Member Junction
    Preparing search index...

    Server-side MJ: Entity Field Permissions entity — the save-time half of the unrestrictable-target guard for field-level security.

    The runtime aggregation (EntityFieldInfo.GetUserFieldPermissions) already forces access open for these targets, so this subclass is not what makes the system safe. It is what makes the system diagnosable: without it an administrator can save a row that silently does nothing, then reasonably conclude the feature is broken. Rejecting at save says why.

    Two categories are refused, matching the two runtime guards exactly:

    1. Primary keys and system columns. Stripping a primary key from a result breaks entity load, CompositeKey construction, relationship resolution, and cache fingerprinting — failures that surface nowhere near the permission record that caused them.
    2. The security-configuration and identity surface (see EntityFieldInfo.IsOnUnrestrictableEntity). Restricting a column on the very entities field security is administered through produces a configuration that cannot be reversed through the product — recovery would mean direct SQL against the database.

    A third category is refused for a different reason: a Deny aimed at a role the MJ system user holds (see SystemUserRoleRejectionReason). That one is not about diagnosability — it is what lets the runtime aggregation have no exempt user at all. The server's own account gets its access from ordinary Allow rows like everyone else, and this guard is what stops those being revoked.

    Note what is deliberately NOT here: any notion of a user who is exempt from a Deny at RUNTIME. The guards are on which targets are restrictable and on what may be configured, never on whose access is evaluated. A feature whose purpose is compensation and donor-giving confidentiality cannot ship with a role that quietly reads everything.

    Hierarchy (View Summary)

    Index

    Constructors

    Properties

    Accessors

    Methods

    AfterEntityAIAction ApplyFieldLevelCreateSuppression AttachToParent BeforeEntityAIAction BindProvider BuildDeletePlan BuildSavePlan CascadeDeleteChildRecord CheckFieldLevelUpdatePermissions CheckForChildRecords CheckPermissions ClearRestoreContext Config ConstructUninitializedEntity CopyFrom DeclareEmbeddedRecord DeclareRelatedRecords Delete DeserializeCompanions EmbedTextLocal EnforceDisjointSubtype EnsureDeleteComplete EnsureISAChild EnsureLoadComplete EnsureSaveComplete FieldIsDirty From GenerateEmbedding GenerateEmbeddingByFieldName GenerateEmbeddings GenerateEmbeddingsByFieldName Get GetAll GetAncestors GetChangesSinceLastSave GetChildren GetCompanion GetDataObject GetDataObjectJSON GetDescendants GetFieldByCodeName GetFieldByName GetRecordName getRecursiveForeignKeyField GetRelatedEntityData GetRelatedEntityDataExt Hydrate InitializeChildEntity InitializeEmbeddedRecords InitializeParentEntity InnerLoad Load LoadFromData LoadRelatedRecords NewRecord RaiseEvent RaiseReadyForTransaction Refresh RegisterCompanion RegisterEventHandler RegisterResultHistoryEntry RegisterTransactionPreprocessing ResetVectors ResolveSubtypeEntityName Revert Save SerializeCompanions Set SetEmbeddedLoadVisited SetMany SetRestoreContext SupportsEmbedTextLocal ThrowPermissionError To Validate ValidateAsync ValidateReadAccessRequiredForCreateOrUpdate ClearSubtypeLookupCache EntityPermissionRequiredRejectionReason GetRecordChanges RejectionReason ResolveLeafEntity SystemUserRoleRejectionReason WriteVerbRejectionReason

    Constructors

    Properties

    MAX_RESULT_HISTORY: 50

    Maximum number of BaseEntityResult entries retained in _resultHistory per entity instance. Set to 50 — enough for diagnostic context while bounding worst-case memory for entities that survive thousands of Save/Delete cycles.

    Accessors

    • get __mj_CreatedAt(): Date
      • Field Name: __mj_CreatedAt
      • Display Name: Created At
      • SQL Data Type: datetimeoffset
      • Default Value: getutcdate()

      Returns Date

    • get __mj_UpdatedAt(): Date
      • Field Name: __mj_UpdatedAt
      • Display Name: Updated At
      • SQL Data Type: datetimeoffset
      • Default Value: getutcdate()

      Returns Date

    • get ActiveUser(): UserInfo

      Internal helper method for the class and sub-classes - used to easily get the Active User which is either the ContextCurrentUser, if defined, or the Metadata.Provider.CurrentUser if not.

      Returns UserInfo

    • get BoundProvider(): IEntityDataProvider

      The provider actually stored on this instance, or null if none was bound. Unlike ProviderToUse, this does not fall back to the process-wide BaseEntity.Provider. Use it to detect a dropped constructor argument: GetEntityObject(graphProvider) must yield BoundProvider === graphProvider.

      Returns IEntityDataProvider

    • get Companions(): readonly EntityCompanion<unknown>[]

      The companions registered on this entity, in declaration order.

      Empty for the vast majority of entities. Nothing in the save, load or validation paths does any companion work when this is empty, so the feature costs nothing where it is unused.

      Returns readonly EntityCompanion<unknown>[]

    • get ContextCurrentUser(): UserInfo

      Returns UserInfo

    • set ContextCurrentUser(user: UserInfo): void

      The ContextCurrentUser is a property used to manually set the "current" user for scenarios, primarily on the server side, where the user changes per request. For situations where there is no global CurrentUser in the Metadata.Provider, you MUST set this property to the user you want to use for the current operation. If you used Metadata.GetEntityObject() to get the entity object, this property will be set automatically for you as that method has a parameter that can be provided for the ContextCurrentUser.

      Parameters

      Returns void

    • get CreateAccess(): "Allow" | "Deny" | "No Access"
      • Field Name: CreateAccess
      • Display Name: Create Access
      • SQL Data Type: nvarchar(20)
      • Default Value: No Access
      • Value List Type: List
      • Possible Values
        • Allow
        • Deny
        • No Access
      • Description: Whether this role may supply the field's value when INSERTING a record. Allow grants it; Deny blocks it and beats every Allow from the user's other roles; No Access is neutral (the default). Requires ReadAccess = Allow. When a user may not create a field, any value they supply is dropped and the column takes its default — the insert is not rejected, matching the read path where a denied field is simply absent rather than an error. A NOT NULL column with no default that a user cannot create makes records uncreatable for that user; restricted fields should be nullable or defaulted.

      Returns "Allow" | "Deny" | "No Access"

    • set CreateAccess(value: "Allow" | "Deny" | "No Access"): void

      Parameters

      • value: "Allow" | "Deny" | "No Access"

      Returns void

    • get DefaultSkipAsyncValidation(): boolean
      Protected

      Default value for whether async validation should be skipped.

