Usage
Code Generation
This module is typically used alongside generated server code. To generate the server code, runbijection dev in your Bijection project.
This will create a bijection/_generated/server.js file with the following
functions, typed for your schema:
If you aren’t using TypeScript and code generation, you can use these untyped
functions instead:
Example
Bijection functions are defined by using either thequery or
mutation wrappers.
Queries receive a db that implements the GenericDatabaseReader interface.
mutation instead which provides a db that
implements the GenericDatabaseWriter interface.
Classes
- Crons
- Expression
- IndexRange
- PublishedDefinition
- HttpRouter
- TableDefinition
- SchemaDefinition
- SearchFilter
- FilterExpression
- ViewQuery
- ViewDefinition
Interfaces
- UserIdentity
- Auth
- ProtectedFileBinding
- BijectionStorageReader
- PrepareUploadOptions
- BijectionStorageWriter
- BijectionStorageActionWriter
- OccurrenceCustody
- BijectionQueryCtx
- BijectionMutationCtx
- BijectionActionCtx
- CronJob
- BaseTableReader
- GenericDatabaseReader
- GenericDatabaseReaderWithTable
- GenericDatabaseWriter
- GenericDatabaseWriterWithTable
- BaseTableWriter
- FilterBuilder
- IndexRangeBuilder
- ExternalCalls
- Approvals
- Sources
- ActionSources
- TransactionLimits
- QueryMeta
- MutationMeta
- ActionMeta
- PaginationResult
- PaginationOptions
- QueryInitializer
- Query
- OrderedQuery
- GenericMutationCtx
- GenericQueryCtx
- GenericActionCtx
- ValidatedFunction
- AdvancedRunQueryOptions
- Scheduler
- SearchIndexConfig
- VectorIndexConfig
- DefineSchemaOptions
- SystemDataModel
- SearchFilterBuilder
- SearchFilterFinalizer
- ProjectedOrderedQuery
- ProjectedQuery
- SelectableOrderedQuery
- SelectableQuery
- SelectableQueryInitializer
- StorageReader
- StorageWriter
- StorageActionWriter
- VectorSearchQuery
- VectorFilterBuilder
References
UserIdentityAttributes
Re-exports UserIdentityAttributesType Aliases
FunctionType
Ƭ FunctionType:"query" | "mutation" | "action"
The type of a Bijection function.
FunctionReference
Ƭ FunctionReference<Type, Visibility, Args, ReturnType, ComponentPath>: Object
A reference to a registered Bijection function.
You can create a FunctionReference using the generated api utility:
FunctionReference as a callback argument, prefer
typing the callback parameter as FunctionReference_future.
Type parameters
Type declaration
FunctionReference_future
Ƭ FunctionReference_future<Type, Visibility, Args, ReturnType, ComponentPath>: Object
A reference to a Bijection function whose arguments are checked closer to the
way Bijection checks them at runtime.
Use this instead of FunctionReference when you accept someone else’s
Bijection function as a callback and know which arguments you will pass it.
A plain FunctionReference gets a couple things backwards: it accepts a
function requiring arguments you never pass, and rejects a function
accepting broader values than you pass. An ordinary TypeScript function type
doesn’t map perfectly either: it treats a surplus argument as harmless,
where a Bijection validator rejects it.
This type melds regular TypeScript function reference behavior with top
level checking of arguments to prevent surplus arguments from hitting
runtime validation errors. The caveat: a surplus key inside a nested object,
an array element, or one arm of a union passes the type check and fails the
validator at runtime.
ctx.runMutation,
ctx.scheduler.runAfter, createFunctionHandle, and everything else in
this package that takes a reference, all of which accept either kind.
It is not assignable to a plain FunctionReference. Code that wants to
accept both kinds should take
FunctionReference<...> | FunctionReference_future<...> and read arguments
and return types through FunctionArgs and FunctionReturnType.
Argument checking here relies on strictFunctionTypes (implied by strict)
and is skipped for projects that disable it. Everything else about the
reference is compared exactly as FunctionReference compares it.
Type parameters
Type declaration
ApiFromModules
Ƭ ApiFromModules<AllModules>: FilterApi<ApiFromModulesAllowEmptyNodes<AllModules>, FunctionReference<any, any, any, any> | OperationReference<any, any, any>>
Given the types of all modules in the bijection/ directory, construct the type
of api.
api is a utility for constructing FunctionReferences.
Type parameters
FilterApi
Ƭ FilterApi<API, Predicate>: Expand<{ [mod in keyof API as FilterKeysInApi<mod, API[mod], Predicate>]: API[mod] extends Predicate ? API[mod] : FilterApi<API[mod], Predicate> }>
Filter a Bijection deployment api object for functions which meet criteria,
for example all public queries.
Type parameters
AnyApi
Ƭ AnyApi:Record<string, Record<string, AnyModuleDirOrFunc>>
The type that Bijection api objects extend. If you were writing an api from
scratch it should extend this type.
PartialApi
Ƭ PartialApi<API>: { [mod in keyof API]?: API[mod] extends FunctionReference<any, any, any, any> | OperationReference<any, any, any> ? API[mod] : PartialApi<API[mod]> }
Recursive partial API, useful for defining a subset of an API when mocking
or building custom api objects.
Type parameters
FunctionArgs
Ƭ FunctionArgs<FuncRef>: ExtractSignature<FuncRef>["args"]
Given a FunctionReference or FunctionReference_future, get
the arguments of the function.
This is represented as an object mapping argument names to values.
Type parameters
OptionalRestArgs
Ƭ OptionalRestArgs<FuncRef>: FunctionArgs<FuncRef> extends EmptyObject ? [args?: EmptyObject] : [args: FunctionArgs<FuncRef>]
A tuple type of the (maybe optional) arguments to FuncRef.
This type is used to make methods involving arguments type safe while allowing
skipping the arguments for functions that don’t require arguments.
Type parameters
ArgsAndOptions
Ƭ ArgsAndOptions<FuncRef, Options>: FunctionArgs<FuncRef> extends EmptyObject ? [args?: EmptyObject, options?: Options] : [args: FunctionArgs<FuncRef>, options?: Options]
A tuple type of the (maybe optional) arguments to FuncRef, followed by an options
object of type Options.
This type is used to make methods like useQuery type-safe while allowing
- Skipping arguments for functions that don’t require arguments.
- Skipping the options object.
Type parameters
FunctionReturnType
Ƭ FunctionReturnType<FuncRef>: ExtractSignature<FuncRef>["returnType"]
Given a FunctionReference or FunctionReference_future, get
the return type of the function.
Type parameters
ValidatorTypeToReturnType
Ƭ ValidatorTypeToReturnType<T>: Promise<NullToUndefinedOrNull<T>> | NullToUndefinedOrNull<T>
Type parameters
ApplicationSourceControl
Ƭ ApplicationSourceControl: (ctx: GenericMutationCtx<GenericDataModel>, request: { action: "sync" | "check" ; collection: string ; source: string }) => Promise<boolean>
Type declaration
▸ (ctx, request): Promise<boolean>
The program’s decision whether this caller may ask for a sync of, or a
connection check on, one source of an exposed synced collection
(applicationQueries({ sourceControl })). Whoever it allows spends
provider budget; the engine’s coalescing and the connection’s budget bound
that. It runs after authorize and the collection check, with the
caller’s own context, and only true allows the request.
Parameters
Returns
Promise<boolean>
CollectionNotificationKind
Ƭ CollectionNotificationKind:Object
A category whose events are rows of an exposed collection: the event names
the object it is about in objectProperty and carries its message in
messageProperty. With tab, the notice opens that object view tab with
the event itself as its detail.
Type declaration
AppNoticeContent
Ƭ AppNoticeContent:Object
What a resolved category’s event is, as the reader may see it now. The
message is cut to APP_NOTICE_MESSAGE_MAX characters. An object
subject names an exposed collection’s object, which is titled through the
reader’s own read of it; a page subject names a workspace page by its
kebab-case id, the route it opens and its title (at most 200 characters are
shown).
Type declaration
ResolvedNotificationKind
Ƭ ResolvedNotificationKind:Object
A category resolved by product code. resolve runs inside the reader’s own
notification query and updates, with the READER’s context and current
authority, and answers the notice or null to omit it. It may make at most
one protected read for an object subject (the object is read once more to
title it) and two for a page subject: a notification is budgeted
READ_SUBJECTS_PER_NOTIFICATION read subjects, its delivery row
included, and a query beyond the engine’s bound fails whole. An answer that
does not have the shape above is omitted like null.
Type declaration
ApplicationNotificationKind
Ƭ ApplicationNotificationKind:CollectionNotificationKind | ResolvedNotificationKind
ApplicationNotifications
Ƭ ApplicationNotifications:Object
Customer-owned delivery state referencing authoritative business events.
table is a private table with by_recipient_read and
by_recipient_archive indexes whose rows are
applicationNotificationRows. kinds declares at most sixteen
categories, each keyed by a kebab-case identifier. The in-app recipient is
the caller’s own person (applicationQueries({ people })).
Type declaration
ApplicationPeople
Ƭ ApplicationPeople:Object
Who the application’s people are: the one identity every recipient,
grantee, author and mention names.
collection is an exposed collection whose objects are the people. It
declares search, so a person can be found by name, it is not a connection
type, and its title property is a person’s name: names are read through
it under the reader’s rules, never stored beside an id.
self answers the signed-in caller’s own person: the id of their object in
collection, or null when the caller is not one of its people. It runs
after authorize, with the caller’s context, so its reads are the caller’s.
Type declaration
AppPlace
Ƭ AppPlace:Object
One place a location search found: WGS84 [longitude, latitude], how
precise the match is, and the provider’s attribution text.
Type declaration
AppPlaceSearch
Ƭ AppPlaceSearch: {status: "pending" } | { status: "answered" ; places: AppPlace[] } | { status: "failed" | "unknown" ; message: string }
A durable location search as its reader answers it: still pending,
answered with at most APP_PLACES places, or failed / of unknown
outcome with the provider’s message.
ApplicationPlaces
Ƭ ApplicationPlaces:Object
A program’s location search (applicationQueries({ places })). A search is
durable intent: request records it under the caller in the calling
mutation and the program’s own scheduled work asks its provider, so the
browser never holds a provider key; read answers the recorded request
reactively. Both run in the application’s functions with the caller’s
authority, after the application’s authorize.
Type declaration
ApplicationMapValues
Ƭ ApplicationMapValues:Record<string, { collection: string ; label: string ; values: (ctx: GenericQueryCtx<GenericDataModel>, ids: string[]) => Promise<Record<string, null | string | number>> }>
Values a program computes for map styling (Foundry function-backed
styling), by name: each belongs to one exposed collection and answers for
the ids it is given. The mapValues query reads every object through the
ordinary authorized read first and passes only readable ids.
AppSpatialBound
Ƭ AppSpatialBound:Object
What an index may spend reading. subjects is the read-access budget of a
collection read under per-row access checks, null for a collection read
without them. The engine records one subject per distinct range demand (a
range’s equalities) and rowCost per distinct row visited, matching or
not.
Type declaration
AppSpatialIndex
Ƭ AppSpatialIndex:Object
A program’s spatial index over one declared geometry property: the reads
that answer the property’s spatial clauses. Each runs with ordinary reads of
the collection in the calling query, under the caller’s authority.
kind:pointsfor a point property (regions of every kind byintersectsanddisjoint, nearest objects, cells),shapesfor any other (box and polygon regions by every mode).table: the collection the index reads, which is the collection it answers for: its reads are the collection’s own, under its read rule.index: the index oftableits range reads use; the engine’s row cost for it bounds them, and an index the engine reports unbounded refuses every clause.cells: the grid systemscellOfanswers (none forshapes).select: the objects of the collection whose value relates toregionbymode, at mostlimit, in any order, as the index’s reads returned them.isComplete: falsewhen more may match or the reads could not cover the region withinsubjects; the application then refuses the scope rather than answering from part of it. An object without a value matches no mode.nearest: theklocated objects nearestcenterwithinmaxMetres, nearest first (ties by id), with their distances in metres, or fewer when fewer exist;isComplete: falsewhen the ranking could not be proven withinsubjects. Ashapesindex refuses it.cellOf: the cell ofgroupingholding one object’s point value, or null when it has none (ashapesindex answers null).
Type declaration
AppSpatialIndexes
Ƭ AppSpatialIndexes:Record<string, Record<string, AppSpatialIndex>>
Spatial indexes by collection and declared geometry property.
AuditLogBody
Ƭ AuditLogBody:Object
Index signature
▪ [key:string]: AuditLogValue
AuditLogValue
Ƭ AuditLogValue:null | undefined | boolean | number | string | LogVar | AuditLogValue[] | { [key: string]: AuditLogValue; }
AuthConfig
Ƭ AuthConfig:Object
The value exported by your Bijection project in auth.config.ts.
Type declaration
AuthProvider
Ƭ AuthProvider: {applicationID: string ; domain: string } | { type: "customJwt" ; applicationID?: string ; issuer: string ; jwks: string ; algorithm: "RS256" | "ES256" }
An authentication provider allowed to issue JWTs for your app.
See: https://docs.bijection.com/auth/advanced/custom-auth and https://docs.bijection.com/auth/advanced/custom-jwt
FunctionHandle
Ƭ FunctionHandle<Type, Args, ReturnType>: string & FunctionReference<Type, "internal", Args, ReturnType>
A serializable reference to a Bijection function.
Passing a this reference to another component allows that component to call this
function during the current function execution or at any later time.
Function handles are used like api.folder.function FunctionReferences,
e.g. ctx.scheduler.runAfter(0, functionReference, args).
A function reference is stable across code pushes but it’s possible
the Bijection function it refers to might no longer exist.
This is a feature of components, which are in beta.
This API is unstable and may change in subsequent releases.
Type parameters
ComponentDefinition
Ƭ ComponentDefinition<Exports, Env>: Object
An object of this type should be the default export of a
bijection.config.ts file in a component definition directory.
This is a feature of components, which are in beta.
This API is unstable and may change in subsequent releases.
Type parameters
Type declaration
EnvDefinition
Ƭ EnvDefinition:Record<string, StringLikeValidator | VOptional<StringLikeValidator>>
A definition of environment variables for the app.
Maps environment variable names to string-like validators. Use
v.string() for a plain string, v.literal("a") for an enum value, or
v.union(v.literal("a"), v.literal("b")) for an enum. Wrap in
v.optional(...) for optional vars.
Example
EnvFromDefinition
Ƭ EnvFromDefinition<E>: Expand<{ [K in keyof E as E[K] extends Validator<any, “optional”, any> ? never : K]: Infer<E[K]> } & { [K in keyof E as E[K] extends Validator<any, “optional”, any> ? K : never]?: Infer<E[K]> }>
Compute the typed environment object from an EnvDefinition.
Required entries get the validator’s inferred string type; optional
entries are T | undefined.
Type parameters
EnvFromAppDefinition
Ƭ EnvFromAppDefinition<A>: A extends AppDefinition<infer E> ? EnvFromDefinition<E> : Record<string, never>
Extract the typed environment from an AppDefinition.
Type parameters
AppDefinition
Ƭ AppDefinition<Env>: Object
An object of this type should be the default export of a
bijection.config.ts file in a component-aware bijection directory.
This is a feature of components, which are in beta.
This API is unstable and may change in subsequent releases.
Type parameters
Type declaration
AnyChildComponents
Ƭ AnyChildComponents:Record<string, AnyComponentReference>
AnyComponents
Ƭ AnyComponents:AnyChildComponents
UploadCompletionReference
Ƭ UploadCompletionReference:FunctionReference<"mutation", "public" | "internal", { file: GenericId<"_storage"> }>
A mutation that attaches a newly uploaded file: it receives the file as
file beside the arguments its preparation named.
