Member Junction
    Preparing search index...

    Class DatabaseProviderBaseAbstract

    This class is a generic server-side provider class to abstract database operations on any database system and therefore be usable by server-side components that need to do database operations but do not want close coupling with a specific database provider like

    @memberjunction/sqlserver-dataprovider

    It contains DB-agnostic business logic (record change tracking, favorites, ISA hierarchy, record dependencies, diffing, etc.) that is shared across all database providers. Subclasses implement abstract methods for DB-specific SQL dialect generation.

    Hierarchy (View Summary)

    Index

    Constructors

    Properties

    Accessors

    Methods

    backgroundValidateAndRefresh BeginTransaction BuildAggregateSQL BuildChildDiscoverySQL BuildDatasetFilterFromConfig BuildDeleteExecuteOptions BuildEntityRecordNameSQL BuildHardLinkDependencySQL BuildParameterPlaceholder BuildRecordChangePayload BuildRecordChangeSQL BuildSaveExecuteOptions BuildSiblingRecordChangeSQL BuildSoftLinkDependencySQL CacheDataset cacheDeniedForViewOnlyRequest CheckCreateRLS CheckRecordRLS CheckToSeeIfRefreshNeeded CheckUserReadPermissions ClearDatasetCache CloneAllMetadata CommitTransaction CompleteMergeLogging ComputeRunViewRLSWhereClause Config ConvertItemFiltersToUniqueKey CopyMetadataFromGlobalProvider CreateAuditLogRecord CreateSharedMetadataShell CreateTransactionGroup CreateUserDescriptionOfChanges Delete DiffObjects EntityByID EntityByName EntityStatusCheck EscapeQuotesInProperties ExecuteAggregateQuery ExecuteQueryFromSpec ExecuteSQL extractMaxUpdatedAt FindISAChildEntities FindISAChildEntity FullTextSearch GenerateDeleteSQL GenerateNewID GenerateSaveSQL GetAllMetadata GetAndCacheDatasetByName GetCachedDataset GetCachedRecordName GetCreateUpdateSPName GetCurrentUser GetDatasetByName GetDatasetCacheKey GetDatasetStatusByName GetEntityAIActions GetEntityDependencies GetEntityObject GetEntityRecordName GetEntityRecordNames GetFullSubTree GetLatestMetadataUpdates GetLocalDatasetTimestamp GetRecordChanges GetRecordDependencies GetRecordDuplicates GetRecordFavoriteID GetRecordFavoriteStatus GetTransactionExtraData HandleEntityActions HandleEntityAIActions InternalExecuteQueryFromSpec InternalGetEntityRecordName InternalGetEntityRecordNames InternalRouteOperation InternalRunQueries InternalRunQuery InternalRunView InternalRunViews invalidateInflightViewsForEntity IsDatasetCached IsDatasetCacheUpToDate IsEntityOrAncestorOf IsExternalQuery IsNonUUIDDatabaseFunction IsServerCacheAllowedForEntity IsUUIDGenerationFunction LoadLocalMetadataFromStorage LocalMetadataObsolete LogRecordChange MapTransactionResultToNewValues mergeCachedAndFreshResults mergeQueryCachedAndFreshResults MergeRecords OnAfterDeleteExecute OnAfterSaveExecute OnBeforeDeleteExecute OnBeforeSaveExecute OnResumeRefresh OnSaveCompleted OnSuspendRefresh OnValidateBeforeSave PostProcessEntityMetadata PostProcessRows PostProcessRunView PostProcessRunViews PostRunQueries PostRunQuery PostRunView PostRunViews PreProcessRunView PreProcessRunViews PreRunQueries PreRunQuery PreRunView PreRunViews preValidateAndRefresh PropagateRecordChangesToSiblings QuoteIdentifier QuoteSchemaAndView RebuildEntityMaps Refresh RefreshIfNeeded RefreshRemoteMetadataTimestamps RemoveLocalMetadataFromStorage ResolvePlatformSQLInParams ResolveQueryCacheAuthorization ResolveSQL RollbackTransaction RouteOperation RunPostRunViewHooks RunPreRunViewHooks RunQueries RunQuery RunReport RunView runViewCacheEligible RunViews Save SaveLocalMetadataToStorage SearchEntities searchEntitiesSemanticPass SearchEntity SetCachedRecordName SetRecordFavoriteStatus shouldAutoCache ShouldTrackRecordChanges StartMergeLogging TransformSimpleObjectToEntityObject TrimString UpdateLocalMetadata ValidateDeleteResult ValidateUserProvidedSQLClause arrayBufferToBase64 base64ToArrayBuffer IsNonUUIDDatabaseFunctionAllPlatforms IsUUIDGenerationFunctionAllPlatforms UnionFieldsWithPrimaryKeys

    Constructors

    Properties

    _preRunQueriesResultType: {
        allCached: boolean;
        cachedResults?: RunQueryResult[];
        cacheStatusMap?: Map<
            number,
            {
                result?: RunQueryResult;
                status: "disabled"
                | "hit"
                | "miss"
                | "expired";
            },
        >;
        telemetryEventId?: string;
        uncachedParams?: RunQueryParams[];
    }

    Result from PreRunQueries hook containing cache status for batch operations

    _preRunQueryResultType: {
        cachedResult?: RunQueryResult;
        cacheStatus: "disabled" | "hit" | "miss" | "expired";
        fingerprint?: string;
        telemetryEventId?: string;
    }

    Result from PreRunQuery hook containing cache status and optional cached result

    _preRunViewResultType: {
        cachedResult?: RunViewResult;
        cacheStatus: "disabled" | "hit" | "miss" | "expired";
        callerRequestedFields?: string[];
        fingerprint?: string;
        telemetryEventId?: string;
    }

    Result from PreRunView hook containing cache status and optional cached result

    Type Declaration

    • OptionalcachedResult?: RunViewResult
    • cacheStatus: "disabled" | "hit" | "miss" | "expired"
    • OptionalcallerRequestedFields?: string[]

      The caller's original Fields list (lowercased), captured before PreRunView widened params.Fields to all entity fields for cache-superset storage. Non-null ONLY when that widening actually happened — PostRunView uses it to project cache-miss DB results back down to the requested shape.

    • Optionalfingerprint?: string
    • OptionaltelemetryEventId?: string
    _preRunViewsResultType: {
        allCached: boolean;
        cachedResults?: RunViewResult[];
        cacheStatusMap?: Map<
            number,
            {
                result?: RunViewResult;
                status: "disabled"
                | "hit"
                | "miss"
                | "expired";
            },
        >;
        callerFieldsMap?: Map<number, string[]>;
        fingerprintMap?: Map<number, string>;
        smartCacheCheckParams?: RunViewWithCacheCheckParams[];
        telemetryEventId?: string;
        uncachedParams?: RunViewParams[];
        useSmartCacheCheck?: boolean;
    }

    Result from PreRunViews hook containing cache status for batch operations

    Type Declaration

    • allCached: boolean
    • OptionalcachedResults?: RunViewResult[]
    • OptionalcacheStatusMap?: Map<
          number,
          { result?: RunViewResult; status: "disabled"
          | "hit"
          | "miss"
          | "expired" },
      >
    • OptionalcallerFieldsMap?: Map<number, string[]>

      Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.