      Returns boolean

      Override this to state a policy explicitly; an explicit override always wins over the inference described below. When the options object passed to Save() includes SkipAsyncValidation, that value takes precedence over both.

      If no subclass overrides this getter, the answer is inferred instead: async validation runs when a subclass has overridden ValidateAsync, and is skipped when none has. Reading the literal true below as "async validation is off unless you find this getter" made every hand-written ValidateAsync a silent no-op — see the note on that method.

    • get Dirty(): boolean

      Returns boolean

    • get EntityField(): string
      • Field Name: EntityField
      • Display Name: Entity Field
      • SQL Data Type: nvarchar(255)

      Returns string

    • get EntityFieldID(): string
      • Field Name: EntityFieldID
      • Display Name: Entity Field ID
      • SQL Data Type: uniqueidentifier
      • Related Entity/Foreign Key: MJ: Entity Fields (vwEntityFields.ID)

      Returns string

    • set EntityFieldID(value: string): void

      Parameters

      • value: string

      Returns void

    • get EntityInfo(): EntityInfo

      Access to the underlying metadata for the entity object.

      Returns EntityInfo

    • get Fields(): EntityField[]

      Returns EntityField[]

    • get FirstPrimaryKey(): EntityField

      Helper method to return just the first Primary Key

      Returns EntityField

    • get HasCompanions(): boolean

      Whether this entity has any registered companions.

      Used as the fast guard on the hot paths — a single boolean check keeps single-record saves on exactly the code path they took before companions existed.

      Returns boolean

    • get ID(): string
      • Field Name: ID
      • Display Name: ID
      • SQL Data Type: uniqueidentifier
      • Default Value: newsequentialid()

      Returns string

    • set ID(value: string): void

      Parameters

      • value: string

      Returns void

    • get ISAChild(): BaseEntity<unknown>

      Returns the child entity in the IS-A composition chain, or null if this entity has no child record, hasn't been loaded yet, or is an overlapping subtype parent (use ISAChildren instead for overlapping parents).

      Example: For a MeetingEntity where a Webinar record exists with the same PK, ISAChild returns the WebinarEntity instance.

      Returns BaseEntity<unknown>

    • get ISAChildren(): { entityName: string }[]

      For overlapping subtype parents (AllowMultipleSubtypes = true), returns the list of child entity type names that have records for this PK. For disjoint parents or non-parent entities, returns null (use ISAChild instead).

      Example: For a PersonEntity with AllowMultipleSubtypes=true, might return [{entityName: 'Members'}, {entityName: 'Volunteers'}, {entityName: 'Speakers'}].

      Returns { entityName: string }[]

    • get ISAParent(): BaseEntity<unknown>

      Returns the parent entity in the IS-A composition chain, or null if this entity is not an IS-A child type.

      Example: For a MeetingEntity that IS-A ProductEntity, ISAParent returns the ProductEntity instance.

      Named with ISA prefix to avoid collision with generated entity properties (many entities have a Parent string column in the database).

      Returns BaseEntity<unknown>

    • get ISAParentEntity(): BaseEntity<unknown>

      Returns BaseEntity<unknown>

      Use ISAParent instead. Kept for backward compatibility.

    • get IsBusy(): boolean

      Returns true if any operation (Save, Delete, or Load) is currently in progress. This is a convenience property that combines IsSaving, IsDeleting, and IsLoading. Useful for disabling UI elements when any database operation is happening.

      Returns boolean

    • get IsDeleting(): boolean

      Returns true if a Delete operation is currently in progress. This is useful for UI components to show loading indicators or disable buttons while deleting.

      Returns boolean

    • get IsLoading(): boolean

      Returns true if a Load operation is currently in progress. This is useful for UI components to show loading indicators while data is being fetched.

      Returns boolean

    • get IsSaved(): boolean

      Returns true if the record has been saved to the database, false otherwise. This is a useful property to check to determine if the record is a "New Record" or an existing one.

      Returns boolean

    • get IsSaving(): boolean

      Returns true if a Save operation is currently in progress. This is useful for UI components to show loading indicators or disable buttons while saving.

      Returns boolean

    • get LatestResult(): BaseEntityResult

      Returns the most recent result from the result history. If there are no results in the history, this method will return null.

      Returns BaseEntityResult

    • get LeafEntity(): BaseEntity

      Returns the leaf (most-derived) entity in the IS-A chain, walking downward through child references. Returns this if no child exists.

      For overlapping subtype parents (AllowMultipleSubtypes = true), returns this because there is no single child chain to follow — the parent is the leaf from its own perspective.

      Returns BaseEntity

    • get PrimaryKey(): CompositeKey

      Returns the primary key for the record. The CompositeKey class is a multi-valued key that can have any number of key/value pairs within it. Always traverse the full set of key/value pairs to get the full primary key for the record.

      Returns CompositeKey

    • get PrimaryKeys(): EntityField[]

      Returns an array of all primary key fields for the entity. If the entity has a composite primary key, this method will return an array of all primary key fields. If the entity has a single primary key, this method will return an array with a single field in it.

      Returns EntityField[]

    • get ProviderToUse(): IEntityDataProvider

      Returns this provider to be used for a given instance of a BaseEntity derived subclass. If the provider is not set, the BaseEntity.Provider is returned.

      Returns IEntityDataProvider

    • get ReadAccess(): "Allow" | "Deny" | "No Access"
      • Field Name: ReadAccess
      • Display Name: Read Access
      • SQL Data Type: nvarchar(20)
      • Default Value: No Access
      • Value List Type: List
      • Possible Values
        • Allow
        • Deny
        • No Access
      • Description: Whether this role may read the field's values. Allow grants it; Deny blocks it and beats every Allow from the user's other roles; No Access is neutral (the default) and leaves the outcome to the user's other roles. Enforced at the API output boundary (result projection and GraphQL field mapping), by predicate validation which rejects an ExtraFilter/OrderBy/Aggregate referencing an unreadable field, and by the strongly-typed accessor path which throws.

      Returns "Allow" | "Deny" | "No Access"

    • set ReadAccess(value: "Allow" | "Deny" | "No Access"): void

      Parameters

      • value: "Allow" | "Deny" | "No Access"

      Returns void

    • get RecordChanges(): Promise<RecordChange[]>

      Returns a list of changes made to this record, over time. Only works if TrackRecordChanges bit set to 1 on the entity you're working with.