BijectionQueryBuilder
Ƭ BijectionQueryBuilder<DM, V>: BijectionFunctionBuilder<DM, V, "query">
Type parameters
BijectionMutationBuilder
Ƭ BijectionMutationBuilder<DM, V>: BijectionFunctionBuilder<DM, V, "mutation">
Type parameters
BijectionActionBuilder
Ƭ BijectionActionBuilder<DM, V>: BijectionFunctionBuilder<DM, V, "action">
Type parameters
GenericDocument
Ƭ GenericDocument:Record<string, Value>
A document stored in Bijection.
GenericFieldPaths
Ƭ GenericFieldPaths:string
A type describing all of the document fields in a table.
These can either be field names (like “name”) or references to fields on
nested objects (like “properties.name”).
GenericIndexFields
Ƭ GenericIndexFields:string[]
A type describing the ordered fields in an index.
These can either be field names (like “name”) or references to fields on
nested objects (like “properties.name”).
GenericTableIndexes
Ƭ GenericTableIndexes:Record<string, GenericIndexFields>
A type describing the indexes in a table.
It’s an object mapping each index name to the fields in the index.
GenericSearchIndexConfig
Ƭ GenericSearchIndexConfig:Object
A type describing the configuration of a search index.
Type declaration
GenericTableSearchIndexes
Ƭ GenericTableSearchIndexes:Record<string, GenericSearchIndexConfig>
A type describing all of the search indexes in a table.
This is an object mapping each index name to the config for the index.
GenericVectorIndexConfig
Ƭ GenericVectorIndexConfig:Object
A type describing the configuration of a vector index.
Type declaration
GenericTableVectorIndexes
Ƭ GenericTableVectorIndexes:Record<string, GenericVectorIndexConfig>
A type describing all of the vector indexes in a table.
This is an object mapping each index name to the config for the index.
FieldTypeFromFieldPath
Ƭ FieldTypeFromFieldPath<Document, FieldPath>: FieldTypeFromFieldPathInner<Document, FieldPath> extends Value | undefined ? FieldTypeFromFieldPathInner<Document, FieldPath> : Value | undefined
The type of a field in a document.
Note that this supports both simple fields like “name” and nested fields like
“properties.name”.
If the field is not present in the document it is considered to be undefined.
Type parameters
FieldTypeFromFieldPathInner
Ƭ FieldTypeFromFieldPathInner<Document, FieldPath>: FieldPath extends `\{infer First}.{infer Second}` ? ValueFromUnion<Document, First, Record<never, never>> extends infer FieldValue ? FieldValue extends GenericDocument ? FieldTypeFromFieldPath<FieldValue, Second> : undefined : undefined : ValueFromUnion<Document, FieldPath, undefined>
The inner type of FieldTypeFromFieldPath.
It’s wrapped in a helper to coerce the type to Value | undefined since some
versions of TypeScript fail to infer this type correctly.
Type parameters
GenericTableInfo
Ƭ GenericTableInfo:Object
A type describing the document type and indexes in a table.
Type declaration
DocumentByInfo
Ƭ DocumentByInfo<TableInfo>: TableInfo["document"]
The type of a document in a table for a given GenericTableInfo.
Type parameters
FieldPaths
Ƭ FieldPaths<TableInfo>: TableInfo["fieldPaths"]
The field paths in a table for a given GenericTableInfo.
These can either be field names (like “name”) or references to fields on
nested objects (like “properties.name”).
Type parameters
Indexes
Ƭ Indexes<TableInfo>: TableInfo["indexes"]
The database indexes in a table for a given GenericTableInfo.
This will be an object mapping index names to the fields in the index.
Type parameters
IndexNames
Ƭ IndexNames<TableInfo>: keyof Indexes<TableInfo>
The names of indexes in a table for a given GenericTableInfo.
Type parameters
NamedIndex
Ƭ NamedIndex<TableInfo, IndexName>: Indexes<TableInfo>[IndexName]
Extract the fields of an index from a GenericTableInfo by name.
Type parameters
SearchIndexes
Ƭ SearchIndexes<TableInfo>: TableInfo["searchIndexes"]
The search indexes in a table for a given GenericTableInfo.
This will be an object mapping index names to the search index config.
Type parameters
SearchIndexNames
Ƭ SearchIndexNames<TableInfo>: keyof SearchIndexes<TableInfo>
The names of search indexes in a table for a given GenericTableInfo.
Type parameters
NamedSearchIndex
Ƭ NamedSearchIndex<TableInfo, IndexName>: SearchIndexes<TableInfo>[IndexName]
Extract the config of a search index from a GenericTableInfo by name.
Type parameters
VectorIndexes
Ƭ VectorIndexes<TableInfo>: TableInfo["vectorIndexes"]
The vector indexes in a table for a given GenericTableInfo.
This will be an object mapping index names to the vector index config.
Type parameters
VectorIndexNames
Ƭ VectorIndexNames<TableInfo>: keyof VectorIndexes<TableInfo>
The names of vector indexes in a table for a given GenericTableInfo.
Type parameters
NamedVectorIndex
Ƭ NamedVectorIndex<TableInfo, IndexName>: VectorIndexes<TableInfo>[IndexName]
Extract the config of a vector index from a GenericTableInfo by name.
Type parameters
GenericDataModel
Ƭ GenericDataModel:Record<string, GenericTableInfo>
A type describing the tables in a Bijection project.
This is designed to be code generated with bijection dev.
AnyDataModel
Ƭ AnyDataModel:Object
A GenericDataModel that considers documents to be any and does not
support indexes.
This is the default before a schema is defined.
Index signature
▪ [tableName:string]: { document: any ; fieldPaths: GenericFieldPaths ; indexes: SystemIndexes ; searchIndexes: {} ; vectorIndexes: {} }
TableNamesInDataModel
Ƭ TableNamesInDataModel<DataModel>: keyof DataModel & string
A type of all of the table names defined in a GenericDataModel.
Type parameters
NamedTableInfo
Ƭ NamedTableInfo<DataModel, TableName>: DataModel[TableName]
Extract the TableInfo for a table in a GenericDataModel by table
name.
Type parameters
DocumentByName
Ƭ DocumentByName<DataModel, TableName>: DataModel[TableName]["document"]
The type of a document in a GenericDataModel by table name.
Type parameters
WritableTableNames
Ƭ WritableTableNames<DataModel>: { [Name in TableNamesInDataModel<DataModel>]: DataModel[Name] extends Object ? never : Name }[TableNamesInDataModel<DataModel>]
Tables accepting ordinary application writes according to generated ownership metadata.
Type parameters
TableKey
Ƭ TableKey<DataModel, Name>: 0 extends 1 & DataModel[Name] ? GenericId<Name> : DataModel[Name] extends { key: infer Key } ? Key : GenericId<Name>
Key accepted by a table-qualified read. A keyed view preserves its authoritative key domain.
Type parameters
ExternalCallStatus
Ƭ ExternalCallStatus:"pending" | "held" | "unknown" | "delivered" | "refused" | "indeterminate" | "delivered_unacknowledged" | "not_applied" | "duplicated" | "superseded"
Where a governed external call stands, as the operations owner records it.
pending: persisted, not yet delivered.held: waiting on its ordering domain or an approval.unknown: a dispatch’s outcome could not be established; it stays unknown until reconciled, and is never read as a failure.delivered,refused: the destination’s settled answer.indeterminate,delivered_unacknowledged,not_applied,duplicated: what reconciliation established when the answer itself was not proof.superseded: replaced by a later operation.
ExpressionOrValue
Ƭ ExpressionOrValue<T>: Expression<T> | T
An Expression or a constant Value
Type parameters
AccessFields
Ƭ AccessFields: readonlystring[] | "rest"
The fields a permission covers: a list, or every field no other
permission of the same map lists.
AccessRowGrant
Ƭ AccessRowGrant:string | { role: string ; members: { type: string ; permission: string } }
A field of a row that names users or groups and so confers a role on
them: a grant stored in the row.
AccessTypeDefinition
Ƭ AccessTypeDefinition:Object
One object type.
Type declaration
AccessRoleDefinition
Ƭ AccessRoleDefinition: readonlystring[] | { permissions: readonly string[] ; maxDuration?: number ; justification?: boolean ; selfGrant?: string }
A role: the permissions it bundles, as type:name, type:* or
type:grant.*, on its own type and descendant types. A role may bound
the duration of its grants, require a written reason on each, and let
holders of a permission of its type grant it to themselves: just-in-time
access, which must then be bounded and justified, and which ends no later
than the holder’s own grant of that permission.
AccessDirectory
Ƭ AccessDirectory:Object
A source-owned table of identity-provider memberships conferring role
on (member, object) pairs. index covers [member, object].
A row confers its role only while the source that published it (its
source_id) has completed an acquisition, has not lost continuity, and
was last observed less than maxAge milliseconds ago, read through
ctx.sources.coverage. A removal the provider exposes at time t therefore
takes effect by t + maxAge at the latest, whether or not the sync runs,
and a decision relying on a membership is valid until its source’s
observation is maxAge old. An observation stamped later than the
decision’s clock counts as made then, so no decision outlasts maxAge
from now. A row without a source, or a context without sources, confers
nothing.
Type declaration
AccessDirectoryCoverage
Ƭ AccessDirectoryCoverage:Pick<SourceCoverage, "acquired" | "observedTo" | "continuityLost">
What a directory’s freshness rule reads of a source’s coverage.
AccessRoleDefinitions
Ƭ AccessRoleDefinitions:Object
Roles tenants define as rows of table, each scoped to one object of the
scope type, which must be a tenant root type. Defining one needs
defineRoles on the scope object and every permission it bundles there,
held, for a permission added to a role already granted, at least as long
as those grants last; granting one needs grant.custom on the
object.
Type declaration
RoleDefinitionDocument
Ƭ RoleDefinitionDocument:Object
One tenant-defined role: the permissions, as type:name, of a role of
type usable on objects under the scope object scope. maxDuration
bounds its grants as a declared role’s does: each must expire within it,
and recertifying one renews it for at most that long.
Type declaration
AccessModelDefinition
Ƭ AccessModelDefinition:Object
The whole declaration.
Type declaration
AccessCtx
Ƭ AccessCtx:Object
The context a rule or helper needs. Every query context satisfies it.
Type declaration
AccessMutationCtx
Ƭ AccessMutationCtx:Object
The context of the grant mutation helpers.
Type declaration
GrantDocument
Ƭ GrantDocument:Object
One stored grant.
Type declaration
AccessPath
Ƭ AccessPath: {via: "grant" ; on: string ; role: string ; principal: string } | { via: "row" ; on: string ; role: string ; field: string } | { via: "directory" ; on: string ; role: string ; table: string ; source: string ; until: number }
How a permission was reached, for explain. A directory path names the
source that published the membership and the instant its observation
becomes too old to rely on.
AccessClaimType
Ƭ AccessClaimType:"String" | "Long" | "Bool" | "Set<String>" | "Set<Long>"
The type of a declared claim.
GrantInput
Ƭ GrantInput:Object
A grant to insert through grant.
Type declaration
GrantMutation
Ƭ GrantMutation:FunctionReference<"mutation", "internal", { id: GenericId<string> }>
A product internal mutation taking a grant’s id.
GrantReminder
Ƭ GrantReminder:Object
A review reminder for a bounded grant: notify, the product’s internal
mutation, runs before milliseconds ahead of the grant’s expiry (at once
when that moment has passed) with the grant’s id. It calls reviewDue
and commits the notice.
Type declaration
GrantOptions
Ƭ GrantOptions:Object
How grant and recertify schedule a bounded grant’s lapse, through
expire, the product’s export of expireGrant, and its review reminder.
Type declaration
AccessModel
Ƭ AccessModel:ReturnType<typeof buildModel>
The declared model and everything derived from it.
AccessCedarPolicies
Ƭ AccessCedarPolicies:Object
A model compiled to Cedar: a schema in Cedar’s schema syntax, one template
per role and the static policies, all in Cedar’s policy syntax. They depend
on the declaration only.
Type declaration
AccessCedarUid
Ƭ AccessCedarUid:Object
A Cedar entity reference in Cedar’s JSON format.
Type declaration
AccessCedarEntities
Ƭ AccessCedarEntities:Object
The Cedar data a world of rows determines, in Cedar’s JSON formats: the
entities, one template per tenant-defined role and scope, and one template
link per live grant or directory row.
Type declaration
ServiceName
Ƭ ServiceName:"ai-gateway"
A Bijection-managed service. The backend decides which names it accepts; this
type lists the ones the current release knows about.
SetupSupplier
Ƭ SetupSupplier:"administrator" | "account"
Who is holding the answer.
administrator is deployment configuration: the person who deployed this
definition knows it, it is the same for every connection they make, and it
may be recorded. account is the connecting customer’s own: their instance,
their region, their workspace. The distinction is not cosmetic — it decides
who is asked, what may be retained and, for a value that reaches a URL, how
far it is allowed to move.
SetupSlot
Ƭ SetupSlot:"base_url"
The one slot a setup value may fill beyond being recorded.
A value that fills base_url is rendered as prefix + value + suffix and
becomes the connection’s base URL. That is the ONLY way a supplied value
reaches an address, and it is why the rendering is a template the definition
wrote rather than a string the supplier wrote: the supplier contributes one
host label inside an address they did not choose, and the result still has
to pass the deployment’s ordinary base-URL confinement before any request is
built from it.
SetupValidation
Ƭ SetupValidation:Object
What an admitted value has to look like.
pattern is matched against the WHOLE value; there is no need to anchor it
and no way to leave it unanchored. It is restricted to the constructs Rust’s
regular expressions and JavaScript’s agree on, because the same pattern is
compiled on both sides and a pattern that means two things is worse than no
pattern at all: lookaround and backreferences are refused at definition time.
Type declaration
SetupField
Ƭ SetupField:SetupValidation & { key: string ; supplier: SetupSupplier ; label: string ; help?: string ; docUrl?: string ; example?: string ; prefix?: string ; suffix?: string ; secret?: boolean ; optional?: boolean ; derivable?: boolean ; fills?: SetupSlot }
One thing a connection has to be told.
SetupDeclaration
Ƭ SetupDeclaration: readonlySetupField[]
The declaration as it is written on an integration definition.
SetupRefusal
Ƭ SetupRefusal: {kind: "unknown_field" ; key: string } | { kind: "missing_required" ; key: string } | { kind: "pattern_mismatch" ; key: string } | { kind: "not_allowed" ; key: string } | { kind: "too_short" ; key: string ; minLength: number } | { kind: "too_long" ; key: string ; maxLength: number } | { kind: "secret_not_accepted" ; key: string } | { kind: "slot_not_one_label" ; key: string } | { kind: "not_account_supplied" ; key: string }
Why one supplied value was refused.
Exhaustive and typed on both sides of the boundary: the same variants are a
Rust enum the backend matches on, so a new kind of refusal is a compile
error rather than a new string nobody renders.
SetupRequirement
Ƭ SetupRequirement:SetupField & { configured: boolean }
What the deployment says about one declared field when asked what a
connection still needs.
It carries the declaration and ONE fact about the deployment: whether the
value is already held. It never carries a value — not a secret, and not a
recorded administrator value either, because a reader that does not need it
to fill a form does not need it at all.
IntegrationAddress
Ƭ IntegrationAddress:Object
Type declaration
SourceBinding
Ƭ SourceBinding:Object
Type declaration
WirePath
Ƭ WirePath: readonlystring[]
Paths select own wire-object fields, never arbitrary guest expressions.
HttpArgumentReference
Ƭ HttpArgumentReference:Object
A retained command argument, addressed by its own field path.
