authorize property

Future<bool> Function(DVMutation mutation)? authorize
final

Whether this mutation may be applied at all, asked before anything is written and before validate.

Replay is the one write path where the server is handed a change that nothing on the server decided to make: it was made on a device, possibly days ago, possibly by somebody whose access has since been withdrawn, and it names its own table and key. Applying it because it arrived is the same as having no authorization on the route that carries it.

A generated Model.offlineRemote always supplies one, which asks the model's own policy -- the same policy an online write asks. This class is not in the barrel an application imports, so the only remotes without one are the framework's own and its tests'.

An authorizer that throws refuses. A check that cannot reach its answer is not a yes.

Implementation

final Future<bool> Function(DVMutation mutation)? authorize;