      Returns Promise<RecordChange[]>

    • get RecordLoaded(): boolean

      Returns true if the record has been loaded from the database, false otherwise. This is useful to check to see if the record is in a "New Record" state or not.

      Returns boolean

    • get RestoreContext(): RestoreContext

      Returns the active restore context for the next save, if any.

      Read by the data provider when generating the RecordChange SQL: when non-null, the resulting RecordChange row is written with Source='Restore', RestoredFromID = SourceChangeID, and RestoreReason = Reason. Returns null for ordinary saves.

      Returns RestoreContext

    • get ResultHistory(): BaseEntityResult[]

      The result history shows the history of the attempted transactions (Save and Delete) for this particular entity object. This is useful for tracking the results of operations on the entity object.

      Returns BaseEntityResult[]

    • get Role(): string
      • Field Name: Role
      • Display Name: Role
      • SQL Data Type: nvarchar(50)

      Returns string

    • get RoleID(): string
      • Field Name: RoleID
      • Display Name: Role ID
      • SQL Data Type: uniqueidentifier
      • Related Entity/Foreign Key: MJ: Roles (vwRoles.ID)

      Returns string

    • set RoleID(value: string): void

      Parameters

      • value: string

      Returns void

    • get RootEntity(): BaseEntity

      Returns the root (least-derived) entity in the IS-A chain, walking upward through parent references. Returns this if no parent exists.

      Returns BaseEntity

    • get RunQueryProviderToUse(): IRunQueryProvider

      Returns the RunQueryProvider to be used for a given instance of a BaseEntity derived subclass.

      Returns IRunQueryProvider

    • get RunViewProviderToUse(): IRunViewProvider

      Returns the RunViewProvider to be used for a given instance of a BaseEntity derived subclass.

      Returns IRunViewProvider

    • get SkipEmbeddings(): boolean

      Returns boolean

    • set SkipEmbeddings(value: boolean): void

      Parameters

      • value: boolean

      Returns void

    • get TransactionGroup(): TransactionGroupBase

      Transaction Groups are used to group multiple transactions into a single ATOMic transaction in a database. They are also useful even in situations with ATOMicity is less important but you want to submit a group of changes to the API server in a single network call.

      Returns TransactionGroupBase

    • set TransactionGroup(group: TransactionGroupBase): void

      Parameters

      Returns void

    • get UpdateAccess(): "Allow" | "Deny" | "No Access"
      • Field Name: UpdateAccess
      • Display Name: Update Access
      • SQL Data Type: nvarchar(20)
      • Default Value: No Access
      • Value List Type: List
      • Possible Values
        • Allow
        • Deny
        • No Access
      • Description: Whether this role may modify the field's value on an EXISTING record. Allow grants it; Deny blocks it and beats every Allow from the user's other roles; No Access is neutral (the default). Requires ReadAccess = Allow — a field a user cannot see is one they cannot change. Enforced server-side before SQL generation; the client-side BaseEntity check is UX-level defense-in-depth only.

      Returns "Allow" | "Deny" | "No Access"

    • set UpdateAccess(value: "Allow" | "Deny" | "No Access"): void

      Parameters

      • value: "Allow" | "Deny" | "No Access"

      Returns void

    • get Vectors(): Map<string, number[]>

      Utility storage for vector embeddings that represent the active record. Each string in the Map can be any unique key relative to the object so you can use this to track vectors associated with

      Returns Map<string, number[]>

    • get BaseEventCode(): string

      When a BaseEntity class raises an event with MJGlobal, the eventCode property is set to this value. This is used to identify events that are raised by BaseEntity objects. Any MJGlobal event that is raised by a BaseEntity class will use a BaseEntityEvent type as the args parameter

      Returns string

    • get Provider(): IEntityDataProvider

      Static property to get/set the IEntityDataProvider that is used by all BaseEntity objects. This is a global setting that is used by all BaseEntity objects. It can be overriden for a given BaseEntity object instance by passing in a provider to the constructor of the BaseEntity object. Typically, a provider will pass itself into BaseEntity objects it creates to create a tight coupling between the provider and the BaseEntity objects it creates. This allows multiple concurrent connections to exist in the same process space without interfering with each other.

      Returns IEntityDataProvider

    • set Provider(value: IEntityDataProvider): void

      Parameters

      Returns void

    Methods

    • Field-level security on the INSERT path: marks the fields this user may not supply so the save omits them and each column takes its database default.

      This never rejects, and that is deliberate. Rejecting would be inconsistent with the read path (a denied field is simply absent, not an error) and would leak information — an error naming Salary confirms the field exists and is restricted, which the ambiguous denial wording exists to prevent. Silently defaulting is also what an unrestricted user gets by leaving the field blank, so a restricted user creating a record ends up with the same record SHAPE rather than a failure.

      The cost is that a user who supplies a value for a create-denied field gets no feedback that it was dropped, which is why the drop is logged and why the admin UI should not render the field at all.

      Runs on every save (clearing prior marks first) because the answer depends on the acting user, and one entity object can be saved by different users over its lifetime.

      Returns void

    • IS-A PROMOTION (#3825): binds this NEW child record to an EXISTING parent row, so saving it ADDS a subtype to a person/org/product that already exists instead of trying to create a duplicate parent.

      Before this existed the operation was impossible: NewRecord() always starts a fresh parent chain, so "this existing Person is now also an Applicant" INSERTed a second Person and collided with the existing primary key (or, with parent fields unset, failed the parent's NOT NULL validation as if it were brand new). Discovery ran the other way only — a loaded parent finds its existing child — and promotion is the normal case in a multi-app install, where a shared entity like Person accumulates subtypes owned by different applications.

      What it does, in the existing machinery rather than beside it:

      1. LOADS the parent chain by the supplied key (InnerLoad, which also hydrates any grandparents from the same row). A loaded parent saves as an UPDATE, which is the whole trick — the chain save that already runs parent-first now updates the existing row and INSERTs only this child.
      2. Mirrors the shared primary key into this child's local fields, restoring _NeverSet exactly as NewRecord()'s adoption path does, so the ReadOnly mirror stays writable for the rest of the lifecycle.

      Everything else is deliberately UNTOUCHED: field routing still sends parent-held values to the (now loaded) parent, permissions and validation run at every level, and EnforceDisjointSubtype still refuses a second subtype where the parent forbids overlap. If loading the parent discovers an existing child of ANOTHER subtype, the chain save is unaffected — parent saves run with IsParentEntitySave, which bypasses leaf delegation.