Type declaration
HttpInputReference
Ƭ HttpInputReference: {input: "checkpoint" | "resume" | "operation_id" | "expires_at" | "target_version" } | { input: "target_key" ; path?: WirePath } | { input: "created_key" } | HttpArgumentReference | { input: "parameter" ; path?: WirePath }
HttpInput
Ƭ HttpInput: {kind: "input" } & HttpInputReference
HttpTemplate
Ƭ HttpTemplate: {kind: "key_component" ; subject: HttpInputReference ; index: number } | { kind: "json_string" ; value: HttpTemplate } | { kind: "host" ; value: "listener_channel_id" | "listener_callback_url" | "listener_expiration" | "listener_resource_id" | "listener_channel_token" } | { kind: "resume_path" ; prefix: string } | { kind: "literal" ; value: JSONValue } | HttpInput | { kind: "object" ; fields: Record<string, HttpTemplate> } | { kind: "array" ; items: readonly HttpTemplate[] }
Selector
Ƭ Selector: {kind: "header" ; name: string } | { kind: "body" ; path?: WirePath }
Where one piece of evidence is read in a retained response. A provider’s
conditional token is often a header, so selection cannot assume a body.
BodyContract
Ƭ BodyContract: {kind: "none" } | { kind: "json" ; validator: Validator<any, any, any> } | { kind: "xml" ; validator: Validator<any, any, any> } | { kind: "jsonl" ; validator: Validator<any, any, any> } | { kind: "positional" ; schema: WirePath ; name: WirePath ; column_type: WirePath ; rows: WirePath ; cells: WirePath ; value: WirePath ; columns: Record<string, string> ; validator: Validator<any, any, any> } | { kind: "json_fields" ; fields: readonly string[] ; optional_fields?: readonly string[] } | { kind: "json_batch" ; selection: { items: WirePath ; fields: readonly string[] ; max_records: number ; scan_key?: string ; string_fields?: readonly WirePath[] ; parents?: { path: WirePath ; key: WirePath ; child_key: WirePath } } } | { kind: "opaque" }
The body an admitted status carries. These are three different things.
none is no body at all: a successful empty 204 declares it, and bytes
arriving anyway violate the contract rather than being an empty success.
json must parse and match the validator; malformed bytes are invalid at
that status and never degrade to an empty success. opaque is bytes the
host retains without interpreting, such as a provider answering an ordinary
error with HTML or plain text. opaque is not “ignore any body”: the status
is still evidence, and the body supplies no field evidence at all.
ResponseContract
Ƭ ResponseContract:Object
What may be interpreted from a response. A status outside statuses is
still retained, but proves only that the provider answered.
Type declaration
ScalarValue
Ƭ ScalarValue: {type: "bool" ; value: boolean } | { type: "text" ; value: string } | { type: "integer" ; value: string } | { type: "null" } | { type: "missing" }
An exact scalar a response field may equal. Matching is by type and value
together, so false, "false", null and an absent field stay four
different things. An integer is canonical decimal text compared against an
exact JSON integer, never through a float.
KeyEncoding
Ƭ KeyEncoding:"text" | "integer"
How one key component is read. integer preserves an exact provider
identifier: a value that is not an exact JSON integer is refused rather than
rounded, so a large numeric id never loses its low digits.
KindMatch
Ƭ KindMatch:Object
Type declaration
RecordKindSource
Ƭ RecordKindSource: {kind: "fixed" ; record: "present" | "deleted" } | { kind: "match" ; path: WirePath ; variants: readonly KindMatch[] }
How a response says what each of its records is. Providers differ: one tags
rows with a string, another with a boolean archived flag, and an endpoint
that only ever returns live records says nothing at all.
KeyPart
Ƭ KeyPart: {kind: "literal" ; value: string } | { kind: "mapped_field" ; path: WirePath ; values: Record<string, string> } | HttpInput | { kind: "field" ; path: WirePath ; encoding: KeyEncoding }
One component of a compound key. A provider returning association rows omits
the parent it was asked about, so identity is completed from the admitted
request context rather than from anything a response invented.
RecordKeySource
Ƭ RecordKeySource: {kind: "input" } & HttpInputReference | { kind: "field" ; path: WirePath ; encoding: KeyEncoding } | { kind: "compound" ; parts: readonly KeyPart[] }
How each record’s key is assembled.
ResumeSource
Ƭ ResumeSource: {kind: "stated" ; from: Selector } | { kind: "while_more" ; from: Selector } | { kind: "link_relation" ; header: string ; relation: string } | { kind: "last_record_key" } | { kind: "maximum_field" ; path: WirePath }
Where the position the NEXT acquisition request resumes from comes from.
stated is the provider’s own cursor, read from the position it states it
at. last_record_key is the after=<id> walk: the provider states no cursor
and the next request continues after the LAST record this response returned,
so the HOST derives the position from the keys it already verified against
this same response’s declared key. The connector composes nothing, because
a position the host cannot check against retained evidence is one a guest
could move backwards over records already published. An empty page names no
last row and therefore derives no position.
maximum_field is the third, and it is the same derivation over a different
value: the provider states no cursor and the next request continues from the
LARGEST value a declared ordered field took over this page’s records —
Odoo’s write_date >= <the largest one you saw>, and BigQuery’s APPENDS
instant. It exists because neither other arm can say it: there is no stated
cursor to select, and the last ROW’s key is a different value in a different
domain from the one the request filters on.
Two rules come with it. The values are compared as the PROVIDER spelled them,
so every row must carry the field as text of one width — a fixed-width
timestamp orders by bytes and "9" against "10" does not, so a page mixing
widths is refused rather than positioned wrongly. And the continuation is
INCLUSIVE of its own boundary, because the field’s rendering may be coarser
than the comparison the provider makes on it: Odoo renders write_date to
the second and compares at full stored precision, so a strict > returns the
row it came from. The boundary row is therefore re-read on every resume, and
the declaration owes an opaque record version so that the re-read row is
deduplicated by (key, version) instead of churning history.
That inclusiveness is also why the walk needs an end: the last page returns
its boundary row and nothing else, and its maximum is the position the
request already carried. The host derives a position only where what it
computed is STRICTLY GREATER than the one this request resumed from, and an
empty page derives none, so a finished walk exhausts instead of asking for
the same page for ever.
RecordProjection
Ƭ RecordProjection:Object
Type declaration
HttpEvidence
Ƭ HttpEvidence: {kind: "resources" ; items?: WirePath ; id: { path: WirePath ; encoding: KeyEncoding } ; label?: WirePath ; next_page?: WirePath } | { kind: "query_result" ; collection: string ; items: WirePath ; columns: WirePath ; column_names: readonly string[] ; key_prefix: readonly string[] ; key_columns: readonly number[] ; has_more: WirePath ; is_cached: WirePath ; calculated_at: WirePath ; calculated_at_field: string } | { kind: "identity" ; account?: { path: WirePath ; encoding: KeyEncoding } ; incarnation?: WirePath } | { kind: "feed" ; collection: string ; items: WirePath ; discriminator: WirePath ; variants: Record<string, { kind: "replace" | "delete" ; key: WirePath ; position: WirePath }> ; through: WirePath ; head: WirePath ; has_more: WirePath } | { kind: "records" ; collection: string ; subject?: HttpInputReference ; items?: WirePath ; parents?: WirePath ; sole?: WirePath ; presence: RecordKindSource ; key: RecordKeySource ; version?: Selector ; complete?: WirePath ; more?: WirePath ; end_cursor?: WirePath ; resume?: ResumeSource ; exact?: readonly { path: WirePath ; encoding: { kind: "decimal_string" } | { kind: "minor_units" ; scale: number } | { kind: "implied_decimals" ; scale: number } }[] } | { kind: "projections" ; records: readonly RecordProjection[] } | { kind: "incremental" ; collection: string ; items: WirePath ; items_optional?: boolean ; presence: RecordKindSource ; key: RecordKeySource ; version?: Selector ; next_page: Selector ; next_sync: Selector ; terminal?: WirePath ; sync_parameter: string ; page_parameter: string ; reset_status: number } | { kind: "traversal" ; collection: string ; deletions: readonly string[] ; items: readonly { parents?: WirePath ; parents_optional?: boolean ; items: WirePath ; items_optional?: boolean ; key: WirePath ; version?: WirePath ; presence: RecordKindSource }[] ; duplicates: "present" | "deleted" | "last" ; next_page?: Selector ; checkpoint?: Selector ; checkpoint_name: string ; page_parameter?: string ; checkpoint_parameter?: string ; reset_status: number ; terminal_without_checkpoint?: boolean } | { kind: "discovery" ; collection: string ; items: WirePath ; presence: RecordKindSource ; key: RecordKeySource ; complete?: WirePath ; resume?: Selector ; continuation?: HttpInputReference } | { kind: "data" } | { kind: "checkpoint" ; name: string ; value: Selector } | { kind: "command" ; command: string ; outcome: { kind: "status" } | { kind: "selected" ; from: Selector } | { kind: "presence" ; of: WirePath } ; outcomes: Record<string, { kind: "confirmed" ; target_key?: Selector ; effects?: readonly { response: WirePath ; input: HttpArgumentReference }[] ; observation?: { key: WirePath ; position: WirePath } } | { kind: "rejected" | "pending" | "unknown" } | { kind: "counted" } | { kind: "withdrawn" } | { kind: "refused" }> ; refusal?: { name: Selector ; kinds: Record<string, "precondition_failed" | "member_missing" | "invariant_violated" | "malformed" | "identity_reused"> ; member?: { on: string[] ; reasons: WirePath ; code: WirePath ; unaffected: string } ; current?: { kind: "body" ; path: WirePath } | { kind: "member" ; path: WirePath } } ; attribution?: { kind: "echoed" ; operation_id: Selector } | { kind: "searched" ; list?: WirePath ; operation_id: WirePath ; complete?: WirePath ; more?: WirePath ; page: number } | { kind: "absence" ; target_key: Selector } | { kind: "created" } ; created?: Selector }
HttpContract
Ƭ HttpContract:Object
Type declaration
ResponseEvidence
Ƭ ResponseEvidence:string
A reference is only a lookup key; native admission checks its invocation.
IntegrationContext
Ƭ IntegrationContext<H>: Object
Type parameters
Type declaration
SourceProtocol
Ƭ SourceProtocol: {kind: "postgres_cdc" } | { kind: "change_feed" ; position: { domain: string ; encoding: "uint64_decimal" | "int64_decimal" } ; checkpoint: { initial: string ; continuity: "complete_prefix" ; retention: Retention } ; records: "full_or_delete" ; atomic_group: "one_change" } | { kind: "record_observation" ; version: { kind: "opaque" } | { kind: "none" } ; coverage: { kind: "enumeration" } | { kind: "query_result" ; max_rows: number } | { kind: "incremental_snapshot" ; max_rows: number } | { kind: "filtered" ; completeness: "stated" | "none" } | { kind: "none" } ; resume: { kind: "opaque_cursor" } | { kind: "none" } } | { kind: "measurement" ; shape: MeasurementShape ; cadence: { revisionsPerKeyPerMinute: number } }
What an acquisition actually proves. Records with a done flag and a
a resume cursor are not a change feed; declaring one would claim ordering and
completeness the provider never established.
MeasurementShape
Ƭ MeasurementShape: {shape: "twin_hot" } | { shape: "twin_cold" ; dwell_ms: number } | { shape: "window" ; definition: string ; revision: number ; window_ms: number ; lateness_ms: number } | { shape: "late_observation" } | { shape: "occurrence_log" } | { shape: "refusal" }
Which of the shapes a measurement collection holds.
Each is a different bound on the same quantity. The two twin shapes revise
one row per key; the other three append a row and are bounded by what
produces them — a closed interval, a transition, or a refusal.
CoupledResult
Ƭ CoupledResult<S>: wire.CoupledResult<{ [K in keyof S]: RecordObservation<ObjectType<S[K]>>[] }, keyof S & string>
What one coupled acquisition attempt claims, as a candidate only.
The envelope is generated; this states the two narrowings that are facts
about the declaration rather than about the wire, exactly as
ProtocolInput and ProtocolResult do below: records is a mapped type
over the author’s own collection schemas, and every collection named by an
unresolved key or a file request is one of the author’s own collections.
Type parameters
CouplingDefinition
Ƭ CouplingDefinition<S, H>: Object
One acquisition over a whole group of collections: the collections it owns,
the one interval the group is scheduled on, and the one reader.
Type parameters
Type declaration
ListenerProtocol
Ƭ ListenerProtocol: {kind: "queue" ; provider: "sqs" ; visibility_seconds: number ; wait_seconds: number ; poll_interval_ms: number ; proves: "refresh_hint" } | { kind: "socket" ; open: string ; address: Selector ; envelope: readonly string[] ; frame_kind: readonly string[] ; disconnect: string ; acknowledge: string ; max_frame_bytes: number ; proves: "refresh_hint" } | { kind: "push" ; ingress: ListenerIngress ; subscription?: { channel: { resource: readonly string[] ; proof: { channel_id: Selector ; resource_id: Selector ; resource_uri: Selector ; expiration: Selector } ; matching: { tolerated_query?: readonly string[] ; lifetime_ms: number ; renewal_margin_ms: number } } ; watch: string ; stop: string } } | { kind: "pull" ; poll: string ; interval_ms: number ; min_interval_ms: number ; max_interval_ms: number ; continuation: { kind: "validator" ; request_header: string ; response_header: string ; interval_header?: string ; quiet_status: number } | { kind: "cursor" ; parameter: string ; resume: ResumePrefix ; retention: Retention } ; position: { items?: readonly string[] ; id: readonly string[] ; order: "decimal" | "opaque" | "opaque_ascending" } ; keys?: { list: string ; items?: readonly string[] ; id?: readonly string[] ; parameter: string ; partition: readonly string[] } }
How change hints reach the engine for one collection, and the whole of what
a listener declares.
The variant is the transport class and it carries what that transport needs.
push has an ingress endpoint because the provider delivers to one; pull
has none, because nothing is delivered to it. Neither is an optional field a
declaration could leave empty.
A delivery, and equally a poll, is a refresh hint only: it asks the engine to
read again and proves nothing by itself. A listener’s collection declares its
own sync, because a hint asks for acquisition and there has to be one to
ask for.
CollectionDefinition
Ƭ CollectionDefinition<S, H, P>: CollectionShape<S, P> & { sync: { every: SyncEvery ; read: (ctx: IntegrationContext<H>, input: ProtocolInput<P>) => Promise<ProtocolResult<P, ObjectType<S>>> } }
A collection acquired on its own: it declares its own interval and its own
reader.
Type parameters
CoupledCollectionDefinition
Ƭ CoupledCollectionDefinition<S, P>: CollectionShape<S, P> & { sync?: never }
A collection of a coupled group. One acquisition walks the whole group, so
the group’s coupling owns the interval and the read and the collection
declares neither: a per-collection sync here would name a schedule nothing
runs and a reader nothing calls.
Type parameters
CommandCondition
Ƭ CommandCondition: {kind: "target_version" ; from: { kind: "record_observation_position" } | { kind: "record_version" } } | { kind: "unconditional" } | { kind: "field_ownership" }
Exact native provenance for the provider’s conditional version. An ordered
feed position and an opaque record token are not interchangeable.
unconditional states that the destination enforces no compare-and-set on
this endpoint, so the request carries no provider conditional token at all.
It is the ABSENCE of a precondition, never an empty or fabricated one, and it
promises nothing about writers acting directly in the provider.
CommandGoverningResult
Ƭ CommandGoverningResult: [Exclude<GoverningResult, null> & { recheckAt?: never } | null | { recheckAt: number ; validUntil?: never }]
A command rule decides one command and returns a one-element list: the
shared permitting results plus command-only advisory deferral. A bare
value, an empty or longer list, and a rule that falls off its end refuse.
recheckAt denies now and requests a future evaluation; it is never permission.
Its timestamp has the same finite safe-integer epoch-millisecond, strictly
future, at-most-366-day bounds as validUntil. Review, acceptance and send
require a permitting result whose validity extends past the actual commit.
The native decoder rejects unknown fields and mixed permit/defer objects.
A rule that never defers declares returns: readAccessResults.
