basalt / teams/src / TenantMembershipPluginOptions
Interface: TenantMembershipPluginOptions
Defined in: teams/src/plugin.ts:97
Properties
cache?
> optional cache?: object
Defined in: teams/src/plugin.ts:124
Opt-in decision cache. Without it every authenticated, tenant-scoped request costs one membership lookup (a single indexed PK read — usually fine). With it, decisions are cached in-process for ttlMs and invalidated immediately by the team:joined / team:role_changed / team:member_removed hooks, so same-process changes are always exact; ttlMs only bounds staleness for changes made on ANOTHER replica — i.e. a member removed elsewhere may retain access for up to ttlMs. Size-bounded by maxEntries (default 10_000, oldest evicted).
maxEntries?
> optional maxEntries?: number
ttlMs
> ttlMs: number
exempt?
> optional exempt?: (context) => boolean
Defined in: teams/src/plugin.ts:113
Context-level escape hatch for identities that legitimately cross tenants (platform admins, support impersonation). Return true to skip the membership check for this request, e.g. exempt: ({ user }) => user?.platformAdmin === true. Prefer this over marking routes meta.central when the exemption is about WHO is calling (central disables the guard for everyone on that route).
Parameters
context
Record<string, unknown>
Returns
boolean
role?
> optional role?: string
Defined in: teams/src/plugin.ts:104
Require a minimum RANKED role instead of plain membership. Default: undefined — any membership record passes (an existence check), so members holding custom roles that are absent from roleRank are not rejected. Set e.g. role: 'member' to enforce rank semantics explicitly.