      Call AFTER NewRecord() and BEFORE Save():

      const applicant = await md.GetEntityObject<ApplicantEntity>('Applicants', contextUser);
      applicant.NewRecord();
      if (!await applicant.AttachToParent(CompositeKey.FromID(personId))) {
      // no such parent row — decide whether to create a fresh chain instead
      }
      applicant.Set('CompanyID', companyId); // child-held fields as usual
      await applicant.Save(); // Person UPDATEd, Applicant INSERTed, one transaction

      Parameters

      • parentKey: CompositeKey

        Primary key of the EXISTING parent row to promote.

      Returns Promise<boolean>

      true when the parent loaded and this record is now bound to it; false when no parent row exists under that key (this record is left exactly as it was — still a fresh chain — so the caller can choose to save it as one).

      When this entity is not an IS-A child type, or has already been saved — promotion is a decision about what a NEW record IS, not an edit to an existing one.

    • Bind this instance to a provider after construction.

      Rule (ORM, not just metadata-sync): every DB read and write on this instance — Save, Load, Delete, RunView, GetEntityObject of children/embeds, lookups, RecordGeoCode — MUST use this provider. Mixing another provider (especially the process-wide host) into the same record graph is a deadlock: a child FK waits on an uncommitted parent on another connection.

      ProviderBase.GetEntityObject always calls this so a subclass that declares constructor(Entity: EntityInfo) and drops the second ClassFactory argument cannot silently run on the global host.

      Parameters

      Returns void

    • Builds the ordered unit of work for deleting this record and everything its companions contribute.

      Companions contribute first: children hold foreign keys pointing at the row that is about to disappear, so they must be removed before it.

      Returns EntitySavePlan

      The plan.

    • Builds the ordered unit of work for saving this record and everything its companions contribute.

      The root node comes first — children need the parent's primary key, and on a create it does not exist until the parent row is inserted.

      Parameters

      • OptionalincludeRoot: boolean

        Whether to include this record's own save. False when the caller has already persisted the root by other means.

      • OptionalsaveOptions: EntitySaveOptions

        The caller's save options, forwarded to each companion so it can honor flags that change what counts as work (IgnoreDirtyState, most importantly — a companion that skips clean children must not skip them when the caller demanded a full write-out).

      Returns EntitySavePlan

      The plan. A NodeCount of 1 means there is no graph and the caller should take the ordinary single-record path.

    • Cascade-deletes an IS-A child record when the parent entity has CascadeDeletes enabled. Loads the child entity, then deletes it through the normal IS-A chain. The child's delete will cascade further down if it also has children and CascadeDeletes.

      Parameters

      • childCheck: { ChildEntityName: string; HasChildren: boolean }
      • parentOptions: EntityDeleteOptions

      Returns Promise<boolean>

    • Field-level security on the write path: rejects a save that modifies a field this user has no update permission on.

      ENFORCEMENT LAYER — read this before treating it as the security boundary. BaseEntity also runs in the browser, where this guard is trivially bypassable. The AUTHORITATIVE check is the server-side execution of this same code: the MJServer mutation resolver re-instantiates the entity and re-runs Save on the server, where the client cannot reach it. The client-side occurrence is UX and defense-in-depth — fail fast with a clear message before a network round-trip — and must never be relied on alone.

      UPDATE rejects; CREATE does not — see ApplyFieldLevelCreateSuppression.

      Note this checks DIRTY fields only. CLIENT-side that is safe on its own: nothing ever nulls a restricted value in memory, so a field the user cannot see was never loaded as null, is not dirty, and an unrelated edit saves cleanly with the restricted column keeping its stored value.

      SERVER-side, dirty-only is safe only because ResolverBase.UpdateRecord guarantees the entity was hydrated FROM THE DATABASE on every FLS entity. Two distinct resolver behaviours carry that premise, and BOTH are load-bearing:

      1. StripDeniedReadFieldsFromClientInput removes client-sent values for fields the caller cannot READ, which SetMany would otherwise make genuinely dirty with fabricated data.
      2. entityInfo.EnableFieldLevelSecurity forces the truth-load branch, so the entity's non-dirty baseline is the real stored row rather than the client's OldValues___.

      (2) is not redundant with (1). A value arriving through LoadFromData is recorded by the EntityField setter as the field's INITIAL value, so it is not dirty — and this check would never see it, while GenerateSaveSQL sends it anyway (it filters on NotLoaded, never on Dirty). Without the forced truth-load, a caller with Read Allow + Update Deny — the canonical FLS configuration, and one that leaves (1) with nothing to strip — could write an update-denied field just by pinning its value in OldValues___ and never naming it in the mutation. If you are considering relaxing that branch condition, this check is what breaks.

      The refusal names the missing permission when the caller can READ the field, and falls back to the ambiguous "does not exist or you do not have access" wording when they cannot. See FieldSecurityWriteDenialMessage for why that split discloses nothing.

      Returns void

    • Checks if this entity has any child records in IS-A child entity tables. Used for parent delete protection — a parent record cannot be deleted while child type records referencing it still exist.

      Returns Promise<{ ChildEntityName: string; HasChildren: boolean }>

      Object with HasChildren flag and the name of the child entity found

    • Clears any pending restore context. Safe to call when no context is set. Recommended after Save() returns so a subsequent ordinary save isn't accidentally tagged as a restore.

      Returns void

    • This method MUST be called right after the class is instantiated to provide an async/await pair for any asynchronous operations a given entity needs to do when it is first created/configured. When you call Metadata/Provider GetEntityObject() this is done automatically for you. In nearly all cases you should go through GetEntityObject() anyway and not ever directly instantiate a BaseEntity derived class.

      Parameters

      Returns Promise<void>

    • Builds a related entity the way GetEntityObject does, minus NewRecord / Load. Used by EmbeddedRecord so construction can thread a cycle-detection set.

      Type Parameters

      • T extends BaseEntity<unknown>

        The entity type to construct.

      Parameters

      • entityName: string

        Metadata entity name.

      • visited: Set<string>

        Cycle guard, forwarded into the new instance's own embeddeds.

      Returns Promise<T>

    • This method will copy the values from the other entity object into the current one. This is useful for things like cloning a record. This method will ONLY copy values for fields that exist in the current entity object. If the other object has fields that don't exist in the current object, they will be ignored.

      Parameters

      • other: BaseEntity

        the other entity object to copy values from

      • OptionalincludePrimaryKeys: boolean

        if true, the primary keys will be copied as well, if false, they will be ignored, defaults to false and generally you want to leave it that way

      • OptionalreplaceOldValues: boolean

        if true, the old values of the fields will be reset to the values provided in the other parameter, if false, they will be left alone, defaults to false and generally you want to leave it that way

      Returns boolean

    • Declares a typed child collection on this entity and registers it as a companion.