    • OptionalfingerprintMap?: Map<number, string>

      Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.

    • OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]

      When CacheLocal is enabled, contains the cache check params to send to server

    • OptionaltelemetryEventId?: string
    • OptionaluncachedParams?: RunViewParams[]
    • OptionaluseSmartCacheCheck?: boolean

      When CacheLocal is enabled, indicates we should use smart cache check

    _mjMetadataDatasetName: string = 'MJ_Metadata'
    CoalesceWindowMs: number = 10

    When enabled, concurrent RunViews calls arriving within the same microtask (or within CoalesceWindowMs) are merged into a single mega-batch before hitting the network. This dramatically reduces the number of HTTP round-trips during startup when multiple engines independently call RunViews in parallel.

    Set to 0 to disable coalescing. Default 10ms — enough to capture all engines that fire in the same tick, without adding perceptible delay.

    DedupLingerMs: number = 5000

    How long (ms) a resolved RunViews result stays available for instant replay. Set to 0 to disable the linger window (in-flight dedup still applies). Default 5 000 ms.

    MaxLingerEntries: number = 500

    Safety cap on the number of linger entries held simultaneously. The linger window is a latency optimization — under extreme churn (more distinct query keys than this resolving within one window) new resolutions skip lingering instead of accumulating result arrays in memory.

    MinRefreshCheckIntervalMs: number = 30000

    Minimum interval (ms) between metadata refresh checks to prevent redundant network calls when Config()/RefreshIfNeeded() fire in quick succession (e.g., multiple engines during startup). Does NOT affect forced Refresh() calls. Default: 30 000 ms.

    ServerAutoCacheMaxRows: number = 250

    Maximum row count for auto-caching on the server side. When TrustLocalCacheCompletely is true and a RunView result has no ExtraFilter, no OrderBy, and the result count is at or below this threshold, the result is automatically stored in LocalCacheManager even without an explicit CacheLocal flag.

    This captures small reference/lookup tables that are repeatedly queried by multiple clients while avoiding caching large ad-hoc result sets. Invalidation is handled by the standard BaseEntity event-driven upsert (safe because unfiltered caches can be updated in-place).

    Set to 0 to disable auto-caching. Default 250.

    Accessors

    • get AllowRefresh(): boolean

      Determines if a refresh is currently allowed or not. Subclasses should return FALSE if they are performing operations that should prevent refreshes. This helps avoid metadata refreshes during critical operations.

      Returns boolean

    • get DatabaseConnection(): any

      For providers that have ProviderType==='Database', this property will return an object that represents the underlying database connection. For providers where ProviderType==='Network' this property will throw an exception. The type of object returned is provider-specific (e.g., SQL connection pool).

      Returns any

    • get DBDefaultFunctionPattern(): RegExp

      Regex pattern matching known database default-value functions (non-UUID) for this provider's platform. SQL Server should match GETDATE, GETUTCDATE, SYSDATETIME, etc. PostgreSQL should match NOW, CURRENT_TIMESTAMP, clock_timestamp, etc. Case-insensitive, should match the full string with optional whitespace and parens.

      Returns RegExp

    • get Dialect(): SQLDialect

      The SQLDialect instance matching this provider's PlatformKey.

      Use this whenever runtime code needs to emit dialect-specific SQL (boolean literals, identifier quoting, casts, …) — it spares callers from doing GetDialect(provider.PlatformKey) every time, and keeps dialect resolution in one place. Resolves lazily and is cached so repeated access is free.

      Example:

      const lit = provider.Dialect.BooleanLiteral(true); // '1' on SS, 'TRUE' on PG
      

      Returns SQLDialect

    • get InstanceConnectionString(): string

      This property is implemented by each sub-class of ProviderBase and is intended to return a unique string that identifies the instance of the provider for the connection it is making. For example: for network connections, the URL including a TCP port would be a good connection string, whereas on database connections the database host url/instance/port would be a good connection string. This is used as part of cache keys to ensure different connections don't share cached data.

      Returns string

    • get IsInTransaction(): boolean

      Whether this provider currently has an active transaction. Subclasses that track transaction state should override this. Used by callers (e.g. runMaybeSerial) to decide whether to fan out concurrent saves or run them sequentially. Defaults to false for providers that don't expose this state.

      Returns boolean

    • get LocalStoragePrefix(): string

      This property will return the prefix to use for local storage keys. This is useful if you have multiple instances of a provider running in the same environment and you want to keep their local storage keys separate. The default implementation returns an empty string, but subclasses can override this to return a unique string based on the connection or other distinct identifier.

      Returns string

    • get MJCoreSchemaName(): string

      Gets the MemberJunction core schema name (e.g. '__mj'). Subclasses should override if they have a different way to resolve this. Defaults to the value from ConfigData.

      Returns string

    • get PreRunQueriesResult(): {
          allCached: boolean;
          cachedResults?: RunQueryResult[];
          cacheStatusMap?: Map<
              number,
              {
                  result?: RunQueryResult;
                  status: "disabled"
                  | "hit"
                  | "miss"
                  | "expired";
              },
          >;
          telemetryEventId?: string;
          uncachedParams?: RunQueryParams[];
      }

      Returns {
          allCached: boolean;
          cachedResults?: RunQueryResult[];
          cacheStatusMap?: Map<
              number,
              {
                  result?: RunQueryResult;
                  status: "disabled"
                  | "hit"
                  | "miss"
                  | "expired";
              },
          >;
          telemetryEventId?: string;
          uncachedParams?: RunQueryParams[];
      }

    • get PreRunQueryResult(): {
          cachedResult?: RunQueryResult;
          cacheStatus: "disabled"
          | "hit"
          | "miss"
          | "expired";
          fingerprint?: string;
          telemetryEventId?: string;
      }

      Returns {
          cachedResult?: RunQueryResult;
          cacheStatus: "disabled" | "hit" | "miss" | "expired";
          fingerprint?: string;
          telemetryEventId?: string;
      }

    • get PreRunViewResult(): {
          cachedResult?: RunViewResult;
          cacheStatus: "disabled"
          | "hit"
          | "miss"
          | "expired";
          callerRequestedFields?: string[];
          fingerprint?: string;
          telemetryEventId?: string;
      }

      Returns {
          cachedResult?: RunViewResult;
          cacheStatus: "disabled" | "hit" | "miss" | "expired";
          callerRequestedFields?: string[];
          fingerprint?: string;
          telemetryEventId?: string;
      }

      • OptionalcachedResult?: RunViewResult
      • cacheStatus: "disabled" | "hit" | "miss" | "expired"
      • OptionalcallerRequestedFields?: string[]

        The caller's original Fields list (lowercased), captured before PreRunView widened params.Fields to all entity fields for cache-superset storage. Non-null ONLY when that widening actually happened — PostRunView uses it to project cache-miss DB results back down to the requested shape.

