Skip to content

EntitlementSet

Defined in: packages/server/src/circuits/edge.ts:15

The live entitlement set the edge checks a shared-tier read against (ADR-0055 decision 7).

An interface, not an implementation, because the source is a Circuits subscription over the membership relations themselves — freshness is engine propagation, not a cache TTL, and there is no database on the read path.

readonly ready: boolean

Defined in: packages/server/src/circuits/edge.ts:24

Whether the entitlement set can be trusted right now. False while the subscription is catching up, degraded, or stale.

The edge denies when this is false. An unavailable entitlement set is never a permit — the failure mode of the alternative is a disclosure, and the failure mode of this one is a subject retrying a read.

permits(subject, shapeKey, scope): boolean

Defined in: packages/server/src/circuits/edge.ts:26

Whether subject may read shapeKey at scope.

string

string

readonly PredicateValue[]

boolean


scopesFor(subject, shapeKey): readonly readonly PredicateValue[][]

Defined in: packages/server/src/circuits/edge.ts:39

Every scope of shapeKey that subject holds, each an ordered tuple matching the shape’s declared scope columns.

This is what lets a client subscribe by shape alone (ADR-0055 decision 6): it names offering_content, and the control plane answers with one stream per offering the subject can actually read. The alternative — the client naming scopes — makes it restate something only this set knows, so its every answer is either redundant or wrong.

Enumeration and permits must agree: a scope returned here that permits would refuse is a grant the edge then rejects on every read.

string

string

readonly readonly PredicateValue[][]