Skip to content

basalt / teams/src / TenantMembershipPluginOptions

Interface: TenantMembershipPluginOptions ​

Defined in: teams/src/plugin.ts:97

Properties ​

cache? ​

> optional cache?: object

Defined in: teams/src/plugin.ts:124

Opt-in decision cache. Without it every authenticated, tenant-scoped request costs one membership lookup (a single indexed PK read — usually fine). With it, decisions are cached in-process for ttlMs and invalidated immediately by the team:joined / team:role_changed / team:member_removed hooks, so same-process changes are always exact; ttlMs only bounds staleness for changes made on ANOTHER replica — i.e. a member removed elsewhere may retain access for up to ttlMs. Size-bounded by maxEntries (default 10_000, oldest evicted).

maxEntries? ​

> optional maxEntries?: number

ttlMs ​

> ttlMs: number


exempt? ​

> optional exempt?: (context) => boolean

Defined in: teams/src/plugin.ts:113

Context-level escape hatch for identities that legitimately cross tenants (platform admins, support impersonation). Return true to skip the membership check for this request, e.g. exempt: ({ user }) => user?.platformAdmin === true. Prefer this over marking routes meta.central when the exemption is about WHO is calling (central disables the guard for everyone on that route).

Parameters ​

context ​

Record<string, unknown>

Returns ​

boolean


role? ​

> optional role?: string

Defined in: teams/src/plugin.ts:104

Require a minimum RANKED role instead of plain membership. Default: undefined — any membership record passes (an existence check), so members holding custom roles that are absent from roleRank are not rejected. Set e.g. role: 'member' to enforce rank semantics explicitly.

Released under the MIT License.