      This is the entry point for composite entities. Call it from a field initialiser on a shared (client + server) subclass so both tiers see the collection — a declaration that exists only in a server-side class makes the collection invisible to the browser, which is exactly the limitation this feature removes.

      Type Parameters

      Parameters

      Returns RelatedRecordCollection<TChild>

      The registered collection.

      public readonly Lines = this.DeclareRelatedRecords<OrderLineEntity>({
      Name: 'Lines',
      ChildEntity: 'MJ_BizApps_Orders: Order Lines',
      ForeignKey: 'OrderHeaderID',
      OrderBy: 'LineNumber ASC',
      Sequence: { Field: 'LineNumber', From: 1 },
      });
    • In the BaseEntity class this method is not implemented. This method shoudl be implemented only in server-side sub-classes only by calling AIEngine or other methods to generate embeddings for a given piece of text provided. Subclasses that override this method to implement embedding support should also override

      Parameters

      • textToEmbed: string

      Returns Promise<SimpleEmbeddingResult>

      SupportsEmbedTextLocal and return true

    • Enforces disjoint subtype constraint during IS-A child entity creation. A parent record can only be ONE child type at a time. Checks all sibling child types (excluding self) for records with the same PK value. Throws if a sibling child record is found.

      Only called when the parent entity has AllowMultipleSubtypes = false (default). When AllowMultipleSubtypes = true, this check is skipped entirely, allowing overlapping subtypes (e.g., a Person can be both a Member and a Volunteer).

      Only runs on Database providers — client-side (Network/GraphQL) skips this because the server-side save will perform the check authoritatively.

      Returns Promise<void>

    • Returns a promise that resolves when the current Delete operation completes. If no Delete operation is in progress, resolves immediately.

      This is useful when you need to ensure a record is deleted before performing cleanup operations or navigating away from a view.

      Returns Promise<void>

      // Ensure any in-progress delete is complete before proceeding
      await entity.EnsureDeleteComplete();
      // Now safe to navigate away or perform cleanup
      navigateToList();
    • Create-safe prospective counterpart to InitializeChildEntity. Unlike createAndLinkChildEntity, does NOT unlink when InnerLoad finds no row — that is the create case. Idempotent. Defaults to ResolveSubtypeEntityName() when no name is passed.

      Parameters

      • OptionalentityName: string

        Optional explicit child entity name. If omitted, resolved via ResolveSubtypeEntityName().

      Returns Promise<BaseEntity<unknown>>

      The linked child BaseEntity, or null if no subtype applies.

    • Returns a promise that resolves when the current Load operation completes. If no Load operation is in progress, resolves immediately.

      This is useful when you need to ensure data is loaded before accessing entity properties or performing operations that depend on loaded data.

      Returns Promise<void>

      // Ensure any in-progress load is complete before proceeding
      await entity.EnsureLoadComplete();
      // Now safe to access entity data
      console.log(entity.Name);
    • Returns a promise that resolves when the current Save operation completes. If no Save operation is in progress, resolves immediately.

      This is useful when you need to ensure data is persisted before performing a dependent operation, or when coordinating between multiple components that might trigger saves.

      Returns Promise<void>

      // Ensure any in-progress save is complete before proceeding
      await entity.EnsureSaveComplete();
      // Now safe to perform operations that depend on the saved state
      await someOperationThatNeedsSavedData(entity);
    • True when any of the named fields exists on this entity and its current value differs from the last loaded or saved value.

      This is the boolean form of GetFieldByName(name)?.Dirty === true. Prefer it at call sites that only care whether a column has been edited — pricing, validation, and "did the user type this" gates — so they do not repeat the optional-chain and do not treat a missing field as a distinct third state.

      Semantics:

      • Unknown or blank names return false. They are not dirty; they are absent. Callers that must distinguish "no such field" from "field is clean" should use GetFieldByName and inspect the result.
      • Names are case-insensitive and trimmed, matching GetFieldByName.
      • Read-only fields are never dirty, even if their value was overwritten internally.
      • Multiple names are OR'd. FieldIsDirty('UnitPrice', 'ProductPriceID') is true if either field has been edited. An empty rest list is a single-field check.

      Parameters

      • fieldName: string

        First field to test. A missing/blank name contributes false.

      • ...more: string[]

        Additional field names, each OR'd with the first.

      Returns boolean

      true if at least one named field exists and is dirty; otherwise false.

      // Single field
      if (line.FieldIsDirty('UnitPrice')) { ... }

      // Either money column was edited
      if (line.FieldIsDirty('UnitPrice', 'ProductPriceID')) { ... }
    • Strongly-typed wrapper for the SetMany method.

      Type Parameters

      • K extends AnyZodObject

      Parameters

      • data: unknown
      • Optionalschema: TypeOf<K>

        the zod schema to validate the data against

      Returns boolean

      data - the data to set on the entity object

    • Generates a vector embedding for a single text field using AI engine. Only generates embeddings for new records or when the source field has changed. Stores both the vector embedding and the model ID used to generate it.

      Parameters

      • field: EntityField

        The EntityField containing the text to embed

      • vectorField: EntityField

        The EntityField to store the generated vector embedding (as JSON string)

      • modelField: EntityField

        The EntityField to store the ID of the AI model used

      Returns Promise<boolean>

      Promise that resolves to true if embedding was generated successfully, false otherwise

    • Generates a vector embedding for a single text field identified by field name. Retrieves the field objects and delegates to GenerateEmbedding method.

      Parameters

      • fieldName: string

        Name of the text field to generate embedding from

      • vectorFieldName: string

        Name of the field to store the vector embedding

      • modelFieldName: string

        Name of the field to store the model ID used for embedding

      Returns Promise<boolean>

      Promise that resolves to true if embedding was generated successfully, false otherwise

    • Generates vector embeddings for multiple text fields using EntityField objects. Processes fields in parallel for better performance.

      Parameters

      • fields: { field: EntityField; modelField: EntityField; vectorField: EntityField }[]

        Array of field configurations with EntityField objects for source, vector, and model fields

      Returns Promise<boolean>

      Promise that resolves to true if all embeddings were generated successfully, false if any failed

    • Generates vector embeddings for multiple text fields by their field names. Processes fields in parallel for better performance.

