While the BaseEngine class is a singleton, normally, it is possible to have multiple instances of the class in an application if the class is used in multiple contexts that have different providers.
Returns true if ALL configured properties loaded successfully. Useful as a quick health check after engine startup.
Returns a COPY of the metadata configs array for the engine. This is a copy so you can't modify the original configs by modifying this array.
Returns the context user set for the object, this is set via the Config() method.
Observable that emits when any data property changes due to a refresh. Subscribe to this to react to engine data updates (e.g., sync Angular observables).
Events are emitted after data is refreshed in response to BaseEntity save/delete events. The event includes the full config and the new data array.
Returns a read-only snapshot of all engine property load states. Each entry maps a property name to its load status, including entity/dataset name, row count, success/failure flag, and error message if applicable. Used by dev tools for diagnostics and health monitoring.
ProtectedEngineControls the default RunView ResultType for all entity configs loaded by this engine. Override in subclasses to change the default for the entire engine without modifying each individual config entry.
Individual configs can still override this via their own ResultType property.
ProtectedEntityOverridable property to set the debounce time for entity events. Default is 1500 milliseconds (1.5 seconds). This debounce time is used when immediate array mutations cannot be applied (e.g., when Filter, OrderBy, or AdditionalLoading overrides are present) and a full view refresh is required.
Note: When immediate mutations ARE possible (no Filter, OrderBy, or AdditionalLoading override), updates happen synchronously without any debounce delay.
True when the engine loaded successfully but all entity configs were skipped because the current user lacks read permissions. Accessor properties will throw PermissionConstrainedError if accessed in this state. Check this flag first to degrade gracefully.
Returns true if the data has been loaded, false otherwise.
Returns the loading subject. You can call await Config() and after Config() comes back as true that means you're loaded. However you can also directly subscribe to this subject to get updates on the loading status.
ProtectedMaxMaximum number of retries for an event-triggered config refresh that failed transiently. Overridable by subclasses that want more or less persistence.
List of entity names that were skipped due to permission denial. Empty if not permission-constrained. Useful for logging/diagnostics.
Returns the metadata provider to use for the engine. If a provider is set via the Config method, that provider will be used, otherwise the default provider will be used.
Returns the RunView provider to use for the engine. This is the same underlying object as the
StaticInstanceAdds a dynamic metadata configuration at runtime.
The metadata configuration to add
OptionalcontextUser: UserInfoThe context user information
ProtectedAdditionalSubclasses can override this method to perform additional loading tasks
OptionalcontextUser: UserInfoProtectedapplyApplies an immediate array mutation based on the entity event type. This is faster than running a full view refresh for simple add/update/delete operations.
On save, the cached entry is a clone owned by this engine's provider — not the saver's entity instance. Storing the saver's instance would pin the saver's provider (often a per-request provider) inside the engine's cache for the engine's full lifetime, which leaks the provider and all its associated state.
The configuration for the property being mutated
The entity event containing the affected entity and event type
ProtectedapplyRemoves a deleted record from the engine's in-memory arrays using the primary key values from the remote-invalidate event payload. No server round-trip needed.
true if successfully applied to all matching configs, false if fallback is needed
ProtectedapplyApplies record data from a remote-invalidate event directly to the engine's in-memory arrays. Creates a BaseEntity instance, loads the JSON data into it, then updates the matching config arrays — same as applyImmediateMutation but from serialized data instead of a live entity.
true if successfully applied to all matching configs, false if fallback is needed
ProtectedbeginOpens a new full-refresh "generation" for a property and returns its token. Each call bumps the property's monotonic counter, so a token is the latest iff no later refresh for that property has begun since. See _configRefreshGeneration.
ProtectedcanDetermines if an immediate array mutation can be used instead of running a full view refresh. Immediate mutations are only safe when:
The configuration to check
OptionalskipAdditionalLoadingCheck: booleanWhen true, skips the AdditionalLoading override check. Use this when the caller will invoke AdditionalLoading() itself after applying mutations (e.g., applyRemoteRecordData applies all config mutations then calls AdditionalLoading).
true if immediate mutation is safe, false if a full view refresh is needed
ProtectedCheckProtectedCheckAll-or-nothing permission gate: checks CanRead on every entity config. If ANY
entity is denied, ALL configs are skipped — the engine is marked permission-constrained
and its data arrays are set to empty []. This prevents noisy permission-denied errors
and endless retry loops for users with limited permissions (e.g., org-scoped SaaS roles).
On the server side with a system user (who has all permissions), this method returns the original configs unchanged — no behavior change for privileged users.
The original configs array (all permissions pass) or an empty array (any denied)
ProtectedclassifyClassifies a single entity event against a single config's backing array:
For deletes, the by-key membership check uses the event payload's pre-delete OldValues snapshot — BaseEntity.Delete() calls NewRecord() right after raising the event, which wipes field values and REGENERATES the primary key, so the live entity's key can never match the deleted row by the time the debounced handler runs.
ProtectedcloneCreates a fresh BaseEntity owned by this engine's provider and populates it from the given source entity's field values. Used by applyImmediateMutation to avoid pinning the source entity's provider inside this engine's cache.
Configures the engine by loading metadata from the database. Subclasses must implement this method to define their configuration behavior.
Note: This method is called by ConfigEx() - prefer using ConfigEx() directly for new code as it provides more flexible configuration options.
OptionalforceRefresh: booleanOptionalcontextUser: UserInfoOptionalprovider: IMetadataProviderExtended configuration method with object-based options. This provides a more flexible API compared to Config() with positional parameters.
Internally calls Config() after setting up options that Load() can access.
Optionaloptions: ConfigExOptionsConfiguration options object
Promise that resolves when configuration is complete
ProtectedconfigTrue when the config's last load attempt left it in a successfully-loaded state. Reads the same map entry HandleSingleViewResult writes — a transient failure (network, server restart) records loadedSuccessfully=false; a permission denial is recorded as loaded-empty (true) and is deliberately NOT retryable.
ProtectedContextReturns false ONLY when we can positively determine that the effective user
lacks Read permission on entityName. Unknown cases (no entity name, no
resolvable user, entity not in metadata) return true — so the default is to
treat a failure as transient/retryable and server-side system-user loads
(full access) are unaffected.
Used by HandleSingleViewResult to classify a FAILED config load: a load that failed because the user can't read the entity is a PERMANENT condition (a retry will never succeed for this role), so the engine should load that property empty rather than loop on "not marking as loaded" — which is what hangs the Explorer shell for a restricted / app-scoped user (e.g. a magic-link guest). Security is unaffected: the user still receives no data.
This is a classifier consulted AFTER a failure, never a predictive pre-skip — so a readable entity is always actually queried, and stale/late client permission metadata can never cause a readable entity to be silently skipped.
ProtectedDebounceThis method handles the debouncing process, by default using the EntityEventDebounceTime property to set the debounce time. Debouncing is done on a per-entity basis, meaning that if the debounce time passes for a specific entity name, the events will be processed. This is done to prevent multiple events from being processed in quick succession for a single entity which would cause a lot of wasted processing.
ALL events raised during the debounce window are buffered and delivered as one batch to ProcessEntityEvents — not just the last one. The refresh-vs-skip decision must be an OR over every coalesced event: judging only the last event would let an already-applied write (e.g., an engine method's in-place save of a cached instance) mask an earlier fresh-instance save the array has never seen.
Override this method if you want to change how debouncing works, such as having variable debounce times per-entity, etc.
ProtectedemitNotifies subscribers of ObserveProperty(propertyName) that the array has changed.
No-op if no one has ever observed this property (BehaviorSubject not created).
Called from the array mutation sites in BaseEngine.
Ensures the engine is loaded before the caller reads engine state. This is
the right call to make at every consumption point — especially for engines
registered with @RegisterForStartup({ deferred: true }) whose initial load
runs in the background after app boot.
Idempotent: if the engine is already loaded, returns immediately. If a load
is in flight (e.g. the deferred startup or another consumer triggered it),
returns the same in-progress promise rather than starting a second load —
BaseEngine.Load handles this internally via _loadingSubject.
