AbstractProtected_Result from PreRunQueries hook containing cache status for batch operations
Protected_Result from PreRunQuery hook containing cache status and optional cached result
Protected_Result from PreRunView hook containing cache status and optional cached result
OptionalcachedResult?: RunViewResultOptionalcallerRequestedFields?: string[]The caller's original Fields list (lowercased), captured before PreRunView widened params.Fields to all entity fields for cache-superset storage. Non-null ONLY when that widening actually happened — PostRunView uses it to project cache-miss DB results back down to the requested shape.
Optionalfingerprint?: stringOptionaltelemetryEventId?: stringProtected_Result from PreRunViews hook containing cache status for batch operations
OptionalcachedResults?: RunViewResult[]OptionalcacheStatusMap?: Map<OptionalcallerFieldsMap?: Map<number, string[]>Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.
OptionalfingerprintMap?: Map<number, string>Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.
OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]When CacheLocal is enabled, contains the cache check params to send to server
OptionaltelemetryEventId?: stringOptionaluncachedParams?: RunViewParams[]OptionaluseSmartCacheCheck?: booleanWhen CacheLocal is enabled, indicates we should use smart cache check
Protected Static_StaticCoalesceWhen enabled, concurrent RunViews calls arriving within the same microtask (or within CoalesceWindowMs) are merged into a single mega-batch before hitting the network. This dramatically reduces the number of HTTP round-trips during startup when multiple engines independently call RunViews in parallel.
Set to 0 to disable coalescing. Default 10ms — enough to capture all engines that fire in the same tick, without adding perceptible delay.
StaticDedupHow long (ms) a resolved RunViews result stays available for instant replay. Set to 0 to disable the linger window (in-flight dedup still applies). Default 5 000 ms.
StaticMaxSafety cap on the number of linger entries held simultaneously. The linger window is a latency optimization — under extreme churn (more distinct query keys than this resolving within one window) new resolutions skip lingering instead of accumulating result arrays in memory.
StaticMinMinimum interval (ms) between metadata refresh checks to prevent redundant network calls when Config()/RefreshIfNeeded() fire in quick succession (e.g., multiple engines during startup). Does NOT affect forced Refresh() calls. Default: 30 000 ms.
StaticServerMaximum row count for auto-caching on the server side. When
TrustLocalCacheCompletely is true and a RunView result has no
ExtraFilter, no OrderBy, and the result count is at or below this
threshold, the result is automatically stored in LocalCacheManager
even without an explicit CacheLocal flag.
This captures small reference/lookup tables that are repeatedly queried by multiple clients while avoiding caching large ad-hoc result sets. Invalidation is handled by the standard BaseEntity event-driven upsert (safe because unfiltered caches can be updated in-place).
Set to 0 to disable auto-caching. Default 250.
Gets all explorer navigation items including inactive ones.
Array of all ExplorerNavigationItem objects
Returns the currently loaded local metadata from within the instance
Protected AbstractAllowDetermines if a refresh is currently allowed or not. Subclasses should return FALSE if they are performing operations that should prevent refreshes. This helps avoid metadata refreshes during critical operations.
Gets all application metadata in the system.
Array of ApplicationInfo objects representing all applications
Gets all audit log types defined for tracking system activities.
Array of AuditLogTypeInfo objects
Gets the flat collection of authorization-role assignments.
Consumed lazily by AuthorizationInfo.Roles — consumers should
prefer accessing roles through AuthorizationInfo.Roles rather than
filtering this array directly.
Array of AuthorizationRoleInfo join-table objects
Gets all authorization definitions in the system.
Array of AuthorizationInfo objects defining permissions
Gets the configuration data that was provided to the provider.
The provider configuration including schema filters
Gets the current user's information including roles and permissions.
UserInfo object for the authenticated user
AbstractDatabaseFor providers that have ProviderType==='Database', this property will return an object that represents the underlying database connection. For providers where ProviderType==='Network' this property will throw an exception. The type of object returned is provider-specific (e.g., SQL connection pool).
Protected AbstractDBRegex pattern matching known database default-value functions (non-UUID) for this provider's platform. SQL Server should match GETDATE, GETUTCDATE, SYSDATETIME, etc. PostgreSQL should match NOW, CURRENT_TIMESTAMP, clock_timestamp, etc. Case-insensitive, should match the full string with optional whitespace and parens.
The SQLDialect instance matching this provider's PlatformKey.
Use this whenever runtime code needs to emit dialect-specific SQL
(boolean literals, identifier quoting, casts, …) — it spares callers
from doing GetDialect(provider.PlatformKey) every time, and keeps
dialect resolution in one place. Resolves lazily and is cached so
repeated access is free.
Example:
const lit = provider.Dialect.BooleanLiteral(true); // '1' on SS, 'TRUE' on PG
Gets all entity metadata in the system.
Array of EntityInfo objects representing all entities
Returns the filesystem provider for the current environment. Default implementation returns null (no filesystem access). Server-side providers should override this to return a NodeFileSystemProvider.
AbstractInstanceThis property is implemented by each sub-class of ProviderBase and is intended to return a unique string that identifies the instance of the provider for the connection it is making. For example: for network connections, the URL including a TCP port would be a good connection string, whereas on database connections the database host url/instance/port would be a good connection string. This is used as part of cache keys to ensure different connections don't share cached data.
Whether this provider currently has an active transaction. Subclasses
that track transaction state should override this. Used by callers
(e.g. runMaybeSerial) to decide whether to fan out concurrent saves
or run them sequentially. Defaults to false for providers that don't
expose this state.
Gets the latest metadata timestamps from local cache. Used for comparison with remote timestamps.
Array of locally cached metadata timestamps
Gets the latest metadata timestamps from the remote server. Used to determine if local cache is out of date.
Array of metadata timestamp information
Gets all library definitions in the system.
Array of LibraryInfo objects representing code libraries
ProtectedLocalThis property will return the prefix to use for local storage keys. This is useful if you have multiple instances of a provider running in the same environment and you want to keep their local storage keys separate. The default implementation returns an empty string, but subclasses can override this to return a unique string based on the connection or other distinct identifier.
AbstractLocalGets the local storage provider implementation. Must be implemented by subclasses to provide environment-specific storage.
Local storage provider instance
Protected AbstractMetadataGets the metadata provider instance. Must be implemented by subclasses to provide access to metadata.
The metadata provider instance
Gets the MemberJunction core schema name (e.g. '__mj'). Subclasses should override if they have a different way to resolve this. Defaults to the value from ConfigData.