      Parameters

      • fields: { fieldName: string; modelFieldName: string; vectorFieldName: string }[]

        Array of field configurations specifying source text field, target vector field, and model ID field names

      Returns Promise<boolean>

      Promise that resolves to true if all embeddings were generated successfully, false if any failed

    • Parameters

      • FieldName: string

      Returns any

    • NOTE: Do not call this method directly. Use the To method instead

      Utility method to create an object and return it with properties in the newly created and returned object for each field in the entity object. This is useful for scenarios where you need to be able to persist the data in a format to send to a network call, save to a file or database, etc. This method will return an object with properties that match the field names of the entity object.

      Parameters

      • OptionaloldValues: boolean

        When set to true, the old values of the fields will be returned instead of the current values.

      • OptionalonlyDirtyFields: boolean

        When set to true, only the fields that are dirty will be returned.

      Returns any

    • Retrieves all ancestor records in the hierarchy from the top-level root down to this record using a single RunView query.

      Type Parameters

      Parameters

      • OptionalparentFieldName: string

        Optional recursive foreign key field name (defaults to 'ParentID' or the first recursive FK found).

      Returns Promise<T[]>

      Array of ancestor entity instances ordered from root down to parent.

    • Returns a partial object that contains only the fields that have changed since the last time the record was saved. This is useful for scenarios where you want to send only the changes to the server or to a client. It is also helpful for quickly finding the fields that are "dirty".

      Returns Partial<T>

    • This utility method generates a completely new object that has properties that map to the fields and values in the entity at the time it is called. It is a copy, NOT a link, so any changes made to the object after calling this method will NOT be reflected in the object that is returned. This is useful for things like sending data to a client, or for use in a view model.

      Parameters

      Returns Promise<any>

    • This utility method calls GetDataObject() internally and formats the result as a JSON string. If you want to get the data as an object instead of a string, call GetDataObject() directly.

      Parameters

      Returns Promise<string>

    • Convenience method to access a field by name. This method is case-insensitive and will return null if the field is not found. You can do the same thing with more fine tune controlled by accessing the Fields property directly.

      Parameters

      • fieldName: string

      Returns EntityField

    • Utility method to return the Name of the record (the value of the column that comes back from EntityInfo.NameField) from the current object. This avoids needing a network round trip to get the record name whenever we have the object already loaded in memory.

      Returns any

    • Resolves the recursive foreign key field for this entity. If parentFieldName is provided, finds that specific field. Otherwise defaults to 'ParentID' if present, or the first self-referencing foreign key field found on the entity.

      Parameters

      • OptionalparentFieldName: string

      Returns EntityFieldInfo

    • Resets this entity to a pristine state and populates it from the provided data object.

      Unlike SetMany, which incrementally updates existing field values, Hydrate() first resets ALL internal state — fields, composite key cache, loaded/saved flags — then populates from the provided data as if loading a fresh record from the database.

      This is critical for IS-A (table-per-type) inheritance: when a child entity loads its record, parent entities in the chain must be fully reset and re-populated from the child's view data, including the shared primary key. After init(), each EntityField's _NeverSet flag is true, allowing even ReadOnly PK fields to be set exactly once via SetMany.

      After population, entities are automatically marked as saved/loaded when all PK values are present (via UpdateSavedStateFromPrimaryKeys).

      The parent chain is handled recursively: if this entity has an IS-A parent, the parent is hydrated first (deepest ancestor first). Each level only receives the fields it owns — a child's view row is the union of every ancestor plus its own columns, and passing that whole row to the parent used to trip WarningManager ("fields were not found in entity definitions") for every child-only column. That is how loading Accounting Company Profiles as entity objects produced a MJ: Companies missing-field dump at MJAPI boot.

      Parameters

      • data: Record<string, unknown>

        A plain object whose properties map to field names on this entity (and potentially parent entities in the IS-A chain).

      Returns void

    • Discovers and initializes the IS-A child entity for a loaded record.

      After a record is loaded, this method checks whether a more-derived child entity record exists with the same primary key. If found, it creates the child entity instance, shares the current instance chain (so child._parentEntity === this), and recursively discovers further children down the hierarchy.

      This ensures that Save/Delete operations always delegate to the leaf entity, running the full validation and event chain at every level.

      Must be called AFTER a record is loaded (PK must be available). Skipped for entities that are not parent types or have already been discovered.

      Returns Promise<void>

    • Constructs every declared embedded peer without NewRecord or Load. Called from GetEntityObject after InitializeParentEntity.

      Parameters

      • Optionalvisited: Set<string>

        Entity names already being constructed (cycle guard).

      Returns Promise<void>

    • Initializes the IS-A parent entity composition chain. For child type entities, this creates the parent entity instance (and recursively its parent, etc.) and caches the parent field name set for routing.

      Must be called AFTER EntityInfo is available but BEFORE any Load/NewRecord/Set/Get. This is called by Metadata.GetEntityObject() after constructing the entity.

      Returns Promise<void>

      • This method loads a single record from the database. Make sure you first get the correct BaseEntity sub-class for your entity by calling Metadata.GetEntityObject() first. From there, you can call this method to load your records.
      • NOTE: You should not be calling this method directly from outside of a sub-class in most cases. You will use the auto-generated sub-classes that have overriden versions of this method that blow out the primary keys into individual parameters. This is much easier to program against.

      Parameters

      • CompositeKey: CompositeKey

        Wrapper that holds an array of objects that contain the field name and value for the primary key of the record you want to load. For example, if you have a table called "Customers" with a primary key of "ID", you would pass in an array with a single object like this: {FieldName: "ID", Value: 1234}. *If you had a composite primary key, you would pass in an array with multiple objects, one for each field in the primary key. You may ONLY pass in the primary key fields, no other fields are allowed.

      • OptionalEntityRelationshipsToLoad: string[]

        Optional, you can specify the names of the relationships to load up. This is an expensive operation as it loads up an array of the related entity objects for the main record, so use it sparingly.

      Returns Promise<boolean>

      true if success, false otherwise

    • Loads the MJ: Entity Field Permissions record from the database

      Parameters

      • ID: string
      • OptionalEntityRelationshipsToLoad: string[]

        (optional) the relationships to load

      Returns Promise<boolean>

      • true if successful, false otherwise

      MJEntityFieldPermissionEntity

    • Loads entity data from a plain object, typically from database query results.

      This method is meant to be used only in situations where you are sure that the data you are loading is current in the database. MAKE SURE YOU ARE PASSING IN ALL FIELDS. The Dirty flags and other internal state will assume what is loading from the data parameter you pass in is equivalent to what is in the database.

