 names, confined to the shapes that incur it — a
transform shape gives up CDN shareability and SSE framing, and every other shape gives up nothing.
The transform’s serverOnlyColumns are fetched by the engine so the transform can read them and
are stripped here, after it runs, to the columns the client’s local table declares.
The claims a transform sees at the edge are { sub } and nothing else: a stream token carries the
subject, not the JWT it was minted from, and re-deriving richer claims per read would put an auth
provider call on the read path this whole topology exists to keep off it. A transform that needs
more than the subject is therefore NOT expressible at egress — put the subject-dependent part in
the shape’s private rowFilter.customPredicate, which is compiled at subscribe time from the full
verified claims.
Parameters
Section titled “Parameters”options
Section titled “options”Returns
Section titled “Returns”(request, path, now) => Promise<Response>