      • Optionalfingerprint?: string
      • OptionaltelemetryEventId?: string
    • get PreRunViewsResult(): {
          allCached: boolean;
          cachedResults?: RunViewResult[];
          cacheStatusMap?: Map<
              number,
              {
                  result?: RunViewResult;
                  status: "disabled"
                  | "hit"
                  | "miss"
                  | "expired";
              },
          >;
          callerFieldsMap?: Map<number, string[]>;
          fingerprintMap?: Map<number, string>;
          smartCacheCheckParams?: RunViewWithCacheCheckParams[];
          telemetryEventId?: string;
          uncachedParams?: RunViewParams[];
          useSmartCacheCheck?: boolean;
      }

      Returns {
          allCached: boolean;
          cachedResults?: RunViewResult[];
          cacheStatusMap?: Map<
              number,
              {
                  result?: RunViewResult;
                  status: "disabled"
                  | "hit"
                  | "miss"
                  | "expired";
              },
          >;
          callerFieldsMap?: Map<number, string[]>;
          fingerprintMap?: Map<number, string>;
          smartCacheCheckParams?: RunViewWithCacheCheckParams[];
          telemetryEventId?: string;
          uncachedParams?: RunViewParams[];
          useSmartCacheCheck?: boolean;
      }

      • allCached: boolean
      • OptionalcachedResults?: RunViewResult[]
      • OptionalcacheStatusMap?: Map<
            number,
            { result?: RunViewResult; status: "disabled"
            | "hit"
            | "miss"
            | "expired" },
        >
      • OptionalcallerFieldsMap?: Map<number, string[]>

        Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.

      • OptionalfingerprintMap?: Map<number, string>

        Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.

      • OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]

        When CacheLocal is enabled, contains the cache check params to send to server

      • OptionaltelemetryEventId?: string
      • OptionaluncachedParams?: RunViewParams[]
      • OptionaluseSmartCacheCheck?: boolean

        When CacheLocal is enabled, indicates we should use smart cache check

    • get TrustLocalCacheCompletely(): boolean

      Server-side providers trust the local cache completely because it is kept in perfect sync via BaseEntity save/delete events and cross-server Redis pub/sub. No lightweight DB validation needed on cache hits.

      Returns boolean

    • get UUIDFunctionPattern(): RegExp

      Regex pattern matching known database UUID/ID generation functions for this provider's platform. SQL Server should match NEWID, NEWSEQUENTIALID. PostgreSQL should match gen_random_uuid, uuid_generate_v4. Case-insensitive, should match the full string with optional whitespace and parens.

      Returns RegExp

    Methods

    • Builds and validates an aggregate SQL query from the provided aggregate expressions. Uses SQLExpressionValidator from @memberjunction/global for injection prevention. Uses QuoteIdentifier/QuoteSchemaAndView for dialect-neutral SQL generation.

      Parameters

      • aggregates: { alias?: string; expression: string }[]

        Array of aggregate expressions to validate and build

      • entityInfo: EntityInfo

        Entity metadata for field reference validation

      • schemaName: string

        Schema name for the entity

      • baseView: string

        Base view name for the entity

      • whereSQL: string

        WHERE clause to apply (without the WHERE keyword)

      Returns { aggregateSQL: string; validationErrors: AggregateResult[] }

      Object with aggregateSQL string and any validation errors

    • Builds a UNION ALL query that checks each child entity's base table for a record with the given primary key. Used by FindISAChildEntity/FindISAChildEntities.

      Parameters

      • childEntities: EntityInfo[]

        The child entities to search

      • recordPKValue: string

        The primary key value to find

      Returns string

    • Builds the SQL to retrieve the "name" field value for a specific entity record. Uses QuoteIdentifier/QuoteSchemaAndView for dialect-neutral SQL generation.

      Parameters

      • entityName: string

        The entity name

      • compositeKey: CompositeKey

        The record's primary key

      Returns string

      The SQL query string, or null if the entity has no name field

    • Builds a parameter placeholder for parameterized queries. Default: PG-style ($1, $2, ...). SQL Server overrides to @p0, @p1, etc.

      Parameters

      • index: number

        Zero-based parameter index

      Returns string

    • Builds the dialect-agnostic payload for a RecordChange row from the entity's old/new data and an optional restore context. Concrete providers consume the returned payload to render their dialect-specific SQL (SQL Server EXEC, PostgreSQL INSERT, etc.).

      Returns null when there's nothing to log — i.e., an Update where DiffObjects found no field-level changes. Creates and Deletes are always logged (one side of oldData/newData is null).

      The payload's recordID is whatever the caller passes in. PG's inline CTE save/delete paths can pass an empty string and resolve the actual RecordID expression in SQL (because the post-INSERT PK isn't known in JS); the standalone BuildRecordChangeSQL path passes a fully-resolved composite-key string.

      Parameters

      • newData: Record<string, unknown>

        Post-change data (null for deletes).

      • oldData: Record<string, unknown>

        Pre-change data (null for creates).

      • recordID: string

        Composite-key serialized RecordID, or empty for CTE callers.

      • entityInfo: EntityInfo

        Entity metadata (provides EntityID + field shapes for diff).

      • type: "Create" | "Update" | "Delete"

        Change type. Create and Delete skip the change-key short-circuit.

      • user: UserInfo

        Acting user (provides UserID).

      • OptionalrestoreContext: RestoreContext

        When non-null, populates source='Restore' plus the lineage columns; otherwise source='Internal'.

      • quoteToEscape: string = "'"

        Quote character for EscapeQuotesInProperties and DiffObjects. Defaults to single quote.

      Returns RecordChangePayload

    • Builds the SQL (and optional parameters) for inserting a record change entry. Each provider generates its own dialect: SQL Server uses EXEC spCreateRecordChange_Internal, PostgreSQL uses INSERT INTO "RecordChange" with parameterized values.

      Returns null if there are no changes to log.

      Implementations should delegate the dialect-agnostic assembly work to BuildRecordChangePayload and only handle SQL string rendering locally — that's how the duplication between SQL Server and PostgreSQL stays minimal.

      Parameters

      • newData: Record<string, unknown>
      • oldData: Record<string, unknown>
      • entityName: string
      • recordID: string
      • entityInfo: EntityInfo
      • type: "Create" | "Update" | "Delete"
      • user: UserInfo
      • OptionalrestoreContext: RestoreContext

        When non-null, the resulting RecordChange row is written with Source='Restore', RestoredFromID = SourceChangeID, and RestoreReason = Reason. Read by callers from BaseEntity.RestoreContext immediately before generating SQL.

      Returns { parameters?: unknown[]; sql: string }

    • Builds the SQL for a single sibling entity's record change entry in the propagation batch. SQL Server uses FOR JSON PATH + spCreateRecordChange_Internal. PostgreSQL uses json_build_object + INSERT INTO "RecordChange".

      Parameters

      • varName: string
      • entityInfo: EntityInfo
      • safeChangesJSON: string
      • safeChangesDesc: string
      • safePKValue: string
      • safeUserId: string

      Returns string

    • Builds SQL for soft-link dependency queries (entities using EntityIDFieldName pattern). Returns a UNION ALL query across all soft-linked entities.

      Parameters

      • entityName: string

        The entity name being checked for dependencies

      • compositeKey: CompositeKey

        The primary key of the record

      Returns string

    • SECURITY — decide whether the shared cache must be BYPASSED for a RunView that targets a saved VIEW rather than a named entity (no EntityName), under a context user.

