basalt / tenancy/src / CustomDomainsOptions
Interface: CustomDomainsOptions
Defined in: tenancy/src/custom-domains.ts:211
Properties
challengeSecret?
> optional challengeSecret?: string
Defined in: tenancy/src/custom-domains.ts:242
Secret that derives a tenant's DNS challenge for a domain someone else holds unverified (challenge()), so that the verified TXT wins: once the real owner publishes it, their add() takes the domain over immediately instead of waiting for the squatter's claim to expire. Keep it stable and identical across instances. Without it, contested domains are freed only by expiry.
claimTtlMs?
> optional claimTtlMs?: number
Defined in: tenancy/src/custom-domains.ts:227
How long an UNVERIFIED claim holds a domain, in milliseconds. Default 72 h.
A claim costs nothing but a sign-up, so without an expiry any tenant could register a domain it does not own and block the real owner forever. Once a claim is older than this and still unverified, another tenant's add() takes the domain over. Verified domains never expire. Infinity disables expiry (not recommended).
now?
> optional now?: () => number
Defined in: tenancy/src/custom-domains.ts:213
Returns
number
reservedDomains?
> optional reservedDomains?: string[]
Defined in: tenancy/src/custom-domains.ts:234
The platform's own domains — e.g. ['basalt.app']. Each one and every subdomain of it is refused by add() with DomainReservedError: tenant subdomains are assigned by the platform (subdomainResolver), never claimed through custom domains. Default: none — set it to your apex.
resolveTxt?
> optional resolveTxt?: (hostname) => Promise<string[][]>
Defined in: tenancy/src/custom-domains.ts:217
DNS TXT resolver (tests). Default: node:dns/promises resolveTxt.
Parameters
hostname
string
Returns
Promise<string[][]>
store?
> optional store?: DomainStore
Defined in: tenancy/src/custom-domains.ts:212
token?
> optional token?: () => string
Defined in: tenancy/src/custom-domains.ts:215
Token generator (tests). Default: 24 random bytes, base64url.
Returns
string