basalt / http/src / assertRoutesGuarded
Function: assertRoutesGuarded()
> assertRoutesGuarded(routes, claimed, allow?): void
Defined in: http/src/guarded-meta.ts:89
Fails loud (at boot) when a route declares one of GUARDED_META_KEYS and no registered guard claimed that key via GUARDED_META_BUCKET. allow waives the check: true for everything (edge-auth deployments), or an array of specific keys. A value of false/undefined on the route's meta is an explicit opt-off, not a protection request — never flagged.
Every adapter plugin calls this at boot. Code that drives runRoute() itself — no adapter, e.g. a bespoke listener — gets no such check for free: pass the booted app's container as claimed and the keys its plugins claimed are read from it, the same check the adapters make:
const app = await createApp({ plugins: [authPlugin(…), permissionsPlugin(…)] }).boot()
assertRoutesGuarded(routes, app.container) // throws UnguardedRouteMetaErrorGiven a container, it also runs every route-meta validator plugins registered in META_VALIDATORS_BUCKET (see assertRouteMetaValid) — allow never waives those: a waiver says "an outer edge enforces this key", not "a typo in its value is fine".
Parameters
routes
readonly BasaltRoute[]
claimed
Container | ReadonlySet<string>
allow?
boolean | readonly string[]
Returns
void