Equivalent to this.Config(false) but reads more clearly at call sites:
await AIEngineBase.Instance.EnsureLoaded();
const models = AIEngineBase.Instance.Models;
OptionalcontextUser: UserInfoOptional context user (server-side only)
Optionalprovider: IMetadataProviderOptional metadata provider override
ProtectedfindFinds an entity in the array by matching all primary key columns. Supports composite primary keys by comparing all PrimaryKey fields from EntityInfo.
The array of entities to search
The entity to find (using its primary key values)
The index of the matching entity, or -1 if not found
ProtectedGetRetrieves engine-loaded data for a config property by name. This is the canonical accessor for engine getter properties — it checks the data map for permission denial and throws PermissionConstrainedError with the specific denied entity name(s) if the config was skipped.
Subclasses should use this in every getter that exposes engine-loaded data:
public get Models(): MJAIModelEntityExtended[] {
return this.GetConfigData<MJAIModelEntityExtended>('_models');
}
The config property name (e.g., '_models', '_agents'), matching the PropertyName used in the engine's Config() params array.
The data array for the property, or an empty array if not yet loaded.
The Global Object Store is a place to store global objects that need to be shared across the application. Depending on the execution environment, this could be the window object in a browser, or the global object in a node environment, or something else in other contexts. The key here is that in some cases static variables are not truly shared because it is possible that a given class might have copies of its code in multiple paths in a deployed application. This approach ensures that no matter how many code copies might exist, there is only one instance of the object in question by using the Global Object Store.
ProtectedHandleThis method handles the individual base entity event. For events that can use immediate array mutations (no Filter, OrderBy, or AdditionalLoading override), processing happens synchronously without debounce. For events that require full view refresh, debouncing is applied to batch rapid successive changes.
Override this method if you want to have a different handling for the filtering of events that are debounced or if you don't want to debounce at all you can do that in an override of this method.
ProtectedHandleSubclasses of BaseEngine can override this method to handle individual MJGlobal events. This is typically done to optimize the way refreshes are done when a BaseEntity is updated. If you are interested in only BaseEntity events, override the HandleIndividualBaseEntityEvent method instead as this method primarily serves to filter all the events we get from MJGlobal and only pass on BaseEntity events to HandleIndividualBaseEntityEvent.
ProtectedHandleHandles remote-invalidate events from cross-server cache invalidation. These events are fired by GraphQLDataProvider when it receives a cache invalidation notification via GraphQL subscription (originating from Redis pub/sub on another server).
When the event payload includes recordData (the saved entity as JSON), the engine applies the change directly to its in-memory array — no server round-trip needed. For delete events or events without recordData, falls back to LoadSingleConfig.
ProtectedHandleHandles the result of a single view load.
OptionalcontextUser: UserInfoAll BaseEngine sub-classes get an implementation of IStartupSink so they can be set the auto start in their app container, if desired, simply by adding the
OptionalcontextUser: UserInfoOptionalprovider: IMetadataProviderProtectedhasChecks if the current instance has overridden the AdditionalLoading method. We do this by comparing the method to the base class's method.
true if AdditionalLoading is overridden, false if using the base implementation
ProtectedisChecks if the exact entity object reference is already in the config's data array. Used to skip unnecessary refreshes for UPDATE events where the object was mutated in place.
The configuration to check
The entity to look for
true if the exact object reference is already in the array
ProtectedisChecks if an entity is in the config's data array by object reference OR by primary key match. Used for DELETE events where we need to know if the entity still exists in the array.
For deletes, pass preDeleteValues (the event payload's OldValues snapshot): by the time
the debounced handler runs, BaseEntity.Delete() has already called NewRecord(), which wipes
the entity's fields and regenerates its primary key — so a by-key check against the live
entity can never match the deleted row. Same hazard (and same OldValues workaround) as
LocalCacheManager.HandleBaseEntityEvent.