CommandTarget
Ƭ CommandTarget:GenericId<string> | { sourceId: string }
Existing records use their local ID. Creates address one installed source,
including when several accounts populate the same table. The host enforces
the target kind against the command declaration and rechecks its binding.
CommandGoverningInput
Ƭ CommandGoverningInput:Object
Type declaration
CommandGoverningDefinition
Ƭ CommandGoverningDefinition:FunctionReference<"query", "public" | "internal", any, CommandGoverningResult> | { query: FunctionReference<"query", "public" | "internal", any, CommandGoverningResult> ; reads: readonly string[] }
A command policy may read named private inputs at review, admission and
send. Only its decision is released; reads do not become caller authority.
Commands always evaluate the current final basis.
CommandStates
Ƭ CommandStates<A>: Object
The change a record-targeted command’s send REQUESTS of its target record,
field by field: each key is a field of the target collection’s schema, and
each value is the path into this command’s arguments whose value the request
asks that field to take. Every path names REQUIRED arguments, and the
argument’s type must be one the field admits.
It is read only on a branch, where nothing is delivered: a held call whose
command states its change is shown there as that change, with assumed
provenance, so the branch’s views show its consequence. It never becomes
evidence that the destination applied anything, and fields the provider
computes — assigned identifiers, totals — are not stated and stay as last
observed. A create cannot state a change: its record’s key is the
provider’s to assign.
Type parameters
Index signature
▪ [field:string]: readonly [keyof A & string, …string[]]
CommandDefinition
Ƭ CommandDefinition<A, S, H>: CommandShape<A, S> & { creates?: undefined ; states?: CommandStates<A> ; send: (ctx: IntegrationContext<H>, input: CommandInput<A>) => Promise<CommandResult<S>> ; reconcile: (ctx: IntegrationContext<H>, input: Omit<CommandInput<A>, "expires_at">) => Promise<CommandResult<S>> } | CommandShape<A, S> & { creates: { kind: "deduplicated" } | { kind: "stored" } | { kind: "unattributed" } ; states?: undefined ; send: (ctx: IntegrationContext<H>, input: CreateCommandInput<A>) => Promise<CommandResult<S>> ; reconcile: (ctx: IntegrationContext<H>, input: Omit<CreateCommandInput<A>, "expires_at">) => Promise<CommandResult<S>> }
One command.
The two arms differ in exactly one fact and everything else follows from it:
whether the send addresses a RECORD of the target collection or the
COLLECTION itself. A record-targeted command’s handlers receive that
record’s key; a create’s do not, because the record does not exist yet, and
they receive the operation’s own identity instead.
Type parameters
CommandHandle
Ƭ CommandHandle<Args>: Object
Type parameters
Type declaration
CommandArgs
Ƭ CommandArgs<C>: C extends CommandHandle<infer Args> ? Args : never
Type parameters
ApprovalId
Ƭ ApprovalId:GenericId<"_approvals">
ExternalCallId
Ƭ ExternalCallId:string & { __externalCallId: unique symbol }
SourceCoverage
Ƭ SourceCoverage:Object
What the engine can prove about one installed source’s population.
Every field is derived from the evidence the capture and acquisition owners
already record for that source alone. There is no credential, destination
name or provider identifier here, and a value read for one source discloses
nothing about another.
Type declaration
SourceFetchValue
Ƭ SourceFetchValue:string | bigint | boolean | ArrayBuffer
An exact value a fetch filter compares a declared field with: the value
the field is published as. There is no number: an approximate value has
no exact equality. An integer column’s value is a bigint; an exact
decimal, a date or a timestamp is its canonical text, a decimal at its
column’s scale ("12.50", not "12.5").
SourceFetchOptions
Ƭ SourceFetchOptions:Object
One pinned, bounded read of an installed source’s table.
Type declaration
SourceFetchReceipt
Ƭ SourceFetchReceipt:Object
What a fetch read.
Type declaration
SourceFetchErrorCode
Ƭ SourceFetchErrorCode:"ReadAccess" | "ActionDisclosure" | "IntegrationReinstallRequired" | "SourceFetchArguments" | "SourceFetchUnavailable" | "SourceFetchUnsupported" | "SourceFetchUnpinned" | "SourceFetchUndeclaredField" | "SourceFetchTooManyFilters" | "SourceFetchFilterValue" | "SourceFetchPosition" | "SourceFetchContinuation" | "SourceFetchSourceReplaced" | "SourceFetchHistoryUnavailable" | "SourceFetchRowBound" | "SourceFetchInexactFilter"
Why a fetch was refused. ReadAccess: the source’s read rule refused the
rows the filters name. ActionDisclosure: the action holds protected
information from elsewhere than this source’s rows, which the fetch would
send to the source. SourceFetchHistoryUnavailable: the source no
longer retains the pinned position; fetch again without at.
SourceFetchSourceReplaced: the table is not the installed incarnation.
SourceFetchInexactFilter: the source’s comparison matched a row whose
value differs from a filter’s.
SourceFetchErrorData
Ƭ SourceFetchErrorData:Object
The data of the BijectionError a refused fetch throws.
Type declaration
SourceHandle
Ƭ SourceHandle<S>: Object
Type parameters
Type declaration
ConnectionBudget
Ƭ ConnectionBudget: {capacity: number ; restorePerSecond: number ; restorePerMinute?: undefined ; perMinute?: undefined } | { capacity: number ; restorePerMinute: number ; restorePerSecond?: undefined ; perMinute?: undefined } | { perMinute: number ; capacity?: undefined ; restorePerSecond?: undefined ; restorePerMinute?: undefined } & { requestCost?: number ; stated?: { available: Selector ; capacity?: Selector ; restorePerSecond?: Selector } }
What one connection may spend, and where the provider’s answers state it.
The budget belongs to the connection rather than to a collection: the
provider counts it against the credential, so every collection, listener and
command that speaks through one connection shares one bucket. Declare it in
whichever form the provider publishes — a cost bucket with a restore rate,
or a count per minute — and the engine keeps one quantity either way.
stated names where an answer carries the provider’s own figure. A stated
availability can only lower what the engine believes it has, because the
engine counts its own requests and the provider counts everybody’s; a stated
ceiling or rate replaces the declared one, because those are the provider’s
contract rather than a measurement.
BackoffRepresentation
Ƭ BackoffRepresentation:"secondsFromResponse" | "epochSeconds" | "epochMillis" | "httpDate" | "retryAfter"
How a stated backoff value is spelled.
secondsFromResponseis a duration from the answer, in seconds. It admits RFC 9110 delta-seconds (Retry-After: 120) and a fractional seconds-remaining (x-ratelimit-reset-after: 0.529) alike: those are one quantity written two ways, and a fraction is always rounded up so a wait never comes out shorter than the one asked for.epochSecondsandepochMillisare an absolute instant. The two cannot be told apart from the value, so the declaration names the unit.httpDateis an absolute instant as an RFC 9110 HTTP-date. The two obsolete date forms are not read.retryAfteris theRetry-Afterheader itself, which RFC 9110 lets a provider spell either way in the same header; the form is decided by the value rather than by the declaration.
ConnectionBackoff
Ƭ ConnectionBackoff:Object
When this provider will accept another request, and where its answers say
so.
It belongs to the connection rather than to a collection or a command,
because a provider throttles the credential. Declare the statuses this
provider states a wait on, where the statement is, and the longest wait this
integration will honour on its own; a provider asking for longer holds the
connection for an operator instead of sleeping for it.
Every declared signal is read and the LATEST instant any of them names is
the one honoured: two fields stating one quantity can disagree, and waiting
longer is the only safe direction.
IT NEVER AUTHORIZES REPEATING AN OPERATION. This says when the provider will
accept another request. Whether a particular external command may be sent
again is decided by that command’s own delivery contract from its retained
operation identity, and nothing declared here reaches that decision.
Type declaration
ReplicationTransport
Ƭ ReplicationTransport:Record<string, never>
A PostgreSQL logical replication slot, pgoutput protocol v1. Physical
relation names, publication and credentials are private installation
configuration and are never declared here.
MailboxTransport
Ƭ MailboxTransport:Object
One mailbox session. The account, endpoint, selected folders and
credentials are private installation configuration; a declaration names only
the three projections it publishes.
Type declaration
StreamTransport
Ƭ StreamTransport:Object
One device stream.
The broker address, its partitions and its credentials are private
installation configuration; a declaration names only the topic and the four
record fields the engine reads. correlation is the field a device’s
acknowledgement carries its command’s operation identity in: a protocol that
omits it declares that it does not acknowledge, and a command against such a
protocol is refused rather than confirmed from a later reading.
The batch cadence is each collection’s own every, exactly as it is for the
other host-executed transports, so a hot twin’s declared revision rate has
one owner rather than a second number here.
Type declaration
AcquisitionTransport
Ƭ AcquisitionTransport: {transport: "replication" ; value: ReplicationTransport } | { transport: "mailbox" ; value: MailboxTransport } | { transport: "stream" ; value: StreamTransport } | { transport: "dynamo_db" ; value: { collection: string } } | { transport: "git" ; value: { collection: string } } | { transport: "big_query" ; value: { collection: string } } | { transport: "sheets" ; value: { collection: string } } | { transport: "kubernetes" ; value: { collection: string } } | { transport: "bayeux" ; value: BayeuxTransport } | { transport: "mongo" ; value: { collection: string ; fields: Record<string, string> ; max_initial_rows: number } } | { transport: "sql" ; value: SqlTransport } | { transport: "dataset" ; value: DatasetTransport } | { transport: "bijection" ; value: BijectionTransport } | { transport: "sftp" ; value: SftpTransport } | { transport: "odata" ; value: ODataTransport }
The declared transport. The discriminator is spelled transport because
that is what it selects; there is no acquisition kind beside it.
SyncInput
Ƭ SyncInput:FeedInput | IncrementalInput | EnumerationInput | SweepInput
The read arguments of one acquisition.
Untagged, because that is the shipped wire and the guest branches on which
fields are present. The three shapes have disjoint required fields and each
refuses unknown ones, so the union stays unambiguous in both directions.
FeedInput
Ƭ FeedInput:Object
Type declaration
IncrementalInput
Ƭ IncrementalInput:Object
Type declaration
EnumerationInput
Ƭ EnumerationInput:Object
Type declaration
SweepInput
Ƭ SweepInput:Object
One batch of a reconciliation sweep: the keys this engine has already
published that this pass is to read again.
The keys are the HOST’s, resolved from publication and pinned on the
acquisition’s own start, so the read that goes out is addressed at a key the
engine holds rather than one a connector chose. There is no cursor here and
no listing: a sweep asks the provider about named records and the provider
answers about exactly those.
Type declaration
CoupledInput
Ƭ CoupledInput:Object
What the host gives one coupled acquisition attempt.
Every field is host state the attempt is checked against, and none of it is
something an integration may invent. It is its own shape rather than a
member of SyncInput because a coupled group has its own reader: the
group’s coupling.read is called with this, a collection’s own sync.read
is called with a SyncInput, and no handler ever receives both.
Type declaration
ChangeFeedResult
Ƭ ChangeFeedResult<T>: Object
What one change-feed read claims.
Type parameters
Type declaration
Observation
Ƭ Observation<T>: { kind: "replace" ; evidence: string ; item_index: number ; key: string ; position: string ; value: T } | { kind: "delete" ; evidence: string ; item_index: number ; key: string ; position: string }
One observed change in an ordered feed.
evidence cites the retained response that proved it; item_index is the
item’s position within that response, which is how the host matches a
guest’s interpretation to the evidence rather than trusting its order. A
feed item is a replacement or a deletion, and both carry the position the
provider stated. There is no third case: a feed that cannot say which of the
two an item is has no evidence contract here.
Type parameters
RecordResult
Ƭ RecordResult<T>: ResetResult | EnumerationResult<T> | FanoutResult<T> | KeyedFanoutResult<T> | SweepResult<T> | SnapshotResult<T>
What one record-observation read claims.
Untagged, because that is the shipped wire: the guest returns a bare object
and branches on which fields it filled. The four shapes are told apart by
fields no other shape admits — reset, next_page/next_sync, complete,
unresolved — and each refuses the others’ fields, so the union stays
unambiguous in both directions.
Type parameters
RecordObservation
Ƭ RecordObservation<T>: { kind: "present" ; evidence: string ; item_index: number ; key: string ; version?: string ; value: T } | { kind: "deleted" ; evidence: string ; item_index: number ; key: string }
One observed record.
version is an opaque equality token and never a position; a deletion
carries neither a version nor a value, because a record the provider says is
gone has no state to project.
Type parameters
TransactionMetric
Ƭ TransactionMetric:Object
Used and remaining amounts for a single transaction limit.
Type declaration
TransactionMetrics
Ƭ TransactionMetrics:Object
The remaining headroom for a transaction before hitting limits.
See https://docs.bijection.com/production/state/limits
Type declaration
FunctionMetadata
Ƭ FunctionMetadata:Object
Metadata about the currently executing Bijection function.
Type declaration
DeploymentMetadata
Ƭ DeploymentMetadata:Object
Metadata about the deployment this function is running on.
Type declaration
RequestMetadata
Ƭ RequestMetadata:Object
Metadata about the HTTP request that triggered the current function execution.
ip and userAgent are null when the function was not triggered by an
HTTP request (e.g. scheduled jobs or cron jobs).
Functions called from within a function (i.e. using runMutation or
runAction) will have the same request metadata as the parent function.
Type declaration
OperationInterfaceContract
Ƭ OperationInterfaceContract:Object
A shared operation shape. The concrete operation supplies its target ID
domain and all execution/authorization behavior.
Type declaration
OperationContract
Ƭ OperationContract:Object
The analyzed business contract paired with a generated operation reference.
It identifies a declaration and grants no authority.
Type declaration
OperationContractMetadata
Ƭ OperationContractMetadata:Object
A contract and the digest carried by its generated reference.
Type declaration
OperationImplementation
Ƭ OperationImplementation<Args, Result>: Object
Protected discovery returns concrete, recoverable operation addresses.
The phantom fields preserve the shared argument/result types.
Type parameters
Type declaration
OperationInterfaceDefinition
Ƭ OperationInterfaceDefinition<Args, Result>: RegisteredQuery<"public", { on?: string }, Promise<OperationImplementation<Args, Result>[]>> & { }
A shared capability and its ordinary discovery query. It supplies no
storage, target authority, approvals or implementation.
Type parameters
ComponentOperationManifest
Ƭ ComponentOperationManifest:Record<string, OperationContractMetadata & { functions: Record<"invoke" | "preview" | "recover" | "status" | "revise", string> }>
Generated component exports bind a contract to each actual adapter address.
OperationReference
Ƭ OperationReference<Visibility, Args, LocalResult, ComponentPath>: Object
A generated business operation reference. This is distinct from an ordinary
query, mutation or action reference.
Type parameters
Type declaration
OperationArgs
Ƭ OperationArgs<Operation>: Operation["_args"]
Arguments inferred from an operation reference.
Type parameters
OperationLocalResult
Ƭ OperationLocalResult<Operation>: Operation["_returnType"]
The operation’s validated local result, independent of remote outcomes.
Type parameters
OperationInvocationId
Ƭ OperationInvocationId:string & { __operationInvocationId: unique symbol }
An accepted business invocation’s opaque identity. It is a locator and grants
no permission to read or change that invocation.
OperationAcceptance
Ƭ OperationAcceptance<LocalResult>: Object
Evidence that the local preparation committed. This does not establish a
provider’s application of any external call.
Type parameters
Type declaration
OperationRecovery
Ƭ OperationRecovery<LocalResult>: { kind: "absent" } | { kind: "accepted" } & OperationAcceptance<LocalResult>
Recovery inspects the original request; an absent result does not itself
authorize submitting different arguments or a new request identity.
Type parameters
OperationPreview
Ƭ OperationPreview<LocalResult>: Object
A native evaluation result on one provisional basis. It grants no approval,
acceptance, reservation or permission to execute later.