Returns the database platform key for this provider. Override in subclasses. Defaults to 'sqlserver' for backward compatibility. Inherited from ProviderBase; redeclared here for DatabaseProviderBase consumers.
ProtectedPreProtectedPreProtectedPreOptionalcachedResult?: RunViewResultOptionalcallerRequestedFields?: string[]The caller's original Fields list (lowercased), captured before PreRunView widened params.Fields to all entity fields for cache-superset storage. Non-null ONLY when that widening actually happened — PostRunView uses it to project cache-miss DB results back down to the requested shape.
Optionalfingerprint?: stringOptionaltelemetryEventId?: stringProtectedPreOptionalcachedResults?: RunViewResult[]OptionalcacheStatusMap?: Map<OptionalcallerFieldsMap?: Map<number, string[]>Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.
OptionalfingerprintMap?: Map<number, string>Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.
OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]When CacheLocal is enabled, contains the cache check params to send to server
OptionaltelemetryEventId?: stringOptionaluncachedParams?: RunViewParams[]OptionaluseSmartCacheCheck?: booleanWhen CacheLocal is enabled, indicates we should use smart cache check
AbstractProviderReturns the provider type for the instance. Identifies whether this is a Database or Network provider.
Gets all security roles defined in the system.
Array of RoleInfo objects representing all roles
Gets all row-level security filters defined in the system.
Array of RowLevelSecurityFilterInfo objects for data access control
ProtectedTrustServer-side providers trust the local cache completely because it is kept in perfect sync via BaseEntity save/delete events and cross-server Redis pub/sub. No lightweight DB validation needed on cache hits.
Protected AbstractUUIDRegex pattern matching known database UUID/ID generation functions for this provider's platform. SQL Server should match NEWID, NEWSEQUENTIALID. PostgreSQL should match gen_random_uuid, uuid_generate_v4. Case-insensitive, should match the full string with optional whitespace and parens.
Gets only active explorer navigation items sorted by sequence. Results are cached for performance.
Array of active ExplorerNavigationItem objects
Background validation for the stale-while-revalidate fast-start pattern. Checks if local metadata is still current; if stale, fetches fresh metadata and atomically swaps it in. The app continues operating on cached data during this process — no blocking.
OptionalproviderToUse: IMetadataProviderAbstractBeginBegins a transaction for the current database connection.
ProtectedBuildBuilds and validates an aggregate SQL query from the provided aggregate expressions. Uses SQLExpressionValidator from @memberjunction/global for injection prevention. Uses QuoteIdentifier/QuoteSchemaAndView for dialect-neutral SQL generation.
Array of aggregate expressions to validate and build
Entity metadata for field reference validation
Schema name for the entity
Base view name for the entity
WHERE clause to apply (without the WHERE keyword)
Object with aggregateSQL string and any validation errors
Protected AbstractBuildBuilds a UNION ALL query that checks each child entity's base table for a record with the given primary key. Used by FindISAChildEntity/FindISAChildEntities.
The child entities to search
The primary key value to find
ProtectedBuildBuilds dataset filters based on the provider configuration. Ensures MJ Core schema is always included and never excluded.
Array of filters to apply when loading metadata
ProtectedBuildBuilds the ExecuteSQLOptions for a Delete operation.
ProtectedBuildBuilds the SQL to retrieve the "name" field value for a specific entity record. Uses QuoteIdentifier/QuoteSchemaAndView for dialect-neutral SQL generation.
The entity name
The record's primary key
The SQL query string, or null if the entity has no name field
Protected AbstractBuildBuilds SQL for hard-link (foreign key) dependency queries. Returns a UNION ALL query across all dependent entities.
The entity-level dependency metadata
The primary key of the record being checked
Builds a parameter placeholder for parameterized queries. Default: PG-style ($1, $2, ...). SQL Server overrides to @p0, @p1, etc.
Zero-based parameter index
ProtectedBuildBuilds the dialect-agnostic payload for a RecordChange row from the entity's old/new data and an optional restore context. Concrete providers consume the returned payload to render their dialect-specific SQL (SQL Server EXEC, PostgreSQL INSERT, etc.).
Returns null when there's nothing to log — i.e., an Update where
DiffObjects found no field-level changes. Creates and Deletes
are always logged (one side of oldData/newData is null).
The payload's recordID is whatever the caller passes in. PG's
inline CTE save/delete paths can pass an empty string and resolve
the actual RecordID expression in SQL (because the post-INSERT PK
isn't known in JS); the standalone BuildRecordChangeSQL path
passes a fully-resolved composite-key string.
Post-change data (null for deletes).
Pre-change data (null for creates).
Composite-key serialized RecordID, or empty for CTE callers.
Entity metadata (provides EntityID + field shapes for diff).
Change type. Create and Delete skip the change-key short-circuit.
Acting user (provides UserID).
OptionalrestoreContext: RestoreContextWhen non-null, populates source='Restore' plus the
lineage columns; otherwise source='Internal'.
Quote character for EscapeQuotesInProperties and
DiffObjects. Defaults to single quote.
Protected AbstractBuildBuilds the SQL (and optional parameters) for inserting a record change entry. Each provider generates its own dialect: SQL Server uses EXEC spCreateRecordChange_Internal, PostgreSQL uses INSERT INTO "RecordChange" with parameterized values.
Returns null if there are no changes to log.
Implementations should delegate the dialect-agnostic assembly work to BuildRecordChangePayload and only handle SQL string rendering locally — that's how the duplication between SQL Server and PostgreSQL stays minimal.
OptionalrestoreContext: RestoreContextWhen non-null, the resulting RecordChange row is
written with Source='Restore', RestoredFromID = SourceChangeID,
and RestoreReason = Reason. Read by callers from
BaseEntity.RestoreContext immediately before generating SQL.
ProtectedBuildBuilds the ExecuteSQLOptions for a Save operation. SQL Server overrides to add connectionSource for IS-A shared transactions.
Protected AbstractBuildBuilds the SQL for a single sibling entity's record change entry in the propagation batch. SQL Server uses FOR JSON PATH + spCreateRecordChange_Internal. PostgreSQL uses json_build_object + INSERT INTO "RecordChange".
Protected AbstractBuildBuilds SQL for soft-link dependency queries (entities using EntityIDFieldName pattern). Returns a UNION ALL query across all soft-linked entities.
The entity name being checked for dependencies
The primary key of the record
Stores a dataset in the local cache. If itemFilters are provided, the combination of datasetName and the filters are used to build a key and determine a match in the cache
ProtectedcacheSECURITY — decide whether the shared cache must be BYPASSED for a RunView that targets
a saved VIEW rather than a named entity (no EntityName), under a context user.
The cache-hit path returns BEFORE the DB provider's read-permission gate
(CheckUserReadPermissions). The primary gate keys off the entity resolved from
params.EntityName, so a ViewID-/ViewName-only request (the Explorer-standard shape for a
saved view) yields no entity there and the gate is disarmed — a read-denied user could be
served rows a permitted user warmed for the same ViewID. The vw: fingerprint segment makes
the two users' requests collide on exactly one slot, so the leak is clean.
Returns true when the cache must be skipped for this call (fail-closed):
ViewEntity supplied and its entity resolves → apply the normal CanRead gate on it
(allow caching for a permitted user; deny for a read-denied one).ViewEntity absent/unresolvable but ViewID/ViewName present → fail closed: the view's
real entity (hence the user's permission) is only known after the async MJ: User Views
lookup that the cache-hit path deliberately skips, so we cannot safely consult the cache.
Returns false when there is no context user, when EntityName is set (the normal gate owns
that path), or when no view identifier is present at all (nothing to gate).OptionalcontextUser: UserInfoProtected AbstractCheckChecks whether a new record's field values pass the Create RLS filter. Subclasses must implement the actual RLS check logic.
Protected AbstractCheckChecks whether an existing record passes RLS for a given permission type (Update or Delete). Subclasses must implement the actual RLS check logic.
Checks if local metadata is out of date and needs refreshing. Compares local timestamps with server timestamps.
OptionalproviderToUse: IMetadataProviderTrue if refresh is needed, false otherwise
ProtectedCheckChecks that the given user has read permissions on the specified entity. Throws if the user lacks CanRead permission.
The entity to check permissions for
The user whose permissions to check
If the specified datasetName is cached, this method will clear the cache. If itemFilters are provided, the combination of datasetName and the filters are used to determine a match in the cache
OptionalitemFilters: DatasetItemFilterType[]ProtectedCloneThe reuse-global fast path now builds a shared shell instead — see CreateSharedMetadataShell. The metadata graph is immutable after Config, so re-instantiating every Info object (~1s of synchronous constructor work for a ~600-entity install) bought no isolation the shell doesn't already provide. Subclass OVERRIDES of this method are still honored on the fast path (see CopyMetadataFromGlobalProvider) for backward compatibility; new customizations should override CreateSharedMetadataShell instead.
AbstractCommitCommits the current transaction.
ProtectedCompleteFinalizes merge logging by updating the log record with completion status and creating deletion detail records. Uses BaseEntity with .Set() calls (no typed entity subclass imports).
OptionalcontextUser: UserInfoProtectedComputeComputes the per-user Row-Level-Security WHERE clause that InternalRunView will append to this query's SQL for the given user, so it can be folded into the cache fingerprint. RLS-scoped reads return a different result set than unscoped reads of the same entity+filter; without including the RLS clause in the cache key, a scoped user could be served a cached unscoped result set (a data leak).
Returns '' when the user is exempt from RLS on this entity (the common case), which makes the resulting fingerprint byte-identical to the pre-RLS format — preserving normal cache sharing.
Uses this (the active provider) to resolve the entity, never the global Metadata, so the
correct per-provider/per-tenant metadata is consulted.
OptionalcontextUser: UserInfoConfigures the provider with the specified configuration data. Handles metadata refresh if needed and initializes the provider.
Configuration including schema filters and connection info
OptionalproviderToUse: IMetadataProviderTrue if configuration was successful
ProtectedConvertConverts dataset item filters into a unique string key for caching.
Array of filters to convert
JSON-formatted string representing the filters
ProtectedCopyAdopts the global provider's metadata for this instance without reloading it from the server: shares the (immutable post-Config) metadata arrays by reference via CreateSharedMetadataShell and builds this instance's entity lookup maps.
Creates an audit log record in the MJ: Audit Logs entity. Uses BaseEntity with .Set() calls (no typed entity subclass imports needed - can't use those from MJCore anyway). Callers typically fire-and-forget.
The user performing the action
Optional authorization name to look up
The audit log type name (must exist in metadata)
'Success' or 'Failed'
Optional details (JSON string, description, etc.)
The entity ID being audited
Optional record ID being audited
Optional description for the audit log
Save options to pass to the entity Save() call
The saved audit log BaseEntity, or null on error
ProtectedCreateBuilds this instance's AllMetadata as a thin shell over another provider's already-loaded metadata: every metadata array is a PER-INSTANCE shallow copy whose elements are the SHARED Info object instances, and CurrentUser remains this instance's own.
Why sharing the instances is safe — and why this replaced the former deep clone (CloneAllMetadata) on the reuse-global fast path: the metadata graph is immutable after Config. Refreshes swap the WHOLE AllMetadata object (UpdateLocalMetadata), never mutate the Info objects in place, so the only per-instance datum inside the graph is CurrentUser — which this shell keeps independent. The deep clone cost ~1s of event-loop-blocking constructor work per provider on every server request (MemberJunction/MJ#3083); the shell is ~20 array-of-pointer copies (microseconds).
Why the array containers are copied rather than aliased: an in-place
.sort()/.push()/.splice() by request-scoped code then stays local to
that provider — matching the clone era's isolation for the common accidental
mutation class — instead of reordering the global graph for every other
in-flight request. Only the top-level AllMetadata collections get this
per-instance protection: everything below them is shared, including the
nested arrays owned by Info objects (entity.Fields,
entity.RelatedEntities, application.ApplicationEntities, ...) — an
in-place mutation of those is process-wide. Property writes on the shared
Info objects themselves are likewise visible process-wide (as they always
were on the client's global provider): treat Info objects and everything
they own as read-only; copy before sorting.
Override precedence: if a subclass overrides BOTH this method and the deprecated CloneAllMetadata, the CloneAllMetadata override wins on the fast path (see CopyMetadataFromGlobalProvider) — the conservative back-compat choice, since pre-#3083 subclasses could only have customized adoption through CloneAllMetadata. Remove the CloneAllMetadata override to activate a CreateSharedMetadataShell override.
AbstractCreateCreates a new transaction group for managing database transactions. Must be implemented by subclasses to provide transaction support.
A new transaction group instance
Converts a diff/changes object into a human-readable description of what changed.
The output of DiffObjects()
Maximum length for displayed values before truncation
Text to append when values are truncated
Deletes an entity record — the full orchestration flow shared by all DB providers.