The configuration to check
The entity to look for
OptionalpreDeleteValues: Record<string, unknown>Pre-delete field snapshot (delete event payload's OldValues)
true if the entity is in the array (by reference or by primary key)
ProtectedisTrue when generation is still the most recent token handed out by
beginConfigRefresh for propertyName — i.e. no newer full refresh for this
property has started since. A refresh whose token is stale must NOT commit its results:
a newer refresh was initiated afterward and read a more-recent state.
Check if a specific property was skipped due to permission denial. Forward-compatible with a future partial-loading approach.
ProtectedLoadThis method should be called by sub-classes to load up their specific metadata requirements. For more complex metadata loading or for post-processing of metadata loading done here, overide the AdditionalLoading method to add your logic.
OptionalforceRefresh: booleanOptionalcontextUser: UserInfoProtectedLoadLoads the specified metadata configurations.
The metadata configurations to load
The context user information
OptionalbypassCache: booleanWhen true, bypasses all server-side caching (RunView and dataset) to fetch fresh data
directly from the database. Passed through from Load when forceRefresh is true (i.e., Config(true)).
ProtectedLoadHandles the process of loading multiple entity configs in a single network call via RunViews()
OptionalbypassCache: booleanWhen true, bypasses server-side cache to get fresh data from the database
ProtectedLoadLoads a single metadata configuration.
The metadata configuration to load
The context user information
OptionalbypassCache: booleanWhen true, bypasses server-side cache to get fresh data from the database
ProtectedLoadHandles the process of loading a single config of type 'dataset'.
OptionalbypassCache: booleanWhen true, bypasses server-side cache to get fresh data from the database.
Uses IMetadataProvider.GetDatasetByName with forceRefresh to skip all cache reads,
then IMetadataProvider.CacheDataset to store fresh results for subsequent non-forced calls.
ProtectedLoadHandles the process of loading a single config of type 'entity'.
OptionalbypassCache: booleanWhen true, bypasses server-side cache to get fresh data from the database
ProtectedMarkRecords a config as successfully loaded with an EMPTY result set. Used when a load failed permanently because the context user lacks Read on the entity: the engine exposes an empty array (not a hang) and is marked loaded so shell boot can complete for a restricted role.
ProtectednotifyEmits change notifications for a config whose backing array ALREADY reflects the
entity event — e.g., engine code saved the array's own cached instance in place,
or manually pushed a newly created entity after Save. In those cases
ProcessEntityEvent safely skips the redundant refresh, but the notification
must NOT be skipped: without it, DataChange$ and ObserveProperty subscribers
(and anything derived from them downstream) never learn the array changed and are
stranded on stale state.
Engine subclasses that manually SPLICE a deleted row out of a config's array must call this themselves ('delete') right after splicing — the debounced event handler cannot distinguish "already spliced" from "never matched this config's Filter", so it stays silent for absent rows.
Deliberately does not run AdditionalLoading — the skip paths never did, and engines that maintain their arrays manually own any derived-data updates themselves.
ProtectedNotifyNotify listeners that a data property has changed. Called automatically by HandleSingleViewResult after data refresh and by applyImmediateMutation for array operations. Subclasses can also call this manually when modifying data arrays directly.
The configuration for the property that changed
The current data array
OptionalchangeType: "delete" | "update" | "add" | "refresh"The type of change: 'refresh', 'add', 'update', or 'delete'
OptionalaffectedEntity: BaseEntityFor add/update/delete, the entity that was affected
Returns an Observable for a specific engine array property. Subscribers receive the current array immediately (BehaviorSubject semantics), then re-receive the same array reference whenever the engine mutates it (save, delete, remote-invalidate, refresh).
The BehaviorSubject for a property is lazy-created on first call — engines where no one observes a property pay zero runtime cost.
The name of the backing array property on the engine (e.g. _UserNotifications).
ProtectedOnCalled when another server instance updates cached data that this engine is tracking. Default behavior: reload the affected config from the database.
Engines can override this for custom behavior (e.g., incremental update using the event's CacheChangedEvent.Data payload).
The engine property config whose data changed
The cache change event from the other server
ProtectedProcessBack-compat single-event wrapper around ProcessEntityEvents. The debounced pipeline delivers full batches to ProcessEntityEvents — override THAT method to change event-processing behavior; this wrapper exists for subclasses/tests that process one event at a time.