      The cache-hit path returns BEFORE the DB provider's read-permission gate (CheckUserReadPermissions). The primary gate keys off the entity resolved from params.EntityName, so a ViewID-/ViewName-only request (the Explorer-standard shape for a saved view) yields no entity there and the gate is disarmed — a read-denied user could be served rows a permitted user warmed for the same ViewID. The vw: fingerprint segment makes the two users' requests collide on exactly one slot, so the leak is clean.

      Returns true when the cache must be skipped for this call (fail-closed):

      • ViewEntity supplied and its entity resolves → apply the normal CanRead gate on it (allow caching for a permitted user; deny for a read-denied one).
      • ViewEntity absent/unresolvable but ViewID/ViewName present → fail closed: the view's real entity (hence the user's permission) is only known after the async MJ: User Views lookup that the cache-hit path deliberately skips, so we cannot safely consult the cache. Returns false when there is no context user, when EntityName is set (the normal gate owns that path), or when no view identifier is present at all (nothing to gate).

      Parameters

      Returns boolean

    • Checks that the given user has read permissions on the specified entity. Throws if the user lacks CanRead permission.

      Parameters

      • entityName: string

        The entity to check permissions for

      • contextUser: UserInfo

        The user whose permissions to check

      Returns void

      Error if contextUser is null, entity is not found, or user lacks read permission

    • Computes the per-user Row-Level-Security WHERE clause that InternalRunView will append to this query's SQL for the given user, so it can be folded into the cache fingerprint. RLS-scoped reads return a different result set than unscoped reads of the same entity+filter; without including the RLS clause in the cache key, a scoped user could be served a cached unscoped result set (a data leak).

      Returns '' when the user is exempt from RLS on this entity (the common case), which makes the resulting fingerprint byte-identical to the pre-RLS format — preserving normal cache sharing.

      Uses this (the active provider) to resolve the entity, never the global Metadata, so the correct per-provider/per-tenant metadata is consulted.

      Parameters

      Returns string

    • Creates an audit log record in the MJ: Audit Logs entity. Uses BaseEntity with .Set() calls (no typed entity subclass imports needed - can't use those from MJCore anyway). Callers typically fire-and-forget.

      Parameters

      • user: UserInfo

        The user performing the action

      • authorizationName: string

        Optional authorization name to look up

      • auditLogTypeName: string

        The audit log type name (must exist in metadata)

      • status: string

        'Success' or 'Failed'

      • details: string

        Optional details (JSON string, description, etc.)

      • entityId: string

        The entity ID being audited

      • recordId: string

        Optional record ID being audited

      • auditLogDescription: string

        Optional description for the audit log

      • saveOptions: EntitySaveOptions

        Save options to pass to the entity Save() call

      Returns Promise<BaseEntity<unknown>>

      The saved audit log BaseEntity, or null on error

    • Builds this instance's AllMetadata as a thin shell over another provider's already-loaded metadata: every metadata array is a PER-INSTANCE shallow copy whose elements are the SHARED Info object instances, and CurrentUser remains this instance's own.

      Why sharing the instances is safe — and why this replaced the former deep clone (CloneAllMetadata) on the reuse-global fast path: the metadata graph is immutable after Config. Refreshes swap the WHOLE AllMetadata object (UpdateLocalMetadata), never mutate the Info objects in place, so the only per-instance datum inside the graph is CurrentUser — which this shell keeps independent. The deep clone cost ~1s of event-loop-blocking constructor work per provider on every server request (MemberJunction/MJ#3083); the shell is ~20 array-of-pointer copies (microseconds).

      Why the array containers are copied rather than aliased: an in-place .sort()/.push()/.splice() by request-scoped code then stays local to that provider — matching the clone era's isolation for the common accidental mutation class — instead of reordering the global graph for every other in-flight request. Only the top-level AllMetadata collections get this per-instance protection: everything below them is shared, including the nested arrays owned by Info objects (entity.Fields, entity.RelatedEntities, application.ApplicationEntities, ...) — an in-place mutation of those is process-wide. Property writes on the shared Info objects themselves are likewise visible process-wide (as they always were on the client's global provider): treat Info objects and everything they own as read-only; copy before sorting.

      Override precedence: if a subclass overrides BOTH this method and the deprecated CloneAllMetadata, the CloneAllMetadata override wins on the fast path (see CopyMetadataFromGlobalProvider) — the conservative back-compat choice, since pre-#3083 subclasses could only have customized adoption through CloneAllMetadata. Remove the CloneAllMetadata override to activate a CreateSharedMetadataShell override.

      Parameters

      Returns AllMetadata

    • Converts a diff/changes object into a human-readable description of what changed.

      Parameters

      • changesObject: Record<string, FieldChange>

        The output of DiffObjects()

      • maxValueLength: number = 200

        Maximum length for displayed values before truncation

      • cutOffText: string = '...'

        Text to append when values are truncated

      Returns string

    • Creates a changes object by comparing two JavaScript objects, identifying fields that have different values. Each property in the returned object represents a changed field, with the field name as the key.

      Parameters

      • oldData: Record<string, unknown>

        The original data object to compare from

      • newData: Record<string, unknown>

        The new data object to compare to

      • entityInfo: EntityInfo

        Entity metadata used to validate fields and determine comparison logic

      • quoteToEscape: string

        The quote character to escape in string values (typically "'")

      Returns Record<string, FieldChange>

      A Record mapping field names to FieldChange objects, or null if either input is null/undefined. Only includes fields that have actually changed and are not read-only.

    • Recursively escapes the specified quote character in all string properties of an object or array. Essential for preparing data to be embedded in SQL strings.

      Parameters

      • obj: unknown

        The object, array, or primitive value to process

      • quoteToEscape: string

        The quote character to escape (typically single quote "'")

      Returns unknown

      A new object/array with all string values having quotes properly escaped

    • Executes an aggregate query and maps results back to the original expressions.

      Parameters

      • aggregateSQL: string

        The SQL query to execute (from BuildAggregateSQL)

      • aggregates: { alias?: string; expression: string }[]

        Original aggregate expression definitions

      • validationErrors: AggregateResult[]

        Any validation errors from BuildAggregateSQL

      • OptionalcontextUser: UserInfo

        User context for query execution

      Returns Promise<{ executionTime: number; results: AggregateResult[] }>

      Array of AggregateResult objects with execution time

    • Executes a query from a QueryExecutionSpec — the lower-layer interface-based entry point. Runs the full pipeline: composition resolution → Nunjucks template processing → SQL execution. Subclasses (GenericDatabaseProvider) provide the concrete implementation via InternalExecuteQueryFromSpec.

      Parameters

      • spec: QueryExecutionSpec

        The execution spec describing the query, parameters, and inline dependencies

      • OptionalcontextUser: UserInfo

        Optional user context for permissions (required server-side)

      Returns Promise<RunQueryResult>

      Query results including data rows and execution metadata

    • Discovers ALL IS-A child entities that have records with the given primary key. Used for overlapping subtype parents (AllowMultipleSubtypes = true) where multiple children can coexist.