Creates a changes object by comparing two JavaScript objects, identifying fields that have different values. Each property in the returned object represents a changed field, with the field name as the key.
The original data object to compare from
The new data object to compare to
Entity metadata used to validate fields and determine comparison logic
The quote character to escape in string values (typically "'")
A Record mapping field names to FieldChange objects, or null if either input is null/undefined. Only includes fields that have actually changed and are not read-only.
O(1) entity lookup by ID (UUID-normalized). Falls back to linear search if the internal Map hasn't been built yet.
O(1) entity lookup by name (case-insensitive, trimmed). Falls back to linear search if the internal Map hasn't been built yet.
ProtectedEntityUsed to check to see if the entity in question is active or not If it is not active, it will throw an exception or log a warning depending on the status of the entity being either Deprecated or Disabled.
OptionalcontextUser: UserInfoProtectedEscapeRecursively escapes the specified quote character in all string properties of an object or array. Essential for preparing data to be embedded in SQL strings.
The object, array, or primitive value to process
The quote character to escape (typically single quote "'")
A new object/array with all string values having quotes properly escaped
ProtectedExecuteExecutes an aggregate query and maps results back to the original expressions.
The SQL query to execute (from BuildAggregateSQL)
Original aggregate expression definitions
Any validation errors from BuildAggregateSQL
OptionalcontextUser: UserInfoUser context for query execution
Array of AggregateResult objects with execution time
Executes a query from a QueryExecutionSpec — the lower-layer interface-based entry point.
Runs the full pipeline: composition resolution → Nunjucks template processing → SQL execution.
Subclasses (GenericDatabaseProvider) provide the concrete implementation via InternalExecuteQueryFromSpec.
The execution spec describing the query, parameters, and inline dependencies
OptionalcontextUser: UserInfoOptional user context for permissions (required server-side)
Query results including data rows and execution metadata
AbstractExecuteExecutes a SQL query with optional parameters and options.
The type of the result set
Optionalparameters: unknown[]Optionaloptions: ExecuteSQLOptionsOptionalcontextUser: UserInfoA promise that resolves to an array of results of type T
ProtectedextractDiscovers ALL IS-A child entities that have records with the given primary key. Used for overlapping subtype parents (AllowMultipleSubtypes = true) where multiple children can coexist.
The parent entity whose children to search
The primary key value to find in child tables
OptionalcontextUser: UserInfoOptional context user for audit/permission purposes
Array of child entity names found (empty if none)
Discovers which IS-A child entity, if any, has a record with the given primary key. Executes a single UNION ALL query across all child entity tables for maximum efficiency.
The parent entity whose children to search
The primary key value to find in child tables
OptionalcontextUser: UserInfoOptional context user for audit/permission purposes
The child entity name if found, or null if no child record exists
Performs a full-text search across all entities that have FullTextSearchEnabled=true. Uses the existing RunView + UserSearchString infrastructure which routes through the database-native FTS capabilities (SQL Server FREETEXT functions, PostgreSQL tsvector).
This is the default implementation that works across all database providers. Each provider's createViewUserSearchSQL() method handles the platform-specific SQL generation.
OptionalcontextUser: UserInfoProtected AbstractGenerateGenerates the SQL (and optional parameters) for a Delete operation.
Generates a new UUID suitable for use as a primary key or unique identifier. Uses uuidv4() from @memberjunction/global. Subclasses may override to provide platform-specific ID generation if needed.
A new UUID string
Protected AbstractGenerateGenerates the SQL (and optional parameters) for a Save (Create or Update) operation. Each provider produces its own dialect: SQL Server generates T-SQL EXEC statements, PostgreSQL generates SELECT FROM function(...) calls, etc.
The entity being saved
True for INSERT / Create, false for UPDATE
The acting user (needed for encryption, audit columns, etc.)
ProtectedGetRetrieves all metadata from the server and constructs typed instances. Uses the MJ_Metadata dataset for efficient bulk loading.
OptionalproviderToUse: IMetadataProviderOptionalforceRefresh: booleanComplete metadata collection with all relationships
Gets a database by name, if required, and caches it in a format available to the client (e.g. IndexedDB, LocalStorage, File, etc). The cache method is Provider specific If itemFilters are provided, the combination of datasetName and the filters are used to determine a match in the cache
OptionalitemFilters: DatasetItemFilterType[]OptionalcontextUser: UserInfoOptionalproviderToUse: IMetadataProviderThis routine gets the local cached version of a given datasetName/itemFilters combination, it does NOT check the server status first and does not fall back on the server if there isn't a local cache version of this dataset/itemFilters combination
OptionalitemFilters: DatasetItemFilterType[]Asynchronous lookup of a cached entity record name. Returns the cached name if available, or undefined if not cached. Use this for synchronous contexts (like template rendering) where you can't await GetEntityRecordName().
The name of the entity
The primary key value(s) for the record
OptionalloadIfNeeded: booleanIf set to true, will load from database if not already cached
The cached display name, or undefined if not in cache
Returns the stored procedure / function name for a Create or Update operation. Pure metadata lookup — no SQL execution needed. SQL Server uses spCreate/spUpdate naming, PostgreSQL uses the same pattern.
The entity being saved
True for Create, false for Update
The SP/function name
Protected AbstractGetGets the current user information from the provider. Must be implemented by subclasses to return user-specific data.
Current user information including roles and permissions
AbstractGetRetrieves a dataset by name. When forceRefresh is true, bypasses any in-memory or local cache
and fetches directly from the database. When false (default), server-side providers may serve
from LocalCacheManager if TrustLocalCacheCompletely is true.
OptionalitemFilters: DatasetItemFilterType[]OptionalcontextUser: UserInfoOptionalproviderToUse: IMetadataProviderOptionalforceRefresh: booleanWhen true, bypasses all caching and fetches fresh data from the database
Creates a unique key for the given datasetName and itemFilters combination coupled with the instance connection string to ensure uniqueness when 2+ connections exist
OptionalitemFilters: DatasetItemFilterType[]AbstractGetRetrieves the date status information for a dataset and all its items from the server. This method will match the datasetName and itemFilters to the server's dataset and item filters to determine a match
OptionalitemFilters: DatasetItemFilterType[]OptionalcontextUser: UserInfoOptionalproviderToUse: IMetadataProviderProtectedGetReturns AI actions configured for the given entity and timing. Override in subclasses that have access to AIEngine. Default: returns empty array.
Returns a list of entity dependencies, basically metadata that tells you the links to this entity from all other entities.
