PointReadAdmission
Optional admission of state point reads: load by id, version or time, and tracing. They replay events and have no query AST, so the gateway never admits them.
Off (the default), they behave as before. On, each state read is turned into its snapshot-shaped record and admitted by the core (QueryAdmission.admitRecord) under an QueryEntry.HTTP entry and the caller's request scope:
the gateways' entryPolicy accepts the entry and, with
require-authenticated-scopeon, rejects a caller whose authenticated scope does not pin the snapshot model's required scope, as a query route does;the caller's scope, every QueryPolicy restriction and the snapshot model's default scope are evaluated on it in memory; a state outside them reads as absent (404 for a load, no rows for tracing), and a filter node the in-memory evaluation does not support fails closed;
the response is masked by the aggregate's snapshot query schema (snapshotSchema), and a tracing response also by its event-stream query schema (eventStreamSchema);
tracing emits at most tracingMaxVersions versions (
0disables the cap), and only when every traced state is admitted.
Policies see a QueryType.SINGLE query by id; a traced state's query also includes deleted states, since tracing replays history. Policies need the snapshot schema, so a point read with policies fails when snapshotSchema is not given or cannot load.
Constructors
Functions
The admitted, masked record of state (a state aggregate or a traced state event), or empty when the caller may not read it.
Rejects a tracing range of versions versions beyond tracingMaxVersions.
What a load route returns for state: its state, or, when enabled, the admitted and masked state JSON.