      Parameters

      • entityInfo: EntityInfo

        The parent entity whose children to search

      • recordPKValue: string

        The primary key value to find in child tables

      • OptionalcontextUser: UserInfo

        Optional context user for audit/permission purposes

      Returns Promise<{ ChildEntityName: string }[]>

      Array of child entity names found (empty if none)

    • Discovers which IS-A child entity, if any, has a record with the given primary key. Executes a single UNION ALL query across all child entity tables for maximum efficiency.

      Parameters

      • entityInfo: EntityInfo

        The parent entity whose children to search

      • recordPKValue: string

        The primary key value to find in child tables

      • OptionalcontextUser: UserInfo

        Optional context user for audit/permission purposes

      Returns Promise<{ ChildEntityName: string }>

      The child entity name if found, or null if no child record exists

    • Generates a new UUID suitable for use as a primary key or unique identifier. Uses uuidv4() from @memberjunction/global. Subclasses may override to provide platform-specific ID generation if needed.

      Returns string

      A new UUID string

    • Generates the SQL (and optional parameters) for a Save (Create or Update) operation. Each provider produces its own dialect: SQL Server generates T-SQL EXEC statements, PostgreSQL generates SELECT FROM function(...) calls, etc.

      Parameters

      • entity: BaseEntity

        The entity being saved

      • isNew: boolean

        True for INSERT / Create, false for UPDATE

      • user: UserInfo

        The acting user (needed for encryption, audit columns, etc.)

      Returns Promise<SaveSQLResult>

    • Asynchronous lookup of a cached entity record name. Returns the cached name if available, or undefined if not cached. Use this for synchronous contexts (like template rendering) where you can't await GetEntityRecordName().

      Parameters

      • entityName: string

        The name of the entity

      • compositeKey: CompositeKey

        The primary key value(s) for the record

      • OptionalloadIfNeeded: boolean

        If set to true, will load from database if not already cached

      Returns Promise<string>

      The cached display name, or undefined if not in cache

    • Returns the stored procedure / function name for a Create or Update operation. Pure metadata lookup — no SQL execution needed. SQL Server uses spCreate/spUpdate naming, PostgreSQL uses the same pattern.

      Parameters

      • entity: BaseEntity

        The entity being saved

      • bNewRecord: boolean

        True for Create, false for Update

      Returns string

      The SP/function name

    • Returns AI actions configured for the given entity and timing. Override in subclasses that have access to AIEngine. Default: returns empty array.

      Parameters

      Returns {
          AIActionID: string;
          AIModelID: string;
          EntityID: string;
          ID: string;
          TriggerEvent: string;
      }[]

    • Creates a new instance of a BaseEntity subclass for the specified entity and automatically calls NewRecord() to initialize it. This method serves as the core implementation for entity instantiation in the MemberJunction framework.

      Type Parameters

      Parameters

      • entityName: string

        The name of the entity to create (must exist in metadata)

      • OptionalcontextUser: UserInfo

        Optional user context for permissions and audit tracking

      Returns Promise<T>

      Promise resolving to the newly created entity instance with NewRecord() called

      Error if entity name is not found in metadata or if instantiation fails

    • Creates a new instance of a BaseEntity subclass and loads an existing record using the provided key. This overload provides a convenient way to instantiate and load in a single operation.

      Type Parameters

      Parameters

      • entityName: string

        The name of the entity to create (must exist in metadata)

      • loadKey: CompositeKey

        CompositeKey containing the primary key value(s) for the record to load

      • OptionalcontextUser: UserInfo

        Optional user context for permissions and audit tracking

      Returns Promise<T>

      Promise resolving to the entity instance with the specified record loaded

      Error if entity name is not found, instantiation fails, or record cannot be loaded

    • Gets the display name for a single entity record with caching. Uses the entity's IsNameField or falls back to 'Name' field if available.

      Parameters

      • entityName: string

        The name of the entity

      • compositeKey: CompositeKey

        The primary key value(s) for the record

      • OptionalcontextUser: UserInfo

        Optional user context for permissions

      • forceRefresh: boolean = false

        If true, bypasses cache and queries database

      Returns Promise<string>

      The display name of the record or null if not found

    • Handles entity actions (non-AI) for save, delete, or validate operations. Override in subclasses that have access to EntityActionEngineServer. Default: no-op, returns empty array.

      Parameters

      • _entity: BaseEntity
      • _baseType: "save" | "delete" | "validate"
      • _before: boolean
      • _user: UserInfo

      Returns Promise<{ Message?: string; Success: boolean }[]>

      Array of action results (empty by default)

    • Handles AI-specific entity actions for save or delete operations. Override in subclasses that have access to AIEngine. Default: no-op.

      Parameters

      Returns Promise<void>

    • Checks whether a given entity matches the target name, or is an ancestor of the target (i.e., the target is somewhere in its descendant sub-tree). Used to identify and skip the active branch during sibling propagation.

      Parameters

      Returns boolean

    • Whether a saved query is bound to an external data source. The base returns false; providers that support external data sources override this (consulting query metadata) so the outer RunQuery CacheLocal layer can defer to InternalRunQuery's own external TTL caching. Synchronous + non-throwing: resolves from cached metadata only.

      Parameters

      Returns boolean

    • Checks whether a string value looks like a known database default-value function that is NOT a UUID generator for this provider's platform.

      Parameters

      • value: string

        The string value to check

      Returns boolean

      true if the value matches a known non-UUID database function pattern

    • Checks whether a string value looks like a database UUID generation function for this provider's platform.

      Parameters

      • value: string

        The string value to check

      Returns boolean

      true if the value matches a known UUID generation function pattern

    • Logs a record change entry by diffing old/new data and executing provider-specific SQL to insert the record change. Concrete orchestration; SQL generation is delegated to BuildRecordChangeSQL.

      Parameters

      • newData: Record<string, unknown>

        The new record data (null for deletes)

      • oldData: Record<string, unknown>

        The old record data (null for creates)

      • entityName: string

        The entity name

      • recordID: string

        The record ID (CompositeKey string)

      • entityInfo: EntityInfo

        The entity metadata

      • type: "Create" | "Update" | "Delete"

        The change type

      • user: UserInfo

        The acting user

      • OptionalrestoreContext: RestoreContext

      Returns Promise<unknown[]>

    • Transforms a transaction result row into a list of field/value pairs.

      Parameters

      • transactionResult: Record<string, unknown>

      Returns { FieldName: string; Value: unknown }[]

    • Merges cached and fresh results for RunViews, maintaining original order.

      Parameters

      • preResult: {
            allCached: boolean;
            cachedResults?: RunViewResult[];
            cacheStatusMap?: Map<
                number,
                {
                    result?: RunViewResult;
                    status: "disabled"
                    | "hit"
                    | "miss"
                    | "expired";
                },
            >;
            callerFieldsMap?: Map<number, string[]>;
            fingerprintMap?: Map<number, string>;
            smartCacheCheckParams?: RunViewWithCacheCheckParams[];
            telemetryEventId?: string;
            uncachedParams?: RunViewParams[];
            useSmartCacheCheck?: boolean;
        }

        The pre-processing result with cache info

        • allCached: boolean
        • OptionalcachedResults?: RunViewResult[]
        • OptionalcacheStatusMap?: Map<
              number,
              { result?: RunViewResult; status: "disabled"
              | "hit"
              | "miss"
              | "expired" },
          >
        • OptionalcallerFieldsMap?: Map<number, string[]>

          Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.