Creates a new instance of a BaseEntity subclass for the specified entity and automatically calls NewRecord() to initialize it. This method serves as the core implementation for entity instantiation in the MemberJunction framework.
The name of the entity to create (must exist in metadata)
OptionalcontextUser: UserInfoOptional user context for permissions and audit tracking
Promise resolving to the newly created entity instance with NewRecord() called
Creates a new instance of a BaseEntity subclass and loads an existing record using the provided key. This overload provides a convenient way to instantiate and load in a single operation.
The name of the entity to create (must exist in metadata)
CompositeKey containing the primary key value(s) for the record to load
OptionalcontextUser: UserInfoOptional user context for permissions and audit tracking
Promise resolving to the entity instance with the specified record loaded
Gets the display name for a single entity record with caching. Uses the entity's IsNameField or falls back to 'Name' field if available.
The name of the entity
The primary key value(s) for the record
OptionalcontextUser: UserInfoOptional user context for permissions
If true, bypasses cache and queries database
The display name of the record or null if not found
Gets display names for multiple entity records in a single operation with caching. More efficient than multiple GetEntityRecordName calls.
Array of entity/key pairs to lookup
OptionalcontextUser: UserInfoOptional user context for permissions
If true, bypasses cache and queries database for all records
Array of results with names and status for each requested record
ProtectedGetRecursively enumerates an entity's entire sub-tree from metadata. No DB queries — uses EntityInfo.ChildEntities which is populated from metadata.
ProtectedGetRetrieves the latest metadata update timestamps from the server.
OptionalproviderToUse: IMetadataProviderArray of metadata update information
Returns the timestamp of the local cached version of a given datasetName or null if there is no local cache for the specified dataset
the name of the dataset to check
OptionalitemFilters: DatasetItemFilterType[]optional filters to apply to the dataset
Retrieves the change history for a specific record. Uses the vwRecordChanges view which exists in both SQL Server and PostgreSQL.
The entity name
The record's composite primary key
OptionalcontextUser: UserInfoOptional context user
Returns a list of record-level dependencies — records in other entities linked to the specified entity/record via foreign keys (hard links) or EntityIDFieldName soft links. Uses abstract SQL builders for dialect-specific query generation.
The entity name to check
The primary key(s) of the record
OptionalcontextUser: UserInfoOptional context user
Initiates duplicate detection for a list of records. Uses BaseEntity to create a Duplicate Run record. Subclasses may override to provide additional functionality.
The duplicate detection request parameters
OptionalcontextUser: UserInfoThe acting user
A response indicating the duplicate detection status
Gets the favorite record ID if the record is a favorite for the given user, null otherwise.
OptionalcontextUser: UserInfoChecks if a record is marked as a favorite for a given user.
OptionalcontextUser: UserInfoProtectedGetReturns provider-specific extra data to attach to a TransactionItem. SQL Server overrides to include { dataSource: this._pool }.
ProtectedHandleHandles entity actions (non-AI) for save, delete, or validate operations. Override in subclasses that have access to EntityActionEngineServer. Default: no-op, returns empty array.
Array of action results (empty by default)
ProtectedHandleHandles AI-specific entity actions for save or delete operations. Override in subclasses that have access to AIEngine. Default: no-op.
Protected AbstractInternalInternal implementation for spec-based query execution. Subclasses must provide the concrete pipeline (composition → templates → execute).
OptionalcontextUser: UserInfoProtectedInternalRetrieves the display name for a single entity record. Uses BuildEntityRecordNameSQL for dialect-neutral SQL generation.
OptionalcontextUser: UserInfoProtectedInternalRetrieves display names for multiple entity records.
OptionalcontextUser: UserInfoProtectedInternalServer in-process transport for Remote Operations: resolves the registered operation by key
and runs it via ExecuteServer. Inherited by both SQL Server and PostgreSQL providers. The
client (GraphQL) provider overrides this to marshal over the wire instead.
Protected AbstractInternalInternal implementation of RunQueries that subclasses must provide. This method should ONLY contain the batch query execution logic - no pre/post processing. The base class handles all orchestration (telemetry, caching).
Array of query parameters
OptionalcontextUser: UserInfoOptional user context for permissions
Protected AbstractInternalInternal implementation of RunQuery that subclasses must provide. This method should ONLY contain the query execution logic - no pre/post processing. The base class handles all orchestration (telemetry, caching).
The query parameters
OptionalcontextUser: UserInfoOptional user context for permissions
Protected AbstractInternalInternal implementation of RunView that subclasses must provide. This method should ONLY contain the data fetching logic - no pre/post processing. The base class handles all orchestration (telemetry, caching, transformation).
The view parameters
OptionalcontextUser: UserInfoOptional user context for permissions
Protected AbstractInternalInternal implementation of RunViews that subclasses must provide. This method should ONLY contain the batch data fetching logic - no pre/post processing. The base class handles all orchestration (telemetry, caching, transformation).
Array of view parameters
OptionalcontextUser: UserInfoOptional user context for permissions
ProtectedinvalidateDrops every in-flight/lingered RunView entry whose params touch the given entity (lowercased name). Called on BaseEntity save/delete/remote-invalidate.
Determines if a given datasetName/itemFilters combination is cached locally or not
OptionalitemFilters: DatasetItemFilterType[]This routine checks to see if the local cache version of a given datasetName/itemFilters combination is up to date with the server or not
OptionalitemFilters: DatasetItemFilterType[]ProtectedIsChecks whether a given entity matches the target name, or is an ancestor of the target (i.e., the target is somewhere in its descendant sub-tree). Used to identify and skip the active branch during sibling propagation.
ProtectedIsWhether a saved query is bound to an external data source. The base returns false; providers that support external data sources override this (consulting query metadata) so the outer RunQuery CacheLocal layer can defer to InternalRunQuery's own external TTL caching. Synchronous + non-throwing: resolves from cached metadata only.
Checks whether a string value looks like a known database default-value function that is NOT a UUID generator for this provider's platform.
The string value to check
true if the value matches a known non-UUID database function pattern
ProtectedIsChecks whether server-side caching is allowed for the entity in the given RunViewParams. Returns false for entities that have TrustServerCacheCompletely = false, or for Record Changes which is always exempt (rows are created via raw SQL side-effects, not BaseEntity.Save(), so cache invalidation events never fire).
Checks whether a string value looks like a database UUID generation function for this provider's platform.
The string value to check
true if the value matches a known UUID generation function pattern
ProtectedLoadLoads metadata from local storage if available. Deserializes and reconstructs typed metadata objects.
Checks if local metadata is obsolete compared to remote metadata. Compares timestamps and row counts to detect changes.
