fingerprintShapeRequest
fingerprintShapeRequest(
request):Promise<string>
Defined in: packages/server/src/circuits/compile.ts:292
A content fingerprint of a compiled shape request — SHA-256 over its canonical JSON, lowercase hex.
CANONICAL because the input is not a literal an author wrote: a predicate reaches here through
rowFilter.customPredicate, whose closure may assemble { col, op, value } in whatever order its
branches happen to take, and p.and(a, b) on one path may nest where another flattens. Two
compiles that MEAN the same thing must fingerprint the same, or the equality below degrades into a
test of how the author’s code was written on the day.
This is an AUTHORIZATION equality check, not a cache key. Two requests fingerprinting the same are the same shape to the engine — same table, same predicate, same projection — so a subject whose recompiled shape still fingerprints as the one their grant names is still authorized for exactly the stream that grant points at. A collision is therefore not a performance regression, it is an authorization one, which is why this is a cryptographic digest and not a cheap hash.
Used by the re-mint path (ADR-0055 decision 6) to re-authorize a private-tier grant against the subject’s current claims. Never sent to the engine, which knows nothing about it.
Parameters
Section titled “Parameters”request
Section titled “request”Returns
Section titled “Returns”Promise<string>