        • OptionalfingerprintMap?: Map<number, string>

          Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.

        • OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]

          When CacheLocal is enabled, contains the cache check params to send to server

        • OptionaltelemetryEventId?: string
        • OptionaluncachedParams?: RunViewParams[]
        • OptionaluseSmartCacheCheck?: boolean

          When CacheLocal is enabled, indicates we should use smart cache check

      • freshResults: RunViewResult[]

        The fresh results from InternalRunViews

      Returns RunViewResult[]

      Combined results in original order

    • Merges cached and fresh results for RunQueries, maintaining original order.

      Parameters

      • preResult: {
            allCached: boolean;
            cachedResults?: RunQueryResult[];
            cacheStatusMap?: Map<
                number,
                {
                    result?: RunQueryResult;
                    status: "disabled"
                    | "hit"
                    | "miss"
                    | "expired";
                },
            >;
            telemetryEventId?: string;
            uncachedParams?: RunQueryParams[];
        }

        The pre-processing result with cache info

      • freshResults: RunQueryResult[]

        The fresh results from InternalRunQueries

      Returns RunQueryResult[]

      Combined results in original order

    • Called after a direct (non-transaction) save succeeds, before the result is returned to the caller and loaded into the entity via finalizeSave().

      Post-Save Patch Mechanism

      This hook can optionally return a Record<string, unknown> containing field values that should be patched onto the SP result row before it is loaded into the entity. This solves a timing problem: the SP result is captured before OnSaveCompleted runs, so any data created by post-save hooks (e.g., geocoding writing to a JOINed table) would be stale in the returned entity without this patch.

      1. The SP executes and returns result[0] with the current view data
      2. OnSaveCompleted runs post-save logic (geocoding, ISA propagation, etc.)
      3. If this method returns a non-null Record, those key/value pairs are merged onto result[0] via Object.assign(), overwriting stale values
      4. The patched result is then returned to BaseEntity.finalizeSave() which calls SetMany() to load the corrected data into the entity

      After geocoding updates RecordGeoCode, the new lat/lng are returned as patches for the __mj_Latitude and __mj_Longitude virtual fields that come from the RecordGeoCode JOIN in the entity's base view. Without this patch, those fields would contain the pre-geocoding values until the next query.

      • Return null if no patches are needed (default behavior)
      • Only include fields that were actually changed by your post-save logic
      • Always call await super.OnSaveCompleted(...) and merge its patches with yours
      • Patches are shallow-merged via Object.assign — last writer wins for each key

      Parameters

      Returns Promise<Record<string, unknown>>

      Patch fields to apply to the SP result, or null if no patches needed

    • Post-processes rows returned by a save/load SQL operation. SQL Server overrides to handle datetimeoffset conversion and field decryption. Default: returns rows unchanged.

      Parameters

      Returns Promise<Record<string, unknown>[]>

    • Post-processing hook for RunQueries (batch). Handles telemetry end.

      Parameters

      • results: RunQueryResult[]

        Array of query results

      • params: RunQueryParams[]

        Array of query parameters

      • preResult: {
            allCached: boolean;
            cachedResults?: RunQueryResult[];
            cacheStatusMap?: Map<
                number,
                {
                    result?: RunQueryResult;
                    status: "disabled"
                    | "hit"
                    | "miss"
                    | "expired";
                },
            >;
            telemetryEventId?: string;
            uncachedParams?: RunQueryParams[];
        }

        The pre-processing result

      • OptionalcontextUser: UserInfo

        Optional user context

      Returns Promise<void>

    • Post-processing hook for RunQuery. Handles cache storage and telemetry end.

      Parameters

      • result: RunQueryResult

        The query result

      • params: RunQueryParams

        The query parameters

      • preResult: {
            cachedResult?: RunQueryResult;
            cacheStatus: "disabled" | "hit" | "miss" | "expired";
            fingerprint?: string;
            telemetryEventId?: string;
        }

        The pre-processing result

      • OptionalcontextUser: UserInfo

        Optional user context

      Returns Promise<void>

    • Post-processing hook for RunView. Handles result transformation, cache storage, and telemetry end.

      Parameters

      • result: RunViewResult

        The view result

      • params: RunViewParams

        The view parameters

      • preResult: {
            cachedResult?: RunViewResult;
            cacheStatus: "disabled" | "hit" | "miss" | "expired";
            callerRequestedFields?: string[];
            fingerprint?: string;
            telemetryEventId?: string;
        }

        The pre-processing result

        • OptionalcachedResult?: RunViewResult
        • cacheStatus: "disabled" | "hit" | "miss" | "expired"
        • OptionalcallerRequestedFields?: string[]

          The caller's original Fields list (lowercased), captured before PreRunView widened params.Fields to all entity fields for cache-superset storage. Non-null ONLY when that widening actually happened — PostRunView uses it to project cache-miss DB results back down to the requested shape.

        • Optionalfingerprint?: string
        • OptionaltelemetryEventId?: string
      • OptionalcontextUser: UserInfo

        Optional user context

      Returns Promise<void>

    • Post-processing hook for RunViews (batch). Handles result transformation, cache storage, and telemetry end.

      Parameters

      • results: RunViewResult[]

        Array of view results

      • params: RunViewParams[]

        Array of view parameters

      • preResult: {
            allCached: boolean;
            cachedResults?: RunViewResult[];
            cacheStatusMap?: Map<
                number,
                {
                    result?: RunViewResult;
                    status: "disabled"
                    | "hit"
                    | "miss"
                    | "expired";
                },
            >;
            callerFieldsMap?: Map<number, string[]>;
            fingerprintMap?: Map<number, string>;
            smartCacheCheckParams?: RunViewWithCacheCheckParams[];
            telemetryEventId?: string;
            uncachedParams?: RunViewParams[];
            useSmartCacheCheck?: boolean;
        }

        The pre-processing result

        • allCached: boolean
        • OptionalcachedResults?: RunViewResult[]
        • OptionalcacheStatusMap?: Map<
              number,
              { result?: RunViewResult; status: "disabled"
              | "hit"
              | "miss"
              | "expired" },
          >
        • OptionalcallerFieldsMap?: Map<number, string[]>

          Per-param-index caller Fields lists (lowercased), captured before PreRunViews widened params.Fields to all entity fields for cache-superset storage. An index is present ONLY when that widening actually happened — PostRunViews uses it to project cache-miss DB results back down to the requested shape.

        • OptionalfingerprintMap?: Map<number, string>

          Per-param-index cache fingerprints computed during PreRunViews — carried forward so PostRunViews doesn't recompute the RLS where-clause and fingerprint string for every batch item.