Optionaltype: stringOptional specific metadata type to check
True if local metadata is out of date
ProtectedLogLogs a record change entry by diffing old/new data and executing provider-specific SQL to insert the record change. Concrete orchestration; SQL generation is delegated to BuildRecordChangeSQL.
The new record data (null for deletes)
The old record data (null for creates)
The entity name
The record ID (CompositeKey string)
The entity metadata
The change type
The acting user
OptionalrestoreContext: RestoreContextProtectedMapProtectedmergeMerges cached and fresh results for RunViews, maintaining original order.
The pre-processing result with cache info
OptionalcachedResults?: RunViewResult[]OptionalcacheStatusMap?: Map<OptionalcallerFieldsMap?: Map<number, string[]>Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.
OptionalfingerprintMap?: Map<number, string>Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.
OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]When CacheLocal is enabled, contains the cache check params to send to server
OptionaltelemetryEventId?: stringOptionaluncachedParams?: RunViewParams[]OptionaluseSmartCacheCheck?: booleanWhen CacheLocal is enabled, indicates we should use smart cache check
The fresh results from InternalRunViews
Combined results in original order
ProtectedmergeMerges cached and fresh results for RunQueries, maintaining original order.
The pre-processing result with cache info
The fresh results from InternalRunQueries
Combined results in original order
Merges multiple records into a single surviving record. Full orchestration: transaction, field map update, dependency re-pointing, deletion, and merge logging.
The merge request with surviving record and records to merge
OptionalcontextUser: UserInfoThe acting user
Optional_options: EntityMergeOptionsOptional merge options
The merge result
ProtectedOnCalled after a successful delete. Intentionally synchronous — see OnAfterSaveExecute.
ProtectedOnCalled after a successful save (both direct and transaction-callback paths). Intentionally synchronous (fire-and-forget) — SQL Server overrides to dispatch after-save entity actions and AI actions without awaiting.
ProtectedOnCalled before the delete SQL is executed. SQL Server overrides to fire before-delete entity actions and AI actions.
ProtectedOnCalled before the save SQL is executed. SQL Server overrides this to fire before-save entity actions and AI actions.
ProtectedOnCalled after a save/delete SQL operation completes (success or failure) to resume refresh.
ProtectedOnCalled after a direct (non-transaction) save succeeds, before the result is returned to the caller and loaded into the entity via finalizeSave().
This hook can optionally return a Record<string, unknown> containing field values
that should be patched onto the SP result row before it is loaded into the entity.
This solves a timing problem: the SP result is captured before OnSaveCompleted runs,
so any data created by post-save hooks (e.g., geocoding writing to a JOINed table)
would be stale in the returned entity without this patch.
result[0] with the current view dataOnSaveCompleted runs post-save logic (geocoding, ISA propagation, etc.)result[0] via Object.assign(), overwriting stale valuesAfter geocoding updates RecordGeoCode, the new lat/lng are returned as patches
for the __mj_Latitude and __mj_Longitude virtual fields that come from the
RecordGeoCode JOIN in the entity's base view. Without this patch, those fields
would contain the pre-geocoding values until the next query.
null if no patches are needed (default behavior)await super.OnSaveCompleted(...) and merge its patches with yoursPatch fields to apply to the SP result, or null if no patches needed
ProtectedOnCalled before starting a save/delete SQL operation to pause background metadata refresh. SQL Server overrides to set _bAllowRefresh = false.
ProtectedOnCalled during Save before any SQL is executed to run validation-type entity actions. Return a non-empty string to abort the save with that message; return null to proceed. SQL Server overrides this to delegate to HandleEntityActions('validate', ...).
ProtectedPostOptionalorganicKeys: OrganicKeyMetadataRow[]OptionalorganicKeyRelatedEntities: OrganicKeyRelatedEntityMetadataRow[]ProtectedPostPost-processes rows returned by a save/load SQL operation. SQL Server overrides to handle datetimeoffset conversion and field decryption. Default: returns rows unchanged.
ProtectedPostBase class post-processor that all sub-classes should call after they finish their RunView process
OptionalcontextUser: UserInfoProtectedPostBase class utilty method that should be called after each sub-class handles its internal RunViews() process before returning results This handles the optional conversion of simple objects to entity objects for each requested view depending on if the params requests a result_type === 'entity_object'
OptionalcontextUser: UserInfoProtectedPostPost-processing hook for RunQueries (batch). Handles telemetry end.
Array of query results
Array of query parameters
The pre-processing result
OptionalcontextUser: UserInfoOptional user context
ProtectedPostPost-processing hook for RunQuery. Handles cache storage and telemetry end.
The query result
The query parameters
The pre-processing result
OptionalcontextUser: UserInfoOptional user context
ProtectedPostPost-processing hook for RunView. Handles result transformation, cache storage, and telemetry end.
The view result
The view parameters
The pre-processing result
OptionalcachedResult?: RunViewResultOptionalcallerRequestedFields?: string[]The caller's original Fields list (lowercased), captured before PreRunView widened params.Fields to all entity fields for cache-superset storage. Non-null ONLY when that widening actually happened — PostRunView uses it to project cache-miss DB results back down to the requested shape.
Optionalfingerprint?: stringOptionaltelemetryEventId?: stringOptionalcontextUser: UserInfoOptional user context
ProtectedPostPost-processing hook for RunViews (batch). Handles result transformation, cache storage, and telemetry end.
Array of view results
Array of view parameters
The pre-processing result
OptionalcachedResults?: RunViewResult[]OptionalcacheStatusMap?: Map<OptionalcallerFieldsMap?: Map<number, string[]>Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.
OptionalfingerprintMap?: Map<number, string>Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.
OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]When CacheLocal is enabled, contains the cache check params to send to server
OptionaltelemetryEventId?: stringOptionaluncachedParams?: RunViewParams[]OptionaluseSmartCacheCheck?: booleanWhen CacheLocal is enabled, indicates we should use smart cache check
OptionalcontextUser: UserInfoOptional user context
ProtectedPreOptionalcontextUser: UserInfoProtectedPreBase class implementation for handling pre-processing of RunViews() each sub-class should call this within their RunViews() method implementation
OptionalcontextUser: UserInfoProtectedPrePre-processing hook for RunQueries (batch). Handles telemetry for batch query operations.
Array of query parameters
OptionalcontextUser: UserInfoOptional user context
Pre-processing result
ProtectedPrePre-processing hook for RunQuery. Handles telemetry and cache lookup.