Type parameters
Type declaration
OperationReviewState
Ƭ OperationReviewState: {kind: "none" } | { kind: "awaiting_review" ; operation: string ; blocker: string ; responsible: string ; since: bigint | null } | { kind: "waiting" ; operation: string ; blocker: string ; responsible: string ; until: bigint | null } | { kind: "approved" ; approval: string ; approved_by: string ; beneficiary: string ; decided_at: number ; expires_at: bigint } | { kind: "awaiting_approval" ; approval: string ; approved_by: string ; beneficiary: string ; expires_at: bigint } | { kind: "rejected" ; approval: string ; approved_by: string ; beneficiary: string }
Whether a request is held, and who must act. Every variant is derived from a
retained row at read time: the approval the request consumed, or the refusal
the ordinary dispatch evaluator returns for one of its external calls. No
variant is inferred from how long a request has been waiting. Instants are
epoch milliseconds: exact bigint where the engine stores an integer, and
number for decided_at, which is the row’s own _creationTime.
OperationStatus
Ƭ OperationStatus:Omit<OperationAcceptance, "local_result"> & { external_calls: { id: string ; delivery: "pending" | "held" | "unknown" | "delivered" | "refused" | "indeterminate" | "delivered_unacknowledged" | "not_applied" | "duplicated" | "superseded" ; publication: null | { kind: "pending" } | { kind: "blocked" } | { kind: "published" ; revision: bigint } }[] ; summary: { total: bigint ; pending: bigint ; unknown: bigint ; refused: bigint ; delivered: bigint ; superseded: bigint ; delivered_unacknowledged: bigint ; publication_pending: bigint ; not_applied: bigint ; duplicated: bigint } ; review: OperationReviewState }
The retained state of one accepted request: its acceptance identity, the
delivery and publication state of each external call it accepted, and its
review state. Delivery values describe local knowledge of the destination,
never proof that the provider applied anything. Status excludes the original
business result. Recovering that result requires retained content protection;
status rechecks current authority without releasing the earlier content.
OperationErrorCode
Ƭ OperationErrorCode:"OperationAccess" | "OperationArguments" | "OperationDefinitionChanged" | "OperationInvocationAccess" | "OperationInvocationBounds" | "OperationInvocationCustody" | "OperationInvocationNotFound" | "OperationObjectType" | "OperationTarget" | "OperationRequestConflict" | "OperationReadProvenanceUnavailable" | "OperationPreviewContext" | "OperationPreviewCapability" | "OperationRetired" | "OperationResultExpired"
Native operation invocation error codes.
OperationErrorData
Ƭ OperationErrorData:Object
Native invocation error data carried by the ordinary BijectionError. This
identifies the refused boundary; it does not describe an external outcome.
Type declaration
OperationFunctionReferences
Ƭ OperationFunctionReferences<Visibility, Args, LocalResult>: Object
Actual generated adapter addresses, for components with explicit export
mappings. No companion address is inferred from an arbitrary component alias.
Type parameters
Type declaration
OperationRevision
Ƭ OperationRevision:Object
What revise reports: which of a request’s external calls were re-stamped
onto the current contract, and which already named it. A call that was ever
held is not in either list — it refuses, and the whole revision with it.
Type declaration
OperationDefinition
Ƭ OperationDefinition<Visibility, Args, LocalResult>: { isOperation: true } & Visibility extends "public" ? { isPublic: true } : { isInternal: true }
A business declaration lowered to ordinary transactional mutation and query
execution. Its object association supports discovery and grants no authority.
Type parameters
OperationBuilder
Ƭ OperationBuilder<DataModel, Visibility>: <ArgsValidator, ReturnsValidator>(definition: { on: ViewDefinition<any, any, any> | TableDefinition<any, any, any, any, false> ; target?: { argument: string } ; implements?: readonly OperationInterfaceDefinition<any, any>[] ; consumes?: PublicationConsumption ; args: ArgsValidator ; returns: ReturnsValidator ; prepare: (ctx: BijectionMutationCtx<DataModel>, args: OperationArgsFromValidator<ArgsValidator>) => ReturnValueForOptionalValidator<ReturnsValidator> }) => OperationDefinition<Visibility, OperationArgsFromValidator<ArgsValidator>, Infer<AsObjectValidator<ReturnsValidator>>>
Type parameters
Type declaration
▸ <ArgsValidator, ReturnsValidator>(definition): OperationDefinition<Visibility, OperationArgsFromValidator<ArgsValidator>, Infer<AsObjectValidator<ReturnsValidator>>>
The schema-specific type used by generated server utilities.
Type parameters
Parameters
Returns
OperationDefinition<Visibility, OperationArgsFromValidator<ArgsValidator>, Infer<AsObjectValidator<ReturnsValidator>>>
Cursor
Ƭ Cursor:string
An opaque identifier used for paginating a database query.
Cursors are returned from paginate and represent the
point of the query where the page of results ended.
To continue paginating, pass the cursor back into
paginate in the PaginationOptions object to
fetch another page of results.
Note: Cursors can only be passed to exactly the same database query that
they were generated from. You may not reuse a cursor between different
database queries.
PublicationConsumption
Ƭ PublicationConsumption:Object
Enforced by the native reader before the declared function body runs.
Type declaration
PublicationRequirement
Ƭ PublicationRequirement:Object
A transaction-local requirement, using concrete native checkpoint values.
Type declaration
PublicationReadiness
Ƭ PublicationReadiness: {kind: "ready" } | { kind: "pending" ; reason: "PublishedUnavailable" | "PublicationUnavailable" | "PublicationSourceUnavailable" | "PublicationGroupMismatch" | "PublicationEvidenceUnavailable" | "PublicationRootMismatch" | "PublicationRootOverlap" | "PublicationCoverage" }
Current native serving state under this query’s read and access dependencies.
PublicationEvidence
Ƭ PublicationEvidence: {kind: "unknown" } | { kind: "certified" ; roots: { table: string ; source: string | null ; readBasis: string ; observedFrom: string | null ; observedTo: string | null }[] ; partitionedRoots: number }
PublicationCapture
Ƭ PublicationCapture:Object
A page read and attested by the native database owner.
Type declaration
PublicationServing
Ƭ PublicationServing: {kind: "unmanaged" } | { kind: "transitioning" ; publisher: string | null ; producer: string | null ; retired: boolean ; isInitial: boolean } | { kind: "serving" | "withdrawn" ; publisher: string ; producer: string ; group: string ; selection: string ; run: string ; evidence: PublicationEvidence }
PublisherScanRefusal
Ƭ PublisherScanRefusal:"manifestFailed" | "manifestInvalid" | "undeclaredProducer" | "relationOwnedElsewhere" | "servingUnverifiable"
Why the native publisher scan cannot use the producer’s declaration.
PublicationStatus
Ƭ PublicationStatus:Object
Type declaration
SerializedPublished
Ƭ SerializedPublished:Object
The wire form of one published-relation declaration, exactly as the
deployment compiler decodes it.
Type declaration
PublisherDefinition
Ƭ PublisherDefinition:Object
A publisher a business program declares.
A published relation’s rows are the engine’s to write. Something has to tell
the engine what to write, and it cannot be a syscall: opening a receipt
grants no authority, and a guest mutation’s transaction carries the guest’s
identity. So the direction is inverted. The program declares three internal
queries, the engine reads them under its own identity, and it verifies every
byte it is handed before any of it reaches a relation.
manifest, a query answering which runs are ready to publish: for each, the producer, the execution basis the transform ran under, how many steps it took and the output members with their row and byte counts. It is read inside the engine’s scan transaction, so the rows it reads become the publisher’s region set: a committed write that makes a run ready is what wakes the driver, and between runs nothing runs.steps, a query paging one ready run’s step records — each step’s state, its input digest, its continuation and the sealed receipt token the engine re-opens for itself.page, a query paging one output member’s staged rows in key order.
rebuild internal mutation records desired state after an
ownership transition. It uses the ordinary commit path and receives no
publication authority; the native driver still owns the binding switch.
Type declaration
ReadAccessRequest
Ƭ ReadAccessRequest:Infer<typeof requests>[number]
One native object or searched-domain authorization obligation.
ReadAccessArgs
Ƭ ReadAccessArgs:Object
The complete batch passed to a scoped read authorization query.
Type declaration
ReadAccessResult
Ƭ ReadAccessResult:null | { validUntil: number ; reason?: string } | { reason: string }
One request’s result: null permits it with no clock-dependent expiry,
{ validUntil } permits it until then. A permission may also say why it
permits, { reason } or { validUntil, reason }: a string of at most 256
UTF-8 bytes, which permits exactly as the same result without it. The
engine records it on its audit line of an audited table (.access(\{ audit: true \}), which covers the table’s read, disclose and write rules) and
never shows it to the caller; a longer or non-string reason refuses.
Throw to refuse. A rule says why it refuses with
throw new BijectionError({ kind: "AccessRefused", why }), which the audit
line records (cut to 256 bytes); the caller of a rule that declares its
inputs sees only the engine’s fixed refusal.
ReadAccessResults
Ƭ ReadAccessResults:ReadAccessResult[]
What every rule returns: one result per item it decides, in order — per
request for a read or disclosure rule, per change for a table’s write rule
(.govern, [] for no change), and a one-element list for an integration
command’s rule. The engine refuses the batch unless every item has a
permitting result, so an item a rule never looked at is refused rather
than permitted. A bare null, and a rule that falls off its end (which
reaches the engine as null), refuses. A rule that permits without
looking must say so for each item.
DisclosureArgs
Ƭ DisclosureArgs:Object
Native fixed-output disclosure request.
Type declaration
GenericMutationCtxWithTable
Ƭ GenericMutationCtxWithTable<DataModel>: Omit<GenericMutationCtx<DataModel>, "db"> & { db: GenericDatabaseWriterWithTable<DataModel> }
A set of services for use within Bijection mutation functions.
The mutation context is passed as the first argument to any Bijection mutation
function run on the server.
You should generally use the MutationCtx type from
"./_generated/server".
Type parameters
GenericQueryCtxWithTable
Ƭ GenericQueryCtxWithTable<DataModel>: Omit<GenericQueryCtx<DataModel>, "db"> & { db: GenericDatabaseReaderWithTable<DataModel> }
A set of services for use within Bijection query functions.
The query context is passed as the first argument to any Bijection query
function run on the server.
This differs from the MutationCtx because all of the services are
read-only.
Type parameters
DefaultFunctionArgs
Ƭ DefaultFunctionArgs:Record<string, unknown>
The default arguments type for a Bijection query, mutation, or action function.
Bijection functions always take an arguments object that maps the argument
names to their values.
ArgsArray
Ƭ ArgsArray:OneArgArray | NoArgsArray
An array of arguments to a Bijection function.
Bijection functions can take either a single DefaultFunctionArgs object or no
args at all.
ArgsArrayToObject
Ƭ ArgsArrayToObject<Args>: Args extends OneArgArray<infer ArgsObject> ? ArgsObject : EmptyObject
Convert an ArgsArray into a single object type.
Empty arguments arrays are converted to EmptyObject.
Type parameters
FunctionVisibility
Ƭ FunctionVisibility:"public" | "internal"
A type representing the visibility of a Bijection function.
RegisteredMutation
Ƭ RegisteredMutation<Visibility, Args, Returns>: { isBijectionFunction: true ; isMutation: true } & VisibilityProperties<Visibility>
A mutation function that is part of this app.
You can create a mutation by wrapping your function in
mutationGeneric or internalMutationGeneric and exporting it.
Type parameters
RegisteredQuery
Ƭ RegisteredQuery<Visibility, Args, Returns>: { isBijectionFunction: true ; isQuery: true } & VisibilityProperties<Visibility>
A query function that is part of this app.
You can create a query by wrapping your function in
queryGeneric or internalQueryGeneric and exporting it.
Type parameters
RegisteredAction
Ƭ RegisteredAction<Visibility, Args, Returns>: { isBijectionFunction: true ; isAction: true } & VisibilityProperties<Visibility>
An action that is part of this app.
You can create an action by wrapping your function in
actionGeneric or internalActionGeneric and exporting it.
Type parameters
PublicHttpAction
Ƭ PublicHttpAction:Object
An HTTP action that is part of this app’s public API.
You can create public HTTP actions by wrapping your function in
httpActionGeneric and exporting it.
Type declaration
UnvalidatedFunction
Ƭ UnvalidatedFunction<Ctx, Args, Returns>: (ctx: Ctx, …args: Args) => Returns | { handler: (ctx: Ctx, …args: Args) => Returns }
Deprecated
— See the type definition for MutationBuilder or similar for
the types used for defining Bijection functions.
The definition of a Bijection query, mutation, or action function without
argument validation.
Bijection functions always take a context object as their first argument
and an (optional) args object as their second argument.
This can be written as a function like:
Type parameters
ReturnValueForOptionalValidator
Ƭ ReturnValueForOptionalValidator<ReturnsValidator>: [ReturnsValidator] extends [Validator<any, any, any>] ? ValidatorTypeToReturnType<Infer<ReturnsValidator>> : [ReturnsValidator] extends [PropertyValidators] ? ValidatorTypeToReturnType<ObjectType<ReturnsValidator>> : any
There are multiple syntaxes for defining a Bijection function:
- We use Validator | void instead of Validator | undefined because the latter does
not work with
strictNullCheckssince it’s equivalent to justValidator. - We use a tuple type of length 1 to avoid distribution over the union https://github.com/microsoft/TypeScript/issues/29368#issuecomment-453529532
Type parameters
ArgsArrayForOptionalValidator
Ƭ ArgsArrayForOptionalValidator<ArgsValidator>: [ArgsValidator] extends [Validator<any, any, any>] ? OneArgArray<Infer<ArgsValidator>> : [ArgsValidator] extends [PropertyValidators] ? OneArgArray<ObjectType<ArgsValidator>> : ArgsArray
Type parameters
DefaultArgsForOptionalValidator
Ƭ DefaultArgsForOptionalValidator<ArgsValidator>: [ArgsValidator] extends [Validator<any, any, any>] ? [Infer<ArgsValidator>] : [ArgsValidator] extends [PropertyValidators] ? [ObjectType<ArgsValidator>] : OneArgArray
Type parameters
MutationBuilder
Ƭ MutationBuilder<DataModel, Visibility>: <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(mutation: { args?: ArgsValidator ; returns?: ReturnsValidator ; handler: (ctx: GenericMutationCtx<DataModel>, …args: OneOrZeroArgs) => ReturnValue } | (ctx: GenericMutationCtx<DataModel>, …args: OneOrZeroArgs) => ReturnValue) => RegisteredMutation<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Type declaration
▸ <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(mutation): RegisteredMutation<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Internal type helper used by Bijection code generation.
Used to give mutationGeneric a type specific to your data model.
Type parameters
Parameters
Returns
RegisteredMutation<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
MutationBuilderWithTable
Ƭ MutationBuilderWithTable<DataModel, Visibility>: <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(mutation: { args?: ArgsValidator ; returns?: ReturnsValidator ; handler: (ctx: GenericMutationCtxWithTable<DataModel>, …args: OneOrZeroArgs) => ReturnValue } | (ctx: GenericMutationCtxWithTable<DataModel>, …args: OneOrZeroArgs) => ReturnValue) => RegisteredMutation<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Type declaration
▸ <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(mutation): RegisteredMutation<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Internal type helper used by Bijection code generation.
Used to give mutationGeneric a type specific to your data model.
Type parameters
Parameters
Returns
RegisteredMutation<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
QueryBuilder
Ƭ QueryBuilder<DataModel, Visibility>: <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(query: { args?: ArgsValidator ; returns?: ReturnsValidator ; handler: (ctx: GenericQueryCtx<DataModel>, …args: OneOrZeroArgs) => ReturnValue } | (ctx: GenericQueryCtx<DataModel>, …args: OneOrZeroArgs) => ReturnValue) => RegisteredQuery<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Type declaration
▸ <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(query): RegisteredQuery<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Internal type helper used by Bijection code generation.
