basalt / realtime/src / RealtimePluginOptions
Interface: RealtimePluginOptions
Defined in: realtime/src/plugin.ts:60
Properties
authorize?
> optional authorize?: (connection, channel, context) => boolean | Promise<boolean>
Defined in: realtime/src/plugin.ts:71
Server-side subscription gate — return false to refuse a client joining a channel. Set this whenever channels carry data not readable by every member of the tenant (private/admin channels); without it any authenticated connection can subscribe to any channel name in its tenant.
Parameters
connection
channel
string
context
The application's container.
authorize runs outside any request — there is no ctx() when a client opens a stream — and Connection carries id, tenantId and userId. Not roles, not permissions, which is exactly what deciding "may this connection hear this channel" needs.
Without this, gates stashed the container in a module-level variable and filled it from a companion plugin's boot — which is quietly wrong when plugin order changes.
A container rather than resolved roles: the gate does not always want roles. It might want a subscription, a feature flag, a per-tenant setting. Deciding that here would be deciding it for everyone.
container
Returns
boolean | Promise<boolean>
backplane?
> optional backplane?: RealtimeBackplane
Defined in: realtime/src/plugin.ts:62
Fan-out backplane. Default in-memory (single instance).
bridge?
> optional bridge?: BridgeRule<string>[]
Defined in: realtime/src/plugin.ts:64
Rules mapping domain hooks to realtime pushes.
maxChannelLength?
> optional maxChannelLength?: number
Defined in: realtime/src/plugin.ts:95
Max channel-name length (DoS bound). Default 256.
maxSubscriptionsPerConnection?
> optional maxSubscriptionsPerConnection?: number
Defined in: realtime/src/plugin.ts:93
Max distinct channels per connection (DoS bound). Default 1000.
onBridgeError?
> optional onBridgeError?: (error, info) => void
Defined in: realtime/src/plugin.ts:102
Called when a bridged broadcast fails (e.g. the backplane is down). The bridge is fire-and-forget by design — a realtime push is cosmetic and must never fail the domain write that emitted the hook — so failures land here instead of propagating. Default: logs to console with the rule's context.
Parameters
error
unknown
info
channel
string
event
string
hook
string
Returns
void
onBridgeSkipped?
> optional onBridgeSkipped?: (info) => void
Defined in: realtime/src/plugin.ts:115
Called when a rule WITHOUT tenant fires but there is no tenant in the active context (the hook was emitted outside a tenant-scoped request/job: boot, a cron tick, a worker without context). The push is skipped. A rule whose own tenant returns undefined is an explicit opt-out and is NOT reported here.
channel is the rule's channel; for a function channel it is evaluated against the payload, falling back to '<dynamic>' if it throws. Default: console.warn once per rule (not per event), so a misconfigured rule is visible without flooding the logs.
Parameters
info
Returns
void
onDeliveryError?
> optional onDeliveryError?: (error, info) => void
Defined in: realtime/src/plugin.ts:121
A local delivery failed (dead socket) — forwarded to the hub. The connection is pruned and remaining recipients still receive the message. Default: console.error with context.
Parameters
error
unknown
info
channel
string
connectionId
string
event
string
tenantId
string
Returns
void