        • OptionalsmartCacheCheckParams?: RunViewWithCacheCheckParams[]

          When CacheLocal is enabled, contains the cache check params to send to server

        • OptionaltelemetryEventId?: string
        • OptionaluncachedParams?: RunViewParams[]
        • OptionaluseSmartCacheCheck?: boolean

          When CacheLocal is enabled, indicates we should use smart cache check

      • OptionalcontextUser: UserInfo

        Optional user context

      Returns Promise<void>

    • Pre-processing hook for RunQueries (batch). Handles telemetry for batch query operations.

      Parameters

      Returns Promise<
          {
              allCached: boolean;
              cachedResults?: RunQueryResult[];
              cacheStatusMap?: Map<
                  number,
                  {
                      result?: RunQueryResult;
                      status: "disabled"
                      | "hit"
                      | "miss"
                      | "expired";
                  },
              >;
              telemetryEventId?: string;
              uncachedParams?: RunQueryParams[];
          },
      >

      Pre-processing result

    • Pre-processing hook for RunQuery. Handles telemetry and cache lookup.

      Parameters

      Returns Promise<
          {
              cachedResult?: RunQueryResult;
              cacheStatus: "disabled"
              | "hit"
              | "miss"
              | "expired";
              fingerprint?: string;
              telemetryEventId?: string;
          },
      >

      Pre-processing result with cache status and optional cached result

    • Pre-processing hook for RunView. Handles telemetry, validation, entity status check, and cache lookup.

      Parameters

      Returns Promise<
          {
              cachedResult?: RunViewResult;
              cacheStatus: "disabled"
              | "hit"
              | "miss"
              | "expired";
              callerRequestedFields?: string[];
              fingerprint?: string;
              telemetryEventId?: string;
          },
      >

      Pre-processing result with cache status and optional cached result

    • Pre-processing hook for RunViews (batch). Handles telemetry, validation, and cache lookup for multiple views.

      Parameters

      Returns Promise<
          {
              allCached: boolean;
              cachedResults?: RunViewResult[];
              cacheStatusMap?: Map<
                  number,
                  {
                      result?: RunViewResult;
                      status: "disabled"
                      | "hit"
                      | "miss"
                      | "expired";
                  },
              >;
              callerFieldsMap?: Map<number, string[]>;
              fingerprintMap?: Map<number, string>;
              smartCacheCheckParams?: RunViewWithCacheCheckParams[];
              telemetryEventId?: string;
              uncachedParams?: RunViewParams[];
              useSmartCacheCheck?: boolean;
          },
      >

      Pre-processing result with cache status for each view

    • Synchronous pre-validation of cached metadata before engine startup.

      On a warm load we serve the metadata graph from IndexedDB so the app can boot without pulling MBs of metadata from the server. Before engines run, this method makes one batched timestamp round-trip to confirm the snapshot is still current:

      • Cached metadata is current → engines proceed against the cached snapshot. Their RunViews calls go through the normal smart-cache-check path which batches per-view fingerprints to the server — efficient and authoritative.
      • Cached metadata is stale → refresh framework metadata in place before engines start, then proceed normally.

      Cost on the warm-current path is one batched timestamp fetch (~50–200 ms depending on RTT). On the warm-stale path we additionally pay the full metadata fetch but avoid serving stale data to the UI in the first place.

      Caller contract: invoke this before StartupManager.Startup().

      Parameters

      Returns Promise<void>

    • Propagates record change entries to sibling branches of an IS-A hierarchy. Called after saving an entity with AllowMultipleSubtypes (overlapping subtypes). Collects SQL from BuildSiblingRecordChangeSQL for each sibling and executes as a batch.

      Parameters

      • parentInfo: EntityInfo

        The parent entity info

      • changeData: { changesDescription: string; changesJSON: string }

        The changes JSON and description

      • pkValue: string

        The primary key value

      • userId: string

        The acting user ID

      • activeChildEntityName: string

        The child entity that initiated the save (to skip)

      • OptionalextraExecOptions: Record<string, unknown>

        Optional provider-specific execution options (e.g. connectionSource for SQL Server transactions)

      Returns Promise<void>

    • Quotes a database identifier (table, column, view name) using the provider's dialect convention. SQL Server uses [brackets], PostgreSQL uses "double quotes".

      Parameters

      • name: string

        The identifier to quote

      Returns string

    • Quotes a schema-qualified object name (e.g. schema.viewName) using the provider's dialect convention. SQL Server uses [schema].[view], PostgreSQL uses "schema"."view".

      Parameters

      • schemaName: string

        The schema name

      • objectName: string

        The object name (table, view, etc.)

      Returns string

    • The RunQuery cache-serve seam (B45/B46) — resolves a RunQuery request against this provider's query metadata and answers, in ONE computation performed BEFORE fingerprinting:

      • categoryPath: the RESOLVED query's canonical full category path. This becomes a distinguishing fingerprint segment (B46) so two same-named queries in different categories can never collide onto one cache slot. When the request is unresolvable the caller falls back to the CALLER-STATED params.CategoryPath (still distinguishing, just not canonicalized).
      • resolvable: whether metadata could resolve the request at all. Runtime-created queries are typically NOT resolvable from the base metadata cache (it does not refresh in-process) — the gate then applies the warmer tie-break instead.
      • authorized: whether user may run the resolved query. Meaningful only when resolvable is true.

      The BASE implementation resolves from the metadata Queries cache and enforces the ROLES-ONLY QueryInfo.UserCanRun — the strongest check available at this layer. Providers with richer query metadata MUST override this to enforce the SAME authorization their miss path enforces (GenericDatabaseProvider overrides with MJQueryEntityExtended.UserCanRun, which adds entity CanRead + recursive composition checks — the exact check ValidateQueryForExecution applies on a cache miss). The invariant this seam exists to hold: a cache HIT must never be easier to read than a cache MISS (B45 was precisely that asymmetry — the TTL gate checked roles only while the miss path also checked entity read permissions).

      Parameters

      Returns QueryCacheAuthorization

    • Resolves a PlatformSQL value to the appropriate SQL string for this provider's platform. If the value is a plain string, it is returned as-is (backward compatible). If the value is a PlatformSQL object, the platform-specific variant is used if available, otherwise the default variant is used.

      Parameters

      Returns string

    • Routes a typed Remote Operation by key to its implementation (see IRemoteOperationProvider).

      This is the public power-tool transport seam. Prefer the typed BaseRemotableOperation.Execute() entry point in application code — RouteOperation is the stringly-typed escape hatch for dynamic dispatch / generic tooling, not for building significant systems. Server providers override InternalRouteOperation to execute the operation in-process; the client (GraphQL) provider overrides it to marshal over the wire. Only registered, active (and, when AI-authored, approved) operations are routable, and every call is authorized on the server side.

      Type Parameters

      • TInput = unknown
      • TOutput = unknown

      Parameters

      • operationKey: string

        Stable registry key of the operation (e.g. RecordProcess.RunNow).

      • input: TInput

        The operation's typed input payload.

      • Optionaloptions: RemoteOpInvokeOptions

        Optional invocation options (mode, progress callback, user, provider, fingerprint).

      Returns Promise<RemoteOpResult<TOutput>>

      The operation result; never throws for logical failures — check Success/ErrorMessage.

    • Runs all registered PostRunView hooks against a single result, returning the (possibly mutated) result.