The query parameters
OptionalcontextUser: UserInfoOptional user context
Pre-processing result with cache status and optional cached result
ProtectedPrePre-processing hook for RunView. Handles telemetry, validation, entity status check, and cache lookup.
The view parameters
OptionalcontextUser: UserInfoOptional user context
Pre-processing result with cache status and optional cached result
ProtectedPrePre-processing hook for RunViews (batch). Handles telemetry, validation, and cache lookup for multiple views.
Array of view parameters
OptionalcontextUser: UserInfoOptional user context
Pre-processing result with cache status for each view
Synchronous pre-validation of cached metadata before engine startup.
On a warm load we serve the metadata graph from IndexedDB so the app can boot without pulling MBs of metadata from the server. Before engines run, this method makes one batched timestamp round-trip to confirm the snapshot is still current:
Cost on the warm-current path is one batched timestamp fetch (~50–200 ms depending on RTT). On the warm-stale path we additionally pay the full metadata fetch but avoid serving stale data to the UI in the first place.
Caller contract: invoke this before StartupManager.Startup().
OptionalproviderToUse: IMetadataProviderProtectedPropagatePropagates record change entries to sibling branches of an IS-A hierarchy. Called after saving an entity with AllowMultipleSubtypes (overlapping subtypes). Collects SQL from BuildSiblingRecordChangeSQL for each sibling and executes as a batch.
The parent entity info
The changes JSON and description
The primary key value
The acting user ID
The child entity that initiated the save (to skip)
OptionalextraExecOptions: Record<string, unknown>Optional provider-specific execution options (e.g. connectionSource for SQL Server transactions)
AbstractQuoteQuotes a database identifier (table, column, view name) using the provider's dialect convention. SQL Server uses [brackets], PostgreSQL uses "double quotes".
The identifier to quote
AbstractQuoteQuotes a schema-qualified object name (e.g. schema.viewName) using the provider's dialect convention. SQL Server uses [schema].[view], PostgreSQL uses "schema"."view".
The schema name
The object name (table, view, etc.)
ProtectedRebuildRebuilds the O(1) entity lookup Maps from the current AllEntities array. Called automatically from UpdateLocalMetadata().
Refreshes all metadata from the server. Respects the AllowRefresh flag from subclasses.
OptionalproviderToUse: IMetadataProviderTrue if refresh was initiated or allowed
Refreshes metadata only if needed based on timestamp comparison. Combines check and refresh into a single operation.
OptionalproviderToUse: IMetadataProviderTrue if refresh was successful or not needed
Refreshes the remote metadata timestamps from the server. Updates the internal cache of remote timestamps.
OptionalproviderToUse: IMetadataProviderTrue if timestamps were successfully refreshed
Removes all cached metadata from local storage. Clears both timestamps and metadata collections.
ProtectedResolveResolves any PlatformSQL values in RunViewParams to plain strings for the active platform. Mutates the params object in place so downstream InternalRunView implementations always receive plain string values for ExtraFilter and OrderBy.
ProtectedResolveThe RunQuery cache-serve seam (B45/B46) — resolves a RunQuery request against this provider's query metadata and answers, in ONE computation performed BEFORE fingerprinting:
categoryPath: the RESOLVED query's canonical full category path. This becomes a
distinguishing fingerprint segment (B46) so two same-named queries in different
categories can never collide onto one cache slot. When the request is unresolvable the
caller falls back to the CALLER-STATED params.CategoryPath (still distinguishing,
just not canonicalized).resolvable: whether metadata could resolve the request at all. Runtime-created
queries are typically NOT resolvable from the base metadata cache (it does not refresh
in-process) — the gate then applies the warmer tie-break instead.authorized: whether user may run the resolved query. Meaningful only when
resolvable is true.The BASE implementation resolves from the metadata Queries cache and enforces the
ROLES-ONLY QueryInfo.UserCanRun — the strongest check available at this layer.
Providers with richer query metadata MUST override this to enforce the SAME authorization
their miss path enforces (GenericDatabaseProvider overrides with
MJQueryEntityExtended.UserCanRun, which adds entity CanRead + recursive composition
checks — the exact check ValidateQueryForExecution applies on a cache miss). The
invariant this seam exists to hold: a cache HIT must never be easier to read than a
cache MISS (B45 was precisely that asymmetry — the TTL gate checked roles only while
the miss path also checked entity read permissions).
Optionaluser: UserInfoResolves a PlatformSQL value to the appropriate SQL string for this provider's platform. If the value is a plain string, it is returned as-is (backward compatible). If the value is a PlatformSQL object, the platform-specific variant is used if available, otherwise the default variant is used.
AbstractRollbackRolls back the current transaction.
Routes a typed Remote Operation by key to its implementation (see IRemoteOperationProvider).
This is the public power-tool transport seam. Prefer the typed
BaseRemotableOperation.Execute() entry point in application code — RouteOperation is the
stringly-typed escape hatch for dynamic dispatch / generic tooling, not for building
significant systems. Server providers override InternalRouteOperation to execute the
operation in-process; the client (GraphQL) provider overrides it to marshal over the wire.
Only registered, active (and, when AI-authored, approved) operations are routable, and every
call is authorized on the server side.
Stable registry key of the operation (e.g. RecordProcess.RunNow).
The operation's typed input payload.
Optionaloptions: RemoteOpInvokeOptionsOptional invocation options (mode, progress callback, user, provider, fingerprint).
The operation result; never throws for logical failures — check Success/ErrorMessage.
ProtectedRunRuns all registered PostRunView hooks against a single result, returning the (possibly mutated) result.
Protected (not private) for the same reason as RunPreRunViewHooks above: a subclass pipeline that returns view rows WITHOUT passing through PostRunView/PostRunViews — e.g. the RunViewsWithCacheCheck smart-cache path — MUST apply these hooks to the rows it returns. PostRunView is the OUTPUT half of the enforcement seam (data masking / audit); a path that skips it returns rows the hooked paths would have masked.
OptionalcontextUser: UserInfoProtectedRunRuns all registered PreRunView hooks against a single RunViewParams, returning the (possibly mutated) params.
Protected (not private) on purpose: any subclass pipeline that executes view queries WITHOUT passing through PreRunView/PreRunViews — e.g. the RunViewsWithCacheCheck smart-cache path in GenericDatabaseProvider — MUST apply these hooks itself. Hooks are an enforcement seam (tenant scoping middleware injects filters here); a query path that skips them silently returns rows the hooked paths would have filtered out.
OptionalcontextUser: UserInfoRuns multiple queries based on the provided parameters. This method orchestrates the full execution flow for batch query operations.