Used to give queryGeneric a type specific to your data model.
Type parameters
Parameters
Returns
RegisteredQuery<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
QueryBuilderWithTable
Ƭ QueryBuilderWithTable<DataModel, Visibility>: <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(query: { args?: ArgsValidator ; returns?: ReturnsValidator ; handler: (ctx: GenericQueryCtxWithTable<DataModel>, …args: OneOrZeroArgs) => ReturnValue } | (ctx: GenericQueryCtxWithTable<DataModel>, …args: OneOrZeroArgs) => ReturnValue) => RegisteredQuery<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Type declaration
▸ <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(query): RegisteredQuery<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Internal type helper used by Bijection code generation.
Used to give queryGeneric a type specific to your data model.
Type parameters
Parameters
Returns
RegisteredQuery<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
ActionBuilder
Ƭ ActionBuilder<DataModel, Visibility>: <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(func: { args?: ArgsValidator ; capabilities?: { functions: readonly FunctionReference<"query" | "mutation" | "action", "public" | "internal">[] } ; returns?: ReturnsValidator ; handler: (ctx: GenericActionCtx<DataModel>, …args: OneOrZeroArgs) => ReturnValue } | (ctx: GenericActionCtx<DataModel>, …args: OneOrZeroArgs) => ReturnValue) => RegisteredAction<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Type declaration
▸ <ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(func): RegisteredAction<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Internal type helper used by Bijection code generation.
Used to give actionGeneric a type specific to your data model.
Type parameters
Parameters
Returns
RegisteredAction<Visibility, ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
HttpActionBuilder
Ƭ HttpActionBuilder: (func: (ctx: GenericActionCtx<any>, request: Request) => Promise<Response>) => PublicHttpAction
Type declaration
▸ (func): PublicHttpAction
Internal type helper used by Bijection code generation.
Used to give httpActionGeneric a type specific to your data model
and functions.
Parameters
Returns
PublicHttpAction
RoutableMethod
Ƭ RoutableMethod: typeofROUTABLE_HTTP_METHODS[number]
A type representing the methods supported by Bijection HTTP actions.
HEAD is handled by Bijection by running GET and stripping the body.
CONNECT is not supported and will not be supported.
TRACE is not supported and will not be supported.
RouteSpecWithPath
Ƭ RouteSpecWithPath:Object
A type representing a route to an HTTP action using an exact request URL path match.
Used by HttpRouter to route requests to HTTP actions.
Type declaration
RouteSpecWithPathPrefix
Ƭ RouteSpecWithPathPrefix:Object
A type representing a route to an HTTP action using a request URL path prefix match.
Used by HttpRouter to route requests to HTTP actions.
Type declaration
RouteSpec
Ƭ RouteSpec:RouteSpecWithPath | RouteSpecWithPathPrefix
A type representing a route to an HTTP action.
Used by HttpRouter to route requests to HTTP actions.
SchedulableFunctionReference
Ƭ SchedulableFunctionReference:FunctionReference<"mutation" | "action", "public" | "internal">
A FunctionReference that can be scheduled to run in the future.
Schedulable functions are mutations and actions that are public or internal.
SystemFieldValidators
Ƭ SystemFieldValidators<TableName>: Object
The validators for the system fields Bijection adds to every document.
Type parameters
Type declaration
DocValidator
Ƭ DocValidator<TableName, DocumentType>: DocumentType extends VUnion<any, infer Members, any, any> ? { [Index in keyof Members]: WithSystemFieldValidators<TableName, Members[Index]> } extends infer NewMembers ? VUnion<WithSystemFieldValidators<TableName, Members[number]>["type"], NewMembers> : never : WithSystemFieldValidators<TableName, DocumentType>
The validator for whole documents of a table: the table’s own validator with
the _id and _creationTime system fields added.
For a table defined with a union, the system fields are added to each member
of the union.
Type parameters
GenericSchema
Ƭ GenericSchema:Record<string, TableDefinition<any, any, any, any, boolean>>
A type describing the schema of a Bijection project.
This should be constructed using defineSchema, defineTable,
and v.
DataModelFromSchemaDefinition
Ƭ DataModelFromSchemaDefinition<SchemaDef>: MaybeMakeLooseDataModel<{ [TableName in keyof SchemaDef[“tables”] & string]: SchemaDef[“tables”][TableName] extends ViewDefinition<infer From, infer Plan, infer ViewIndexes> ? ViewDataModelEntry<SchemaDef[“tables”], From, Plan, ViewIndexes> : SchemaDef[“tables”][TableName] extends PublishedDefinition<infer Row, infer PublishedIndexes> ? PublishedDataModelEntry<Expand<IdField<TableName> & ExtractDocument<Row>>, keyof IdField<TableName> | ExtractFieldPaths<Row>, PublishedIndexes> : SchemaDef[“tables”][TableName] extends TableDefinition<infer DocumentType, infer Indexes, infer SearchIndexes, infer VectorIndexes, infer IsSource> ? Object & SourceWritability<IsSource> : never }, SchemaDef["strictTableNameTypes"]>
Internal type used in Bijection code generation!
Convert a SchemaDefinition into a GenericDataModel.
Type parameters
SystemTableNames
Ƭ SystemTableNames:TableNamesInDataModel<SystemDataModel>
GoverningResult
Ƭ GoverningResult:null | { validUntil: number }
The result a rule gives ONE item it decides: a read or disclosure request,
a table change or a command. A rule never returns it bare: it returns one
per item, in order (ReadAccessResults), so a rule that falls off its
end (return;, which reaches the engine as null) or returns early refuses
instead of permitting what it never decided. Null permits the item with no
clock-dependent expiry. A rule observing time must return its complete
validity bound unless native enforcement independently establishes that
bound. validUntil is finite safe-integer epoch milliseconds, strictly after
the evaluation clock and at most 366 days ahead. The native committer must
commit strictly before it. Throw to deny.
ReadAccess
Ƭ ReadAccess:Object
Read authorization using an ordinary same-component query.
The query receives the native batch described by readAccessArgs
and returns one result per request (ReadAccessResults); a decision
about the whole relation is written requests.map(() => decision). It runs
as the original caller. Declared policy inputs are private to native policy
execution, not disclosure grants. In a query, an index range withholds the
rows the rule refuses and answers as if they did not exist; every other
refused read, and every refused read in a mutation, refuses the whole
answer. Refusal never redacts properties.
Type declaration
TableChange
Ƭ TableChange<Document>: Object
One net local document change passed to a table’s final governing query.
Documents include their ordinary system fields. Null denotes absence.
Type parameters
Type declaration
LinkEndpointFields
Ƭ LinkEndpointFields<DocumentType>: DocumentType extends { fields: infer Fields } ? { [Field in keyof Fields]: Fields[Field] extends Object ? Field : never }[keyof Fields] & string : never
Required ID fields in a table validator eligible as relationship endpoints.
Type parameters
DocumentFields
Ƭ DocumentFields<Document>: Document extends unknown ? keyof Document & string : never
Top-level properties available in any variant of a document.
Type parameters
SelectedDocument
Ƭ SelectedDocument<Document, Fields>: Document extends unknown ? Pick<Document, Extract<Fields | "_id" | "_creationTime", keyof Document>> : never
Selected document properties, retaining identity and creation time.
Type parameters
StorageId
Ƭ StorageId:string
Deprecated
This ID format is no longer returned by stable file storage APIs. Use Id<"_storage"> instead.
The old ID format used by Bijection file storage.
⚠️ Security warning: Anyone that has knows to this ID can download the underlying file
from https://<deployment>.bijection.cloud/api/storage/<storageId>.
(Note that it’s safe to share the new ID format, Id<"_storage">, to anyone).
FileStorageId
Ƭ FileStorageId:GenericId<"_storage"> | StorageId
Deprecated
This type is only necessary for backwards compatibility with Bijection versions that
pre-date bijection@1.6.0. Use Id<"_storage"> instead.
FileMetadata
Ƭ FileMetadata:Object
Deprecated
This type is only returned by storage.getUrl.
To get the details of a document, use ctx.db.system.get("_storage", storageId) instead.
Metadata for a single file as returned by storage.getMetadata.
Type declaration
SystemFields
Ƭ SystemFields:Object
The fields that Bijection automatically adds to documents, not including _id.
This is an object type mapping field name to field type.
Type declaration
IdField
Ƭ IdField<TableName>: Object
The _id field that Bijection automatically adds to documents.
Type parameters
Type declaration
WithoutSystemFields
Ƭ WithoutSystemFields<Document>: Expand<BetterOmit<Document, keyof SystemFields | "_id">>
A Bijection document with the system fields like _id and _creationTime omitted.
Type parameters
WithOptionalSystemFields
Ƭ WithOptionalSystemFields<Document>: Expand<WithoutSystemFields<Document> & Partial<Pick<Document, keyof SystemFields | "_id">>>
A Bijection document with the system fields like _id and _creationTime optional.
Type parameters
SystemIndexes
Ƭ SystemIndexes:Object
The indexes that Bijection automatically adds to every table.
This is an object mapping index names to index field paths.
Type declaration
IndexTiebreakerField
Ƭ IndexTiebreakerField:"_creationTime"
Bijection automatically appends “_creationTime” to the end of every index to
break ties if all of the other fields are identical.
VectorSearch
Ƭ VectorSearch<DataModel, TableName, IndexName>: (tableName: TableName, indexName: IndexName, query: VectorSearchQuery<NamedTableInfo<DataModel, TableName>, IndexName>) => Promise<{ _id: GenericId<TableName> ; _score: number }[]>
Type parameters
Type declaration
▸ (tableName, indexName, query): Promise<{ _id: GenericId<TableName> ; _score: number }[]>
Parameters
Returns
Promise<{ _id: GenericId<TableName> ; _score: number }[]>
ViewLimits
Ƭ ViewLimits:Object
The bounded work requested by a view. Deployment also enforces server caps.
Type declaration
ViewKey
Ƭ ViewKey<From>: Object
Type parameters
Type declaration
ViewWindow
Ƭ ViewWindow:Object
Rolling latest-N rows within each group at the pinned read basis. Values
sort ascending by these fields, then the complete row; the greatest rows
enter the frame. Strings sort lexically. This does not expire by wall time.
Type declaration
ViewPlan
Ƭ ViewPlan: {kind: "scan" ; table: string } | { kind: "alias" ; input: ViewPlan ; alias: string } | { kind: "filter" ; input: ViewPlan ; predicate: JSONValue } | { kind: "select" ; input: ViewPlan ; fields: Record<string, JSONValue> } | { kind: "join" ; input: ViewPlan ; right: ViewPlan ; join: "left" | "inner" ; left: string[] ; right_field: string[] ; index?: string ; cardinality: "one" | "many" } | { kind: "group" ; input: ViewPlan ; fields: string[] ; aggregates: Record<string, ViewAggregate> ; window?: ViewWindow }
Canonical relational declaration; scalar expressions use the ordinary query wire format.
SerializedView
Ƭ SerializedView:Object
Type declaration
ViewJoinOptions
Ƭ ViewJoinOptions:Object
Type declaration
BarrierInstant
Ƭ BarrierInstant:Object
The instant a common barrier requires every named source to have reached.
There is deliberately no literal-revision form here. An engine revision does
not fit a JavaScript number exactly, and a barrier written against a
rounded revision would compare against an instant nobody chose. A decision
that needs a literal revision states it where revisions are exact; from
TypeScript, a barrier is anchored on a source’s own publication.
Type declaration
SourceScope
Ƭ SourceScope:Object
One installed source and the scope of it a decision reads. A barrier names a
source the way the rest of the engine does; it introduces no new identity.
Type declaration
SourceBarrier
Ƭ SourceBarrier: {kind: "none" } | { kind: "each_latest" } | { kind: "complete_versions" } | { kind: "common" ; at: BarrierInstant }
The barrier a decision declares over the source-bound relations it reads.
WaitDefinition
Ƭ WaitDefinition:Object
A durable wait a business program declares.
A business-time boundary — a price validity lapsing, a supplier’s ship-by
promise falling due, a temporary override ending — changes nothing about
the rows it is about when it passes. Something has to commit. Until now the
only way a program could say so was a cron sweeping on an interval, which
makes the interval the deadline’s precision and runs whether or not anything
is due.
A declaration names two of the deployment’s own internal functions and
nothing else:
due, a query answering when this concern’s next boundary is, as epoch milliseconds, ornullwhen there is none. It is read through the ordinary reader, so the rows it reads become the wait’s region set: a committed write that moves the answer is what re-arms the wait, and between boundaries nothing runs.then, a mutation the engine schedules through the ordinary scheduler in the transaction that settles the wait.
then is resolved AGAIN in the transaction that releases the work, because
a wait row outlives the push that created it and the deployment current when
the boundary arrives is the one whose authority the release runs under.
Both are internal, which is the program saying these entry points belong to
the engine rather than to any client that can reach the deployment.
A declaration may also name keys, an internal query returning at most 32
stable instance keys (strings of 1 to 128 bytes). Each key is then its own
standing wait: its due runs in its own transaction, so one instance’s
reads never become another’s, and due and then receive { key }. A key
the query stops listing is retired. keys should read only routing that
grants nothing by itself; then still rechecks the instance’s own state,
because a key can be removed between the boundary and the continuation.
Type declaration
Expand
Ƭ Expand<ObjectType>: ObjectType extends Record<any, any> ? { [Key in keyof ObjectType]: ObjectType[Key] } : never
Hack! This type causes TypeScript to simplify how it renders object types.
It is functionally the identity for object types, but in practice it can
simplify expressions like A & B.
Type parameters
BetterOmit
Ƭ BetterOmit<T, K>: { [Property in keyof T as Property extends K ? never : Property]: T[Property] }
An Omit<> type that:
- Applies to each element of a union.
- Preserves the index signature of the underlying type.
Type parameters
Variables
anyApi
•Const anyApi: AnyApi
A utility for constructing FunctionReferences in projects that
are not using code generation.
You can create a reference to a function like:
api from bijection/_generated/api
instead. It will be more type-safe and produce better auto-complete
in your editor.
execution
•Const execution: Object
Type declaration
ROOT_TYPE
•Const ROOT_TYPE: "root"
The one object every tree hangs from. A type without a parent is a child
of the root, so an administrator of everything is an ordinary role on an
ordinary object, and a whole-table read is a scope pinned at the root.
ROOT_KEY
•Const ROOT_KEY: "*"
The key of the single root object.
log
•Const log: Log
paginationOptsValidator
•Const paginationOptsValidator: VObject<{ id: undefined | number ; endCursor: undefined | null | string ; maximumRowsRead: undefined | number ; maximumBytesRead: undefined | number ; numItems: number ; cursor: null | string }, { numItems: VFloat64<number, "required"> ; cursor: VUnion<null | string, [VString<string, "required">, VNull<null, "required">], "required", never> ; endCursor: VUnion<undefined | null | string, [VString<string, "required">, VNull<null, "required">], "optional", never> ; id: VFloat64<undefined | number, "optional"> ; maximumRowsRead: VFloat64<undefined | number, "optional"> ; maximumBytesRead: VFloat64<undefined | number, "optional"> }, "required", "id" | "numItems" | "cursor" | "endCursor" | "maximumRowsRead" | "maximumBytesRead">
A Validator for PaginationOptions.
Use this as the args validator in paginated query functions so that clients
can pass pagination options.
Example
usePaginatedQuery from "bijection/react":
See
https://docs.bijection.com/database/pagination
publications
•Const publications: Object
Type declaration
readAccessArgs
•Const readAccessArgs: Object
Arguments for an ordinary query used by .access({ read, reads }).