ProtectedProcessDoes the actual work of processing all entity events coalesced into one debounce window. Not called directly from the event handler because we first debounce the events, which also introduces a delay that is usually desirable so processing happens outside the scope of any transaction processing that originated the events.
Per matching config, the decision is an OR over the whole batch:
A transiently-failed refresh schedules a bounded retry via scheduleEventRefreshRetry — without it, the consumed debounce event would leave observers permanently stale until an unrelated event arrived.
This is the best method to override if you want to change the actual processing of entity events but do NOT want to modify the debouncing behavior.
Returns true if the specified property loaded successfully during engine startup. Returns false if the property failed to load (e.g., RunView error) or was never loaded. Consumers can use this to detect partial load failures and trigger recovery.
Refreshes all items
Refreshes a specific item.
The name of the property to refresh
ProtectedRegisterRegisters cross-server cache change callbacks for entity configs. When another server instance updates cached data for an entity this engine tracks, the engine will automatically reload the affected config.
This enables multi-server deployments to keep engine in-memory arrays synchronized without polling. Requires a Redis-backed storage provider with pub/sub enabled (via RedisLocalStorageProvider.StartListening).
The entity configurations to register callbacks for
Removes a dynamic metadata configuration at runtime.
The name of the property to remove
ProtectedscheduleSchedules a bounded, backed-off retry of a config refresh that failed transiently during entity-event processing. Without this, one failed RunView after a save would permanently strand every observer on stale data — the debounced event is already consumed, so nothing else re-runs the refresh until an unrelated event for the same entity arrives.
At most one retry is pending per property at a time; a retry that succeeds notifies observers through the normal HandleSingleViewResult → NotifyDataChange path. Permission denials never reach here (HandleSingleViewResult marks them loaded-empty).
The config whose refresh failed
1-based attempt number; delays back off linearly (2s, 4s, ...)
ProtectedSetInternal method to set the provider when an engine is loaded. Once this engine instance has a provider bound, subsequent calls are no-ops — preventing transient per-request providers from displacing the persistent provider that first bound to this connection. The cache key is the connection (not the object), so the first persistent provider to load an engine for a connection "owns" the engine for that connection's lifetime.
ProtectedSetupThis method is responsible for registering for MJGlobal events and listening for BaseEntity events where those BaseEntity are related to the engine's configuration metadata. The idea is to auto-refresh the releated configs when the BaseEntity is updated.
ProtectedsyncSyncs an entity change to the LocalCacheManager for a config with CacheLocal enabled. This ensures that IndexedDB/localStorage stays in sync with the engine's in-memory array.
Only called for configs WITHOUT Filter/OrderBy (immediate mutation path). Filtered/sorted configs use debounced refresh which handles its own caching.
The configuration for the property being synced
The entity event containing the affected entity and event type
ProtectedTryHelper method for sub-classes to have a single line of code that will make sure the data is loaded before proceeding and will throw an error if not loaded.
ProtectedUpgradeUtility method to upgrade an object to a BaseEnginePropertyConfig object.
Protected StaticgetReturns the singleton instance of the class. If the instance does not exist, it is created and stored in the Global Object Store. If className is provided it will be used as part of the key in the Global Object Store, otherwise the actual class name will be used. NOTE: the class name used by default is the lowest level of the object hierarchy, so if you have a class that extends another class, the lowest level class name will be used.
OptionalclassName: stringStaticGetReturns the cached engine instance for this engine subclass on the connection the given
provider points to, creating one if none exists yet. Lookup is keyed by the provider's
InstanceConnectionString so multiple provider objects targeting the same connection
share a single cached engine.
StaticRemoveRemoves all cached engine instances for the given connection. Call this when a connection is being torn down (e.g. multi-tenant client logging out) to release the cached engines' memory eagerly. For normal server operation this is rarely needed — the cache is bounded by (distinct connections × engine classes), which is small.
Simple cache for commonly used type tables across the system that are outside of what we have in the Metadata object