Array of query parameters
OptionalcontextUser: UserInfoOptional user context for permissions (required server-side)
Array of query results
OptionalcontextUser: UserInfoRuns a report by looking up its SQL definition from vwReports and executing it. Both SQL Server and PostgreSQL share this logic — the only dialect difference is identifier quoting, handled by QuoteIdentifier/QuoteSchemaAndView.
Report parameters including ReportID
OptionalcontextUser: UserInfoOptional context user for permission/audit purposes
Runs a view based on the provided parameters. This method orchestrates the full execution flow: pre-processing, cache check, internal execution, post-processing, and cache storage.
The view parameters
OptionalcontextUser: UserInfoOptional user context for permissions (required server-side)
The view results
ProtectedrunSingle source of truth for whether a RunView call participates in the local cache (both READ and WRITE). Pre/Post hooks for the singular and batch paths must all use this predicate — historically each site recomputed it inline and they drifted (PostRunViews wrote BypassCache results into the cache, poisoning the Fields-agnostic superset slot with narrow rows).
Ineligible:
BypassCache — caller explicitly wants true DB state, no cache interactionAfterKey — keyset pages are single-use AND the fingerprint doesn't include
the seek key, so caching a page would poison the entity+filter slotResultType 'count_only' — returns no rows; caching its empty Results under
a fingerprint that excludes ResultType would poison row queriesRuns multiple views based on the provided parameters. Wraps the execution pipeline with request deduplication and a linger window so that concurrent (and near-sequential) identical calls share a single server round-trip. Every caller receives a shallow-copied Results array to protect against cross-caller mutations (push/sort/splice).
Array of view parameters
OptionalcontextUser: UserInfoOptional user context for permissions (required server-side)
Array of view results (shallow-copied Results per caller)
Saves an entity record — the full orchestration flow shared by all DB providers.
Saves current metadata to local storage for caching. Serializes both timestamps and full metadata collections.
Batch form of SearchEntity. Fans the input list out to N
independent SearchEntity calls via Promise.all; result arrays come
back aligned by input order (result[i] holds the matches for params[i]).
On the server side, the per-entity passes are independent — running them
concurrently is a real wall-clock win when the caller wants results from
multiple entities. On the client side, GraphQLDataProvider overrides
this method to pack the whole batch into a single GraphQL round-trip
instead of issuing N parallel HTTP requests.
See IMetadataProvider.SearchEntities for the contract.
Protected AbstractsearchRun the semantic ranking pass for SearchEntity. Each concrete
ProviderBase subclass supplies its own implementation: server-side
providers (GenericDatabaseProvider) embed the query text and query
an in-process vector pool directly; client-side providers
(GraphQLDataProvider) override SearchEntity / SearchEntities
outright to proxy via GraphQL and never reach this method.
Ranked array of ScoredCandidate whose ID is the parent
entity's record ID and Metadata.entityRecordDocumentId
carries the EntityRecordDocument PK.
Ranked search over one entity's records. See IMetadataProvider.SearchEntity for the contract and how this differs from EntityByName / FullTextSearch.
Implementation overview (concrete on ProviderBase, used as-is by every
server-side provider; GraphQLDataProvider overrides to proxy via GQL):
params.options.entityDocumentId
override or by looking up the active Search-category doc for the entity).IncludeInUserSearchAPI fields) and the semantic
pass (searchEntitiesSemanticPass, the protected template method
each concrete server provider implements).ComputeRRF() with optional per-list weights.Stores a record name in the cache for later synchronous retrieval via GetCachedRecordName(). Called automatically by BaseEntity after Load(), LoadFromData(), and Save() operations.
The name of the entity
The primary key value(s) for the record
The display name to cache
Creates or deletes a user favorite record for the specified entity record. Uses GetEntityObject and BaseEntity CRUD methods (no entity-specific type imports needed).
ProtectedshouldProtectedShouldDialect-agnostic predicate: should we write a RecordChange entry for this entity? Excludes the Record Changes entity itself to prevent recursion. Provider implementations should call this before invoking BuildRecordChangePayload or constructing dialect SQL.
ProtectedStartCreates the initial merge log record at the start of a merge operation. Uses BaseEntity with .Set() calls (no typed entity subclass imports available in MJCore).
OptionalcontextUser: UserInfoProtectedTransformTransforms the result set from simple objects to entity objects if needed.
The RunViewParams used for the request
The RunViewResult returned from the request
OptionalcontextUser: UserInfoThe user context for permissions
ProtectedTrimTruncates a string value to a maximum length, appending trailing characters if truncated.
ProtectedUpdateUpdates the local metadata cache with new data.
The new metadata to store locally
ProtectedValidateValidates the result of a delete SQL execution by checking that the returned primary keys match the entity being deleted. SQL Server overrides to handle the multi-result-set case (CASCADE deletes).
ProtectedValidateValidates a user-provided SQL clause (WHERE, ORDER BY, etc.) to prevent SQL injection. Checks for forbidden keywords (INSERT, UPDATE, DELETE, EXEC, DROP, UNION, etc.) and dangerous patterns (comments, semicolons, xp_ prefix). String literals are stripped before validation to avoid false positives.
The SQL clause to validate
true if the clause is safe, false if it contains forbidden patterns
Protected StaticarrayConverts an ArrayBuffer to a base64-encoded string. Used for compressed metadata storage/retrieval.
Protected Staticbase64Converts a base64-encoded string to an ArrayBuffer. Used for compressed metadata storage/retrieval.
StaticIsStatic convenience: checks all platforms' default-value functions. Prefer the instance method when you have a provider reference.
StaticIsStatic convenience: checks all platforms' UUID generation functions. Prefer the instance method when you have a provider reference.
Protected StaticUnionReturns the caller's requested fields (lowercased) unioned with the entity's
primary key field names. Platform contract: when Fields is explicitly
specified, results ALWAYS include the primary key(s) — the direct SQL path has
always done this, differential smart-cache merges require it, and entity
linking in UIs depends on it. Applying the same union at every projection site
keeps result shapes identical across cached, non-cached, and smart-cache paths.
This class is a generic server-side provider class to abstract database operations on any database system and therefore be usable by server-side components that need to do database operations but do not want close coupling with a specific database provider like
See
@memberjunction/sqlserver-dataprovider
It contains DB-agnostic business logic (record change tracking, favorites, ISA hierarchy, record dependencies, diffing, etc.) that is shared across all database providers. Subclasses implement abstract methods for DB-specific SQL dialect generation.