The native reader constructs the complete batch. Calling the query directly
does not grant private policy-input access or authorize another database read.
properties: null requires the whole document. Otherwise properties include
selected fields and fields contributing to membership, filtering and order,
including _id and _creationTime. Nested paths require their whole top-level
property. Query equalities are guaranteed index bounds, not guessed filters.
An omitted equality value denotes absence; null remains an explicit value.
A query target with covers: true stands for rows the engine does not
present as requests of their own: a maintained total, a count, a table
change token, a whole relation’s status, a range folded past the read
evidence bound (rowsFollowRange) or a retained obligation kept in place of
per-row requests. Its result decides every row it covers. Without the key,
any row the read returned arrives as a request of its own.
Type declaration
readAccessResults
•Const readAccessResults: VArray<(null | { reason: undefined | string ; validUntil: number } | { reason: string })[], VUnion<null | { reason: undefined | string ; validUntil: number } | { reason: string }, [VNull<null, "required">, VObject<{ reason: undefined | string ; validUntil: number }, { validUntil: VFloat64<number, "required"> ; reason: VString<undefined | string, "optional"> }, "required", "validUntil" | "reason">, VObject<{ reason: string }, { reason: VString<string, "required"> }, "required", "reason">], "required", "validUntil" | "reason">, "required">
The return validator of every rule: read, disclose, a table’s write rule
(.govern) and an integration command’s rule. A command rule gives no
reason; one that defers with recheckAt declares that member beside
null and { validUntil }.
disclosureArgs
•Const disclosureArgs: Object
Arguments for the source’s optional .access({ disclose }) query. The host
supplies actual information dependencies and the exact fixed destination.
A table release gives the resulting record its destination table’s policy;
it does not grant future reads of the source or retract previously released
bytes when a source grant is later revoked.
Type declaration
ROUTABLE_HTTP_METHODS
•Const ROUTABLE_HTTP_METHODS: readonly ["GET", "POST", "PUT", "DELETE", "OPTIONS", "PATCH"]
A list of the methods supported by Bijection HTTP actions.
HEAD is handled by Bijection by running GET and stripping the body.
CONNECT is not supported and will not be supported.
TRACE is not supported and will not be supported.
q
•Const q: Object
Declarative relational and scalar operators, evaluated by the engine.
Type declaration
sourceBarrier
•Const sourceBarrier: Object
The barriers, as declared data. The wire shape is exactly what the
engine decodes; views.barrier.test.ts and the Rust decoder each pin it
against independent literals.
Type declaration
Functions
getFunctionName
▸ getFunctionName(functionReference): string
Get the name of a function from a FunctionReference.
The name is a string like “myDir/myModule:myFunction”. If the exported name
of the function is "default", the function name is omitted
(e.g. “myDir/myModule”).
Parameters
Returns
string
A string of the function’s name.
makeFunctionReference
▸ makeFunctionReference<type, args, ret>(name): FunctionReference<type, "public", args, ret>
FunctionReferences generally come from generated code, but in custom clients
it may be useful to be able to build one manually.
Real function references are empty objects at runtime, but the same interface
can be implemented with an object for tests and clients which don’t use
code generation.
Type parameters
Parameters
Returns
FunctionReference<type, "public", args, ret>
filterApi
▸ filterApi<API, Predicate>(api): FilterApi<API, Predicate>
Given an api of type API and a FunctionReference subtype, return an api object
containing only the function references that match.
Type parameters
Parameters
Returns
FilterApi<API, Predicate>
getMany
▸ getMany(_ctx, table, ids): Promise<AppPointRead[]>
Read several objects of one table or view by identifier, each answered on
its own: object, absent, or restricted when the engine refused that
object’s read for the caller. At most 100 distinct identifiers, answered in
order; an identifier that is not one of this table’s is refused as
db.get refuses it.
In a query, one refused object answers restricted and the rest of the
answer stands. Everywhere else (a mutation, a policy) these are ordinary
point reads, and a refused one refuses the whole call as db.get does.
Every other read of the query is still decided with the whole answer,
except that a query’s index range withholds the rows the caller may not
read, as if they did not exist.
Parameters
Returns
Promise<AppPointRead[]>
applicationQueries
▸ applicationQueries(definition): Object
Parameters
Returns
Object
applicationNotificationRow
▸ applicationNotificationRow(args): Object
One delivery row, as the notification table stores it: recipient a person
id and event the occurrence reference kind resolves, each at most
APP_NOTICE_REFERENCE_MAX characters. The row holds references only,
never content.
Parameters
Returns
Object
applicationPerson
▸ applicationPerson(people, ctx): Promise<string | null>
The caller’s own person, as people.self answers it, normalized to an id
of the people collection; null without people or when the caller is not
one of them. An answer that is not such an id (at most
APP_NOTICE_REFERENCE_MAX characters) is refused. Call it after
authorize: it is the one resolution of “who is the caller” that the
application’s own queries and a capability’s exposure helpers share.
Parameters
Returns
Promise<string | null>
createFunctionHandle
▸ createFunctionHandle<Type, Args, ReturnType>(functionReference): Promise<FunctionHandle<Type, Args, ReturnType>>
Create a serializable reference to a Bijection function.
Passing a this reference to another component allows that component to call this
function during the current function execution or at any later time.
Function handles are used like api.folder.function FunctionReferences,
e.g. ctx.scheduler.runAfter(0, functionReference, args).
A function reference is stable across code pushes but it’s possible
the Bijection function it refers to might no longer exist.
This is a feature of components, which are in beta.
This API is unstable and may change in subsequent releases.
Type parameters
Parameters
Returns
Promise<FunctionHandle<Type, Args, ReturnType>>
defineComponent
▸ defineComponent<Exports, Env>(name, options?): ComponentDefinition<Exports, Env>
Define a component, a piece of a Bijection deployment with namespaced resources.
Optionally define typed environment variables that will be available via
the env export from _generated/server in all Bijection functions within
this component. Values are passed by the parent via
app.use(component, { env: { ... } }).
Type parameters
Parameters
Returns
ComponentDefinition<Exports, Env>
defineApp
▸ defineApp<Env>(options?): AppDefinition<Env>
Attach components, reuseable pieces of a Bijection deployment, to this Bijection app.
Optionally define typed environment variables that will be available via
the env export from _generated/server in all Bijection functions.
Example
Type parameters
Parameters
Returns
AppDefinition<Env>
componentsGeneric
▸ componentsGeneric():AnyChildComponents
Returns
AnyChildComponents
getFunctionAddress
▸ getFunctionAddress(functionReference): { functionHandle: string = functionReference; reference?: undefined = referencePath; name?: undefined = body.name } | { functionHandle?: undefined = functionReference; name: any ; reference?: undefined = referencePath } | { functionHandle?: undefined = functionReference; reference: string = referencePath; name?: undefined = body.name }
Parameters
Returns
{functionHandle: string = functionReference; reference?: undefined = referencePath; name?: undefined = body.name } | { functionHandle?: undefined = functionReference; name: any ; reference?: undefined = referencePath } | { functionHandle?: undefined = functionReference; reference: string = referencePath; name?: undefined = body.name }
bijectionQueryGeneric
▸ bijectionQueryGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(definition): RegisteredQuery<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Parameters
Returns
RegisteredQuery<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
bijectionInternalQueryGeneric
▸ bijectionInternalQueryGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(definition): RegisteredQuery<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Parameters
Returns
RegisteredQuery<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
bijectionMutationGeneric
▸ bijectionMutationGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(definition): RegisteredMutation<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Parameters
Returns
RegisteredMutation<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
bijectionInternalMutationGeneric
▸ bijectionInternalMutationGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(definition): RegisteredMutation<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Parameters
Returns
RegisteredMutation<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
bijectionActionGeneric
▸ bijectionActionGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(definition): RegisteredAction<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Parameters
Returns
RegisteredAction<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
bijectionInternalActionGeneric
▸ bijectionInternalActionGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(definition): RegisteredAction<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Type parameters
Parameters
Returns
RegisteredAction<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
cronJobs
▸ cronJobs():Crons
Create a CronJobs object to schedule recurring tasks.
Returns
Crons
externalCallStatus
▸ externalCallStatus(_ctx, id): Promise<ExternalCallStatus>
The status of a governed call this component submitted with
ctx.externalCalls.submit. A tracked read: a query that asks is re-run when
the call settles. A call another component submitted, or an id that names
nothing, is refused as not found.
Parameters
Returns
Promise<ExternalCallStatus>
bothAccessResults
▸ bothAccessResults(...results): GoverningResult
Combine rule results: null only when none carries a bound, otherwise
the earliest validUntil. A result’s reason says why it permitted and
bounds nothing.
Parameters
Returns
GoverningResult
defineAccessModel
▸ defineAccessModel(definition): Object
Declare the access model. Throws on an inconsistent declaration.
Parameters
Returns
Object
getServiceToken
▸ getServiceToken(service): Promise<string>
Get a short-lived credential for calling a Bijection-managed service.
This function can only be called while an action is running. The credential
is scoped to the current deployment and should be sent as a bearer token.
The action runtime caches and refreshes credentials as needed, so call
this function whenever making a service request.
Parameters
Returns
Promise<string>
A JWT to send as Authorization: Bearer <token>. Keep it inside
the action: don’t return it to clients or store it in environment
variables.
getServiceUrl
▸ getServiceUrl(service): Promise<string>
Get the base URL of a Bijection-managed service.
This function can only be called while an action is running. Pair it with
getServiceToken to reach the service.
Parameters
Returns
Promise<string>
The service’s origin, without a trailing slash.
mutationGeneric
▸ mutationGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(mutation): RegisteredMutation<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Define a mutation in this Bijection app’s public API.
You should generally use the mutation function from
"./_generated/server".
Mutations can read from and write to the database, and are accessible from
the client. They run transactionally, all database reads and writes
within a single mutation are atomic and isolated from other mutations.
Example
args and returns validators on all
mutations. If the function doesn’t return a value, use returns: v.null().
Argument validation is critical for security since public mutations are
exposed to the internet.
Common mistake: Mutations cannot call third-party APIs or use fetch.
They must be deterministic. Use actions for external API calls.
Common mistake: Do not use mutation for sensitive internal functions
that should not be called by clients. Use internalMutation instead.
See
https://docs.bijection.com/functions/mutation-functions
Type parameters
Parameters
Returns
RegisteredMutation<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
The wrapped mutation. Include this as an export to name it and make it accessible.
internalMutationGeneric
▸ internalMutationGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(mutation): RegisteredMutation<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Define a mutation that is only accessible from other Bijection functions (but not from the client).
You should generally use the internalMutation function from
"./_generated/server".
Internal mutations can read from and write to the database but are not
exposed as part of your app’s public API. They can only be called by other
Bijection functions using ctx.runMutation or by the scheduler. Like public
mutations, they run transactionally.
Example
internalMutation for any mutation that should not
be directly callable by clients, such as write-back functions from actions
or scheduled background work. Reference it via the internal object:
await ctx.runMutation(internal.myModule.markTaskCompleted, { taskId }).
See
https://docs.bijection.com/functions/internal-functions
Type parameters
Parameters
Returns
RegisteredMutation<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
The wrapped mutation. Include this as an export to name it and make it accessible.
queryGeneric
▸ queryGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(query): RegisteredQuery<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Define a query in this Bijection app’s public API.
You should generally use the query function from
"./_generated/server".
Queries can read from the database and are accessible from the client. They
are reactive, when used with useQuery in React, the component
automatically re-renders whenever the underlying data changes. Queries
cannot modify the database.
Query results are automatically cached by the Bijection client and kept
consistent via WebSocket subscriptions.
Example
args and returns validators. Use
.withIndex() instead of .filter() for efficient database queries.
Queries should be fast since they run on every relevant data change.
Common mistake: Queries are pure reads, they cannot write to the
database, call external APIs, or schedule functions. Use actions for HTTP
calls and mutations for database writes and scheduling.
See
https://docs.bijection.com/functions/query-functions
Type parameters
Parameters
Returns
RegisteredQuery<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
The wrapped query. Include this as an export to name it and make it accessible.
internalQueryGeneric
▸ internalQueryGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(query): RegisteredQuery<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Define a query that is only accessible from other Bijection functions (but not from the client).
You should generally use the internalQuery function from
"./_generated/server".
Internal queries can read from the database but are not exposed as part
of your app’s public API. They can only be called by other Bijection functions
using ctx.runQuery. This is useful for loading data in actions or for
helper queries that shouldn’t be client-facing.
Example
internalQuery for data-loading in actions via
ctx.runQuery(internal.myModule.getUser, { userId }).
See
https://docs.bijection.com/functions/internal-functions
Type parameters
Parameters
Returns
RegisteredQuery<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
The wrapped query. Include this as an export to name it and make it accessible.
actionGeneric
▸ actionGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(func): RegisteredAction<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Define an action in this Bijection app’s public API.
Actions can call third-party APIs, use Node.js libraries, and perform other
side effects. Unlike queries and mutations, actions do not have direct
database access (ctx.db is not available). Instead, use ctx.runQuery
and ctx.runMutation to read and write data.
You should generally use the action function from
"./_generated/server".
Actions are accessible from the client and run outside of the database
transaction, so they are not atomic. They are best for integrating with
external services.
Example
ctx.runQuery and
ctx.runMutation calls from actions. Each call is a separate transaction,
so splitting logic across multiple calls introduces the risk of race
conditions. Try to batch reads/writes into single query/mutation calls.
"use node" runtime: Actions run in Bijection’s default JavaScript
runtime, which supports fetch and most NPM packages. Only add
"use node"; at the top of the file if a third-party library specifically
requires Node.js built-in APIs, it is a last resort, not the default.
Node.js actions have slower cold starts, and only actions can be defined
in "use node" files (no queries or mutations), so prefer the default
runtime whenever possible.
Common mistake: Do not try to access ctx.db in an action, it is
not available. Use ctx.runQuery and ctx.runMutation instead.
See
https://docs.bijection.com/functions/actions
Type parameters
Parameters
Returns
RegisteredAction<"public", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
The wrapped function. Include this as an export to name it and make it accessible.
internalActionGeneric
▸ internalActionGeneric<ArgsValidator, ReturnsValidator, ReturnValue, OneOrZeroArgs>(func): RegisteredAction<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
Define an action that is only accessible from other Bijection functions (but not from the client).
You should generally use the internalAction function from
"./_generated/server".
Internal actions behave like public actions (they can call external APIs and
use Node.js libraries) but are not exposed in your app’s public API. They
can only be called by other Bijection functions using ctx.runAction or via the
scheduler.
Example
internalAction for background work scheduled from
mutations: await ctx.scheduler.runAfter(0, internal.myModule.sendEmail, { ... }).
Only use ctx.runAction from another action if you need to cross runtimes
(e.g., default Bijection runtime to Node.js). Otherwise, extract shared code
into a helper function.
"use node" runtime: Only add "use node"; at the top of the file
as a last resort when a third-party library requires Node.js APIs. Node.js
actions have slower cold starts, and only actions can be defined in
"use node" files (no queries or mutations).
See
https://docs.bijection.com/functions/internal-functions
Type parameters
Parameters
Returns
RegisteredAction<"internal", ArgsArrayToObject<OneOrZeroArgs>, ReturnValue>
The wrapped function. Include this as an export to name it and make it accessible.
httpActionGeneric
▸ httpActionGeneric(func): PublicHttpAction
Define a Bijection HTTP action.
HTTP actions handle raw HTTP requests and return HTTP responses. They are
registered by routing URL paths to them in bijection/http.ts using
HttpRouter. Like regular actions, they can call external APIs and
use ctx.runQuery / ctx.runMutation but do not have direct ctx.db access.
Example
path: "/api/webhook" registers at /api/webhook.
See
https://docs.bijection.com/functions/http-actions
Parameters
Returns
PublicHttpAction
The wrapped function. Route a URL path to this function in bijection/http.ts.
setupPattern
▸ setupPattern(pattern): RegExp
Compile a declared pattern the one way both sides compile it: anchored
whole, never partially matched.
