authorize property
Whether this mutation may be applied at all, asked before anything is written and before validate.
Replay is the one write path where the server is handed a change that nothing on the server decided to make: it was made on a device, possibly days ago, possibly by somebody whose access has since been withdrawn, and it names its own table and key. Applying it because it arrived is the same as having no authorization on the route that carries it.
A generated Model.offlineRemote always supplies one, which asks the
model's own policy -- the same policy an online write asks. This class
is not in the barrel an application imports, so the only remotes
without one are the framework's own and its tests'.
An authorizer that throws refuses. A check that cannot reach its answer is not a yes.
Implementation
final Future<bool> Function(DVMutation mutation)? authorize;