      Protected (not private) for the same reason as RunPreRunViewHooks above: a subclass pipeline that returns view rows WITHOUT passing through PostRunView/PostRunViews — e.g. the RunViewsWithCacheCheck smart-cache path — MUST apply these hooks to the rows it returns. PostRunView is the OUTPUT half of the enforcement seam (data masking / audit); a path that skips it returns rows the hooked paths would have masked.

      Parameters

      Returns Promise<RunViewResult>

    • Runs all registered PreRunView hooks against a single RunViewParams, returning the (possibly mutated) params.

      Protected (not private) on purpose: any subclass pipeline that executes view queries WITHOUT passing through PreRunView/PreRunViews — e.g. the RunViewsWithCacheCheck smart-cache path in GenericDatabaseProvider — MUST apply these hooks itself. Hooks are an enforcement seam (tenant scoping middleware injects filters here); a query path that skips them silently returns rows the hooked paths would have filtered out.

      Parameters

      Returns Promise<RunViewParams>

    • Runs a report by looking up its SQL definition from vwReports and executing it. Both SQL Server and PostgreSQL share this logic — the only dialect difference is identifier quoting, handled by QuoteIdentifier/QuoteSchemaAndView.

      Parameters

      • params: RunReportParams

        Report parameters including ReportID

      • OptionalcontextUser: UserInfo

        Optional context user for permission/audit purposes

      Returns Promise<RunReportResult>

      Reports are no longer supported and will eventually be removed. Interactive Components and Artifacts are replacements

    • Single source of truth for whether a RunView call participates in the local cache (both READ and WRITE). Pre/Post hooks for the singular and batch paths must all use this predicate — historically each site recomputed it inline and they drifted (PostRunViews wrote BypassCache results into the cache, poisoning the Fields-agnostic superset slot with narrow rows).

      Ineligible:

      • BypassCache — caller explicitly wants true DB state, no cache interaction
      • AfterKey — keyset pages are single-use AND the fingerprint doesn't include the seek key, so caching a page would poison the entity+filter slot
      • ResultType 'count_only' — returns no rows; caching its empty Results under a fingerprint that excludes ResultType would poison row queries
      • entities where server caching is disallowed

      Parameters

      Returns boolean

    • Runs multiple views based on the provided parameters. Wraps the execution pipeline with request deduplication and a linger window so that concurrent (and near-sequential) identical calls share a single server round-trip. Every caller receives a shallow-copied Results array to protect against cross-caller mutations (push/sort/splice).

      Type Parameters

      • T = any

      Parameters

      • params: RunViewParams[]

        Array of view parameters

      • OptionalcontextUser: UserInfo

        Optional user context for permissions (required server-side)

      Returns Promise<RunViewResult<T>[]>

      Array of view results (shallow-copied Results per caller)

    • Saves an entity record — the full orchestration flow shared by all DB providers.

      1. Permission & dirty-state checks
      2. Validation via OnValidateBeforeSave hook
      3. Before-save actions via OnBeforeSaveExecute hook
      4. SQL generation via GenerateSaveSQL (abstract, provider-specific)
      5. Execute via TransactionGroup or directly
      6. After-save actions via OnAfterSaveExecute hook
      7. Post-save cleanup via OnSaveCompleted hook (ISA propagation, etc.)

      Parameters

      Returns Promise<{}>

    • Batch form of SearchEntity. Fans the input list out to N independent SearchEntity calls via Promise.all; result arrays come back aligned by input order (result[i] holds the matches for params[i]).

      On the server side, the per-entity passes are independent — running them concurrently is a real wall-clock win when the caller wants results from multiple entities. On the client side, GraphQLDataProvider overrides this method to pack the whole batch into a single GraphQL round-trip instead of issuing N parallel HTTP requests.

      See IMetadataProvider.SearchEntities for the contract.

      Parameters

      Returns Promise<EntitySearchResult[][]>

    • Run the semantic ranking pass for SearchEntity. Each concrete ProviderBase subclass supplies its own implementation: server-side providers (GenericDatabaseProvider) embed the query text and query an in-process vector pool directly; client-side providers (GraphQLDataProvider) override SearchEntity / SearchEntities outright to proxy via GraphQL and never reach this method.

      Parameters

      • entityDocumentId: string
      • searchText: string
      • overFetch: number
      • embeddingAIModelId: string
      • contextUser: UserInfo

      Returns Promise<ScoredCandidate[]>

      Ranked array of ScoredCandidate whose ID is the parent entity's record ID and Metadata.entityRecordDocumentId carries the EntityRecordDocument PK.

    • Ranked search over one entity's records. See IMetadataProvider.SearchEntity for the contract and how this differs from EntityByName / FullTextSearch.

      Implementation overview (concrete on ProviderBase, used as-is by every server-side provider; GraphQLDataProvider overrides to proxy via GQL):

      1. Resolve the EntityDocument (by params.options.entityDocumentId override or by looking up the active Search-category doc for the entity).
      2. In parallel: run the lexical pass (RunView with LIKE filters on the name field + any IncludeInUserSearchAPI fields) and the semantic pass (searchEntitiesSemanticPass, the protected template method each concrete server provider implements).
      3. Fuse via canonical ComputeRRF() with optional per-list weights.
      4. Permission-filter via a second RunView constrained to the matched record IDs — that pipeline already enforces row-level read perms on this entity, so any rows the user can't read drop out.
      5. Slice to topK, apply minScore cutoff, return.

      Parameters

      Returns Promise<EntitySearchResult[]>

    • Stores a record name in the cache for later synchronous retrieval via GetCachedRecordName(). Called automatically by BaseEntity after Load(), LoadFromData(), and Save() operations.

      Parameters

      • entityName: string

        The name of the entity

      • compositeKey: CompositeKey

        The primary key value(s) for the record

      • recordName: string

        The display name to cache

      Returns void

    • Truncates a string value to a maximum length, appending trailing characters if truncated.

      Parameters

      • value: unknown
      • maxLength: number
      • trailingChars: string

      Returns unknown

    • Validates a user-provided SQL clause (WHERE, ORDER BY, etc.) to prevent SQL injection. Checks for forbidden keywords (INSERT, UPDATE, DELETE, EXEC, DROP, UNION, etc.) and dangerous patterns (comments, semicolons, xp_ prefix). String literals are stripped before validation to avoid false positives.

      Parameters

      • clause: string

        The SQL clause to validate

      Returns boolean

      true if the clause is safe, false if it contains forbidden patterns

    • Static convenience: checks all platforms' default-value functions. Prefer the instance method when you have a provider reference.

      Parameters

      • value: string

      Returns boolean

    • Static convenience: checks all platforms' UUID generation functions. Prefer the instance method when you have a provider reference.

      Parameters

      • value: string

      Returns boolean

    • Returns the caller's requested fields (lowercased) unioned with the entity's primary key field names. Platform contract: when Fields is explicitly specified, results ALWAYS include the primary key(s) — the direct SQL path has always done this, differential smart-cache merges require it, and entity linking in UIs depends on it. Applying the same union at every projection site keeps result shapes identical across cached, non-cached, and smart-cache paths.

      Parameters

      Returns string[]