Parameters
Returns
RegExp
validateSetupDeclaration
▸ validateSetupDeclaration(setup): SetupDeclaration
Check the declaration itself, at definition time.
Everything here is a defect in the definition rather than in a supplied
value, so it throws: the module never loads with a declaration the backend
would refuse, and an author sees it at bijection dev rather than at the
first connection.
Parameters
Returns
SetupDeclaration
checkSetupValue
▸ checkSetupValue(field, value): SetupRefusal | undefined
Check one supplied value against one field. undefined is admitted.
The same rules the backend applies, in the same order, so a form that says
“that is not a subdomain” and a server that refuses the request are saying
the same thing. It never decides anything: the backend re-checks every value
it is given.
Parameters
Returns
SetupRefusal | undefined
renderSetupBaseUrl
▸ renderSetupBaseUrl(field, value): string
The address a base_url field renders.
Parameters
Returns
string
describeSetupRefusal
▸ describeSetupRefusal(refusal): string
Say why a value was refused, in one line, for a form or a prompt.
Parameters
Returns
string
setupFieldsToAsk
▸ setupFieldsToAsk(requirements): SetupRequirement[]
The fields a person still has to answer, in declaration order.
Secrets are not among them: they are provisioned through the credential
path, and a form that rendered an input for one would be inviting a secret
into a request that has no business carrying it. An already configured
administrator field is not among them either — that is the whole point of
the configured flag.
Parameters
Returns
SetupRequirement[]
accountSetupFields
▸ accountSetupFields(requirements): SetupRequirement[]
The fields a CONNECTING ACCOUNT answers, in declaration order.
An account connecting its own installation answers what its own installation
decides — its instance, its region, its workspace — and nothing about the
deployment. An administrator field is deployment configuration: the person
consenting has no way to know it, the deployment already states it, and the
backend refuses it from this direction by name. Filtering it out here is what
keeps a consent screen from asking a customer to configure somebody else’s
deployment; the backend still decides.
Parameters
Returns
SetupRequirement[]
admitIntegration
▸ admitIntegration<T>(definition): T
Admit an integration definition authored outside this deployment component.
A definition’s module/export address is assigned by the compiler and names a
module of the deployment being installed. A definition imported from a
package or a sibling directory is not such a module, so it has no address of
its own and cannot be bound by .source(...). Re-exporting it through this
function from a module of the component gives it that module’s address:
Type parameters
Parameters
Returns
T
defineIntegration
▸ defineIntegration<S, A, H>(definition): Object
Define source collections, sync routines and external command contracts.
Compiler addresses are references, never capabilities or trusted evidence.
Type parameters
Parameters
Returns
Object
defineNativeIntegration
▸ defineNativeIntegration<S, H, A>(definition): { commands: { readonly [K in string | number | symbol]: CommandHandle<ObjectType<A[K]>> } ; isIntegration: true ; discover?: (ctx: IntegrationContext<H>, input: { resume: null | string ; next_page_reference: null | string }) => Promise<{ resources: { id: string ; label: null | string }[] ; next_page: null | string ; evidence: string }> = definition.discover; invokeIntegration: (handler: (ctx: IntegrationContext<H>, …args: any[]) => unknown, argsStr: string) => Promise<string> ; [attachment]: (next: IntegrationAddress) => void ; exportIntegration: () => string } & { readonly [K in string | number | symbol]: SourceHandle<S[K]> }
Native protocols use the same analyzed source handles as HTTP integrations.
Their read entrypoints are implemented by the host; there are no guest
callbacks with hidden network or evidence authority.
Type parameters
Parameters
Returns
{commands: { readonly [K in string | number | symbol]: CommandHandle<ObjectType<A[K]>> } ; isIntegration: true ; discover?: (ctx: IntegrationContext<H>, input: { resume: null | string ; next_page_reference: null | string }) => Promise<{ resources: { id: string ; label: null | string }[] ; next_page: null | string ; evidence: string }> = definition.discover; invokeIntegration: (handler: (ctx: IntegrationContext<H>, …args: any[]) => unknown, argsStr: string) => Promise<string> ; [attachment]: (next: IntegrationAddress) => void ; exportIntegration: () => string } & { readonly [K in string | number | symbol]: SourceHandle<S[K]> }
definePostgresIntegration
▸ definePostgresIntegration<S>(definition): { commands: {} ; isIntegration: true ; discover?: (ctx: IntegrationContext<{}>, input: { resume: null | string ; next_page_reference: null | string }) => Promise<{ resources: { id: string ; label: null | string }[] ; next_page: null | string ; evidence: string }> = definition.discover; invokeIntegration: (handler: (ctx: IntegrationContext<{}>, …args: any[]) => unknown, argsStr: string) => Promise<string> ; [attachment]: (next: IntegrationAddress) => void ; exportIntegration: () => string } & { readonly [K in string | number | symbol]: SourceHandle<S[K]> }
Read selected PostgreSQL tables through one consistent initial snapshot and
atomic committed transactions. PostgreSQL installation is private.
Type parameters
Parameters
Returns
{commands: {} ; isIntegration: true ; discover?: (ctx: IntegrationContext<{}>, input: { resume: null | string ; next_page_reference: null | string }) => Promise<{ resources: { id: string ; label: null | string }[] ; next_page: null | string ; evidence: string }> = definition.discover; invokeIntegration: (handler: (ctx: IntegrationContext<{}>, …args: any[]) => unknown, argsStr: string) => Promise<string> ; [attachment]: (next: IntegrationAddress) => void ; exportIntegration: () => string } & { readonly [K in string | number | symbol]: SourceHandle<S[K]> }
defineMailIntegration
▸ defineMailIntegration(definition): ReturnType<typeof defineNativeIntegration>
Read mail through the integration scheduler and retained native evidence.
Account, credentials and selected folders are private installation settings.
Initial capture establishes a baseline; it does not manufacture arrivals.
Message identity is independent of folder/label membership.
Parameters
Returns
ReturnType<typeof defineNativeIntegration>
defineOperationInterface
▸ defineOperationInterface<Args, Returns>(definition): OperationInterfaceDefinition<Infer<AsObjectValidator<Args>>, Infer<AsObjectValidator<Returns>>>
Declare a targeted operation shape. Each concrete operation explicitly
implements it and supplies a required target ID argument. Query this export
to discover currently readable public implementations in its component.
Type parameters
Parameters
Returns
OperationInterfaceDefinition<Infer<AsObjectValidator<Args>>, Infer<AsObjectValidator<Returns>>>
operationImplementationReference
▸ operationImplementationReference<Args, Result>(implementation): OperationReference<"public", Args & { target: GenericId<string> }, Result>
Bind the discovered concrete contract to an ordinary operation reference.
Retain this reference with a request key for recovery; do not resolve the
interface again to retry already accepted work.
Type parameters
Parameters
Returns
OperationReference<"public", Args & { target: GenericId<string> }, Result>
makeOperationReference
▸ makeOperationReference<Visibility, Args, LocalResult>(name, definition, functions?): Promise<OperationReference<Visibility, Args, LocalResult>>
Construct a reference from a checked declaration or validator description.
Types are inferred from the same description used to calculate the runtime
contract. Generated references do not require this asynchronous step.
Type parameters
Parameters
Returns
Promise<OperationReference<Visibility, Args, LocalResult>>
▸ makeOperationReference<ArgsValidator, ReturnsValidator, Visibility>(name, definition, functions?): Promise<OperationReference<Visibility, Infer<AsObjectValidator<ArgsValidator>>, Infer<AsObjectValidator<ReturnsValidator>>>>
Type parameters
Parameters
Returns
Promise<OperationReference<Visibility, Infer<AsObjectValidator<ArgsValidator>>, Infer<AsObjectValidator<ReturnsValidator>>>>
getOperationContract
▸ getOperationContract(operation): OperationContractMetadata
Read the expected contract carried by an operation reference.
Parameters
Returns
OperationContractMetadata
operationInvocationArgs
▸ operationInvocationArgs<Operation>(operation, request_key, args): Object
Build the ordinary request envelope from the reference’s checked contract.
The caller must retain the original key and arguments across uncertain outcomes.
Type parameters
Parameters
Returns
Object
operationStatusArgs
▸ operationStatusArgs(operation, invocation_id): Object
Parameters
Returns
Object
operationPreviewArgs
▸ operationPreviewArgs<Operation>(operation, args): Object
Preview uses the same business arguments and contract as invocation, without
creating or consuming a business acceptance identity.
Type parameters
Parameters
Returns
Object
apiWithOperations
▸ apiWithOperations(manifest, visibility): AnyApi
Overlay analyzed operation references while retaining the inherited runtime
API for every ordinary function. The generator supplies the paired types.
Parameters
Returns
AnyApi
componentsWithOperations
▸ componentsWithOperations(manifest): AnyComponents
Pair installed-component contracts with their explicit native export paths.
Ordinary references retain the inherited component proxy behavior. Generated
components objects call this; the generator supplies the paired types.
Parameters
Returns
AnyComponents
operationFunctionReference
▸ operationFunctionReference<Visibility, Args, LocalResult, Member>(operation, member): OperationFunctionReferences<Visibility, Args, LocalResult>[Member]
Resolve one companion of an operation reference to the ordinary function
reference that serves it: invoke, preview and revise are mutations,
recover and status are queries. Pass the result with the matching
argument helper to a client or ctx.runMutation / ctx.runQuery.
Explicit companion references carried by the reference are used as given;
otherwise the address is derived from the operation’s own path. A component
operation must carry explicit companions, and a function handle cannot name
one. The reference must carry a generated contract. This only names a
function: native analysis owns which companions exist, and calling one still
requires its grants.
Type parameters
Parameters
Returns
OperationFunctionReferences<Visibility, Args, LocalResult>[Member]
defineOperation
▸ defineOperation<ArgsValidator, ReturnsValidator>(definition): OperationDefinition<"public", OperationArgsFromValidator<ArgsValidator>, Infer<AsObjectValidator<ReturnsValidator>>>
Declare a public business operation. Preparation uses an ordinary mutation;
native admission owns request recovery and the committed acceptance receipt.
Type parameters
Parameters
Returns
OperationDefinition<"public", OperationArgsFromValidator<ArgsValidator>, Infer<AsObjectValidator<ReturnsValidator>>>
defineInternalOperation
▸ defineInternalOperation<ArgsValidator, ReturnsValidator>(definition): OperationDefinition<"internal", OperationArgsFromValidator<ArgsValidator>, Infer<AsObjectValidator<ReturnsValidator>>>
Declare an operation callable only from authorized server execution.
Internal visibility does not grant permission to its effects.
Type parameters
Parameters
Returns
OperationDefinition<"internal", OperationArgsFromValidator<ArgsValidator>, Infer<AsObjectValidator<ReturnsValidator>>>
paginationResultValidator
▸ paginationResultValidator<T>(itemValidator): VObject<{ splitCursor: undefined | null | string ; pageStatus: undefined | null | "SplitRecommended" | "SplitRequired" ; page: T["type"][] ; continueCursor: string ; isDone: boolean }, { page: VArray<T["type"][], T, "required"> ; continueCursor: VString<string, "required"> ; isDone: VBoolean<boolean, "required"> ; splitCursor: VUnion<undefined | null | string, [VString<string, "required">, VNull<null, "required">], "optional", never> ; pageStatus: VUnion<undefined | null | "SplitRecommended" | "SplitRequired", [VLiteral<"SplitRecommended", "required">, VLiteral<"SplitRequired", "required">, VNull<null, "required">], "optional", never> }, "required", "page" | "continueCursor" | "isDone" | "splitCursor" | "pageStatus">
A Validator factory for PaginationResult.
Create a validator for the result of calling paginate
with a given item validator.
For example:
Type parameters
Parameters
Returns
VObject<{ splitCursor: undefined | null | string ; pageStatus: undefined | null | "SplitRecommended" | "SplitRequired" ; page: T["type"][] ; continueCursor: string ; isDone: boolean }, { page: VArray<T["type"][], T, "required"> ; continueCursor: VString<string, "required"> ; isDone: VBoolean<boolean, "required"> ; splitCursor: VUnion<undefined | null | string, [VString<string, "required">, VNull<null, "required">], "optional", never> ; pageStatus: VUnion<undefined | null | "SplitRecommended" | "SplitRequired", [VLiteral<"SplitRecommended", "required">, VLiteral<"SplitRequired", "required">, VNull<null, "required">], "optional", never> }, "required", "page" | "continueCursor" | "isDone" | "splitCursor" | "pageStatus">
A validator for the pagination result
definePublished
▸ definePublished<Row>(definition): PublishedDefinition<Row>
Declare a table whose rows one producer publishes.
Type parameters
Parameters
Returns
PublishedDefinition<Row>
▸ definePublished<Row>(definition): PublishedDefinition<VObject<ObjectType<Row>, Row>>
Declare a table whose rows one producer publishes.
Type parameters
Parameters
Returns
PublishedDefinition<VObject<ObjectType<Row>, Row>>
definePublisher
▸ definePublisher(definition): PublisherDefinition
Declare a publisher over this deployment’s own functions.
Parameters
Returns
PublisherDefinition
decideEach
▸ decideEach<R>(requests, decide): Promise<ReadAccessResults>
Decide each request of a batch on its own, in order. A return inside
decide settles only its own request; a throw refuses the batch.
Type parameters
Parameters
Returns
Promise<ReadAccessResults>
httpRouter
▸ httpRouter():HttpRouter
Return a new HttpRouter object.
Returns
HttpRouter
defineTable
▸ defineTable<DocumentSchema>(documentSchema): TableDefinition<DocumentSchema>
Define a table in a schema.
You can either specify the schema of your documents as an object like
Type parameters
Parameters
Returns
TableDefinition<DocumentSchema>
A TableDefinition for the table.
▸ defineTable<DocumentSchema>(documentSchema): TableDefinition<VObject<ObjectType<DocumentSchema>, DocumentSchema>>
Define a table in a schema.
You can either specify the schema of your documents as an object like
Type parameters
Parameters
Returns
TableDefinition<VObject<ObjectType<DocumentSchema>, DocumentSchema>>
A TableDefinition for the table.
docValidator
▸ docValidator<TableName, Table>(tableName, table): DocValidator<TableName, Table["validator"]>
Build the validator for whole documents of a table, by adding the _id and
_creationTime system fields to the table’s own validator.
Prefer doc when you have the schema in hand: it
checks the table name against the schema.
Example
Type parameters
Parameters
Returns
DocValidator<TableName, Table["validator"]>
A validator matching documents of the table.
defineSchema
▸ defineSchema<Schema, StrictTableNameTypes>(schema, options?): SchemaDefinition<Schema, StrictTableNameTypes>
Define the schema of this Bijection project.
This should be exported as the default export from a schema.ts file in
your bijection/ directory. The schema enables runtime validation of documents
and provides end-to-end TypeScript type safety.
Every document in Bijection automatically has two system fields:
_id- a unique document ID with validatorv.id("tableName")_creationTime- a creation timestamp with validatorv.number()
Example
["field1", "field2"] should be named
"by_field1_field2".
See
https://docs.bijection.com/database/schemas
Type parameters
Parameters
Returns
SchemaDefinition<Schema, StrictTableNameTypes>
The schema.
getTableChangeToken
▸ getTableChangeToken(table): Promise<string>
Observe committed changes anywhere in a table, including deletions and
updates outside a sampled page. The opaque token is not source provenance.
Current table access applies, and this read is reactive without scanning rows.
Parameters
Returns
Promise<string>
defineView
▸ defineView<From, Plan>(definition): ViewDefinition<From, Plan>
Type parameters
Parameters
Returns
ViewDefinition<From, Plan>
defineWait
▸ defineWait(definition): WaitDefinition
Declare a durable wait over this deployment’s own functions.
Parameters
Returns
WaitDefinition