      Parameters

      • data: any

        A simple object that has properties that match the field names of the entity object

      • Optional_replaceOldValues: boolean

      Returns Promise<boolean>

      Promise - Returns true if the load was successful

      Generally speaking, you should use Load() instead of this method. The main use cases where this makes sense are:

      1. On the server if you are pulling data you know is fresh from the result of another DB operation
      2. If on any tier you run a fresh RunView result that gives you data from the database
      3. When the RunView Object RunView() method is called with ResultType='entity_object'

      Important for Subclasses: As of v2.53.0, this method is now async to support subclasses that need to perform additional asynchronous loading operations (e.g., loading related data, fetching additional metadata).

      Subclasses that need to perform additional loading should override BOTH this method AND Load() to ensure consistent behavior regardless of how the entity is populated. This is because these two methods have different execution paths:

      • Load() fetches data from the network/database and then calls provider-specific loading
      • LoadFromData() is called when data is already available (e.g., from RunView results)
      // Subclass implementation
      public override async LoadFromData(data: any, replaceOldValues: boolean = false): Promise<boolean> {
      const result = await super.LoadFromData(data, replaceOldValues);
      if (result) {
      // Perform additional async loading here
      await this.LoadRelatedData();
      await this.LoadMetadata();
      }
      return result;
      }

      // Don't forget to also override Load() for consistency, unless you INTEND to have different behavior
      // for Load() vs LoadFromData()
      public override async Load(ID: string, EntityRelationshipsToLoad: string[] = null): Promise<boolean> {
      const result = await super.Load(ID, EntityRelationshipsToLoad);
      if (result) {
      // Same additional loading as in LoadFromData
      await this.LoadRelatedData();
      await this.LoadMetadata();
      }
      return result;
      }
    • Populates this record's declared related-record collections and resolves once they are all ready — the one call to await when you want a fully-hydrated record.

      The point is batching. Cache-sourced collections resolve synchronously against BaseEngineRegistry and cost nothing; every database-sourced collection is gathered into a single RunViews call rather than one RunView each. So a record with four declared collections costs one round trip, or zero when they all read from engine caches — instead of the four sequential queries a naive for (…) await c.Load() would issue.

      Collections declared 'never' are skipped: that mode means write-only staging buffer.

      Parameters

      • ...names: string[]

        Collection names to load. Omit to load every declared collection.

      Returns Promise<void>

      await action.LoadRelatedRecords();              // Params, ResultCodes and Libraries, one trip
      await agent.LoadRelatedRecords('Prompts'); // just the one
    • This method will create a new state for the object that is equivalent to a new record including default values.

      Parameters

      • OptionalnewValues: FieldValueCollection

        optional parameter to set the values of the fields to something other than the default values. The expected parameter is an object that has properties that map to field names in this entity. This is the same as creating a NewRecord and then using SetMany(), but it is a convenience/helper approach.

      Returns boolean

    • Used for raising events within the BaseEntity and can be used by sub-classes to raise events that are specific to the entity.

      Parameters

      • type:
            | "delete"
            | "save"
            | "new_record"
            | "load_complete"
            | "transaction_ready"
            | "save_started"
            | "delete_started"
            | "load_started"
            | "remote-invalidate"
            | "graph_save_started"
            | "graph_save"
            | "other"
      • payload: any
      • OptionalsaveSubType: "create" | "update"

      Returns void

    • Raises the transaction_ready event. This is used to indicate that the entity object is ready to be submitted for transaction processing. This is used by the TransactionGroup class to know when all async preprocessing is done and it can submit the transaction. This is an internal method and shouldn't be used by sub-classes or external callers in most cases. It is primarily used by Provider classes who are handling the tier-specific processing for the entity object.

      Returns void

    • Re-fetches the current record from the database using its existing primary key, replacing all in-memory field values with the latest data from the database. This is useful when you know (or suspect) the record has been modified externally (e.g., by a trigger, another user, or a background process) and you want to bring the entity object up to date.

      Returns Promise<boolean>

      true if the record was successfully reloaded, false if the provider returned no data.

      • The entity must have been previously loaded or saved (i.e., it must have a valid PrimaryKey). Calling Refresh() on a new, unsaved entity will throw because the primary key is not yet valid.
      • After a successful refresh, all field dirty flags are reset — the entity will report Dirty === false.
      • This is equivalent to calling InnerLoad(this.PrimaryKey).
      • If you only need to discard unsaved in-memory changes (without a database round-trip), use Revert instead.

      If the entity has no provider set, the primary key is invalid, or the user lacks Read permission.

    • Registers a companion on this entity. Called from a subclass constructor or field initialiser, normally via DeclareRelatedRecords.

      Type Parameters

      Parameters

      Returns TCompanion

      The same companion, so it can be assigned to a readonly field in one expression.

      When a companion with the same name is already registered — a duplicate name would make the wire payload ambiguous and silently drop one of the two.

    • This method can be used to register a callback for events that will be raised by the instance of the BaseEntity object. The callback will be called with a BaseEntityEvent object that contains the type of event and any payload that is associated with the event. Subclasses of the BaseEntity can define their own event types and payloads as needed.

      Parameters

      Returns Subscription

    • Append a result to _resultHistory, trimming the oldest entries when over MAX_RESULT_HISTORY. All Save/Delete code paths route through this — both inside BaseEntity and in callers like databaseProviderBase and entity subclasses that record their own results.

      Parameters

      Returns void

    • If the entity object has a TransactionGroup associated with it, the TransactionGroup will be notified that we are doing some transaction pre-processing so that the TransactionGroup can properly wait for those pre-processing steps to complete before submitting the transaction. This method should generally NOT be called by anyone other than a provider that is handling the tier-specific processing for the entity object.

      Returns void

    • Prospective counterpart to FindISAChildEntity. Evaluates which IsA child subtype entity this record should have based on:

      1. Registered EntitySubtypeResolver (ClassFactory key = entity name)
      2. Entity.SubtypeSelector declarative FK traversal path
      3. Unconditional single-child IsA fallback (ChildEntities.length === 1)
      4. Otherwise null (no subtype)

      Returns Promise<string>

      plans/sync-composition-axes.md

    • This method will revert the internal state of the object back to what it was when it was last saved, or if never saved, from when it was intially loaded from the database. This is useful if you want to offer a user an "undo" type of feature in a UI.

      Returns boolean

    • Refuses an EDIT that would strip the MJ system user's last Allow on a field.

      Not in Validate() for two reasons. It needs the field's rules as they stand in the DATABASE — loaded metadata lags recent writes, and reading a stale sibling row as Allow is exactly how three individually-innocent No Access edits get through one at a time. And loading them is asynchronous, which Validate() is not.

      Inserts are deliberately not checked: adding a rule can only add access, never remove an existing Allow, so the Deny check in Validate() covers them completely. It has to — snapshot initialization writes its rows one at a time, and an aggregate check would refuse the half-built state.

      Parameters

      Returns Promise<boolean>

    • Sets the value of a given field. If the field doesn't exist, nothing happens. The field's type is used to convert the value to the appropriate type.

      For IS-A child entities, parent fields are routed to _parentEntity.Set() (recursive for N-level chains). The value is also mirrored on the child's own virtual EntityField so that code iterating entity.Fields still sees it. The authoritative state for parent fields lives on _parentEntity.

      Parameters

      • FieldName: string
      • Value: any

      Returns void

    • Seeds the embed-load cycle set for a nested InnerLoad. Called by EmbeddedRecord.LoadEager so inherit walks share one entityName:PK path and a self-parented row fails cleanly instead of recursing forever.

      Parameters

      • visited: Set<string>

      Returns void

    • NOTE: Do not call this method directly. Use the From method instead

      Sets any number of values on the entity object from the object passed in. The properties of the object being passed in must either match the field name (in most cases) or the CodeName (which is only different from field name if field name has spaces in it)

      For IS-A child entities, all fields are first set on self (including parent fields as mirrors), then parent fields are extracted and forwarded to _parentEntity.SetMany() for authoritative state, including proper OldValue tracking via the replaceOldValues parameter.

      Parameters

      • object: any
      • OptionalignoreNonExistentFields: boolean

        if set to true, fields that don't exist on the entity object will be ignored, if false, an error will be thrown if a field doesn't exist

      • OptionalreplaceOldValues: boolean

        if set to true, the old values of the fields will be reset to the values provided in the object parameter, if false, they will be left alone

      • OptionalignoreActiveStatusAssertions: boolean

        if set to true, the active status assertions for the fields will be ignored, if false, an error will be thrown if a field is not active. Defaults to false.

      Returns void

    • Marks the next Save() as a restore from a historical RecordChange row.

      The provider will write a new RecordChange entry with Source='Restore', RestoredFromID pointing at sourceChangeId, and RestoreReason set to reason (or NULL). This produces an auditable lineage chain that the timeline UI can render via the RestoredFromID foreign key.

      The context is consumed exactly once per Save() and persists on the entity until either (a) overwritten by a subsequent SetRestoreContext() call or (b) explicitly cleared via ClearRestoreContext(). It is NOT auto-cleared inside Save() because TransactionGroup execution is deferred — see the comment on _restoreContext for details.

      Parameters

      • sourceChangeId: string

        The ID of the historical RecordChange row whose state is being restored. Required; throws if empty.

      • Optionalreason: string

        Optional user-entered explanation captured at restore time. Persisted to RecordChange.RestoreReason for audit purposes.

      Returns void

      record.SetRestoreContext(versionId, 'Reverting incorrect Q2 entries');
      const ok = await record.Save();
      record.ClearRestoreContext();
    • Specifies if the current object supports the

      Returns boolean

      EmbedTextLocal method or not - useful to know before calling it for conditional code that has fallbacks as needed. BaseEntity does not implement this method but server-side sub-classes often do, but it is not mandatory for any sub-class.

    • Strongly-typed wrapper for the GetAll method

      Type Parameters

      • K extends AnyZodObject

      Parameters

      • Optionalschema: K

        the zod schema to validate the data against

      Returns TypeOf<K>

    • Asynchronous validation method that can be overridden by subclasses to add custom async validation logic. This method is automatically called by Save() AFTER the synchronous Validate() passes.

      IMPORTANT:

      1. This should NEVER be called INSTEAD of the synchronous Validate() method
      2. This is meant to be overridden by subclasses that need to perform async validations
      3. The base implementation just returns success - no actual validation is performed
      4. Overriding this method is what turns it on. You do NOT also have to override DefaultSkipAsyncValidation — that getter is for stating a policy explicitly, and an explicit override of it (either value) still wins. To suppress async validation for one call, pass SkipAsyncValidation: true in the save options.

      Point 4 used to be the opposite, and it was not discoverable: DefaultSkipAsyncValidation defaults to true, so an override written against this docstring alone never ran. It reads as enforced, reviews as enforced, and was not — the failure mode that let an order confirm with no lines in production.

      Subclasses should override this to add complex validations that require database queries or other async operations that cannot be performed in the synchronous Validate() method.

      Returns Promise<ValidationResult>

      Promise A promise that resolves to the validation result

    • Why this role may not carry a field rule on this entity, or null when it may.

      A field permission REFINES an entity permission — the entity gate decides whether you reach the record at all, and field rules then decide which columns of it you see. A rule bound to a role that has no relationship to the entity is not a refinement of anything, and it is the configuration that made the reconciler's orphan test ambiguous: such a row is fully live at runtime (aggregation matches on role membership alone) while looking inert to any check that asks what the role can do on its own.

      Requires only that an entity-permission row EXISTS, not that it grants read. A role whose entity permission grants nothing is the ordinary way to express a deny-only carve-out — "these users are normal, minus this column" — and demanding a grant would force an administrator to hand out entity access in order to take a column away. Deleting the entity permission removes the relationship, and reconciliation then cleans up the field rules with it; see computeOrphanRowIDs, which tests exactly this condition.

      Attributed to RoleID because that is the value the administrator must change — either pick a role that has entity access, or grant this one an entity permission first.

      Parameters

      Returns string

    • Resolves the leaf (most-derived) entity type for a given parent entity record. Walks down the IS-A child hierarchy to find which child type a record belongs to. Returns the child entity name, or the parent's own name if no children exist. Useful for polymorphic operations where you have a parent record and need to know its actual leaf type.

      Parameters

      • entityName: string

        The parent entity name

      • primaryKey: CompositeKey

        The primary key to look up

      • OptionalcontextUser: UserInfo

        Optional context user for server-side operations

      • Optionalprovider: IMetadataProvider

      Returns Promise<{ IsLeaf: boolean; LeafEntityName: string }>

      The leaf entity name and whether it was resolved to a child type

    • Why this rule may not target this role, or null when it may.

      Refuses a restricting rule aimed at a role the MJ system user holds. The system user is what the server runs background work as: it pre-warms the shared engine caches at startup, and in task mode (job and agent runners) whichever caller touches an engine first configures it for the whole process. Restricting that account does not just restrict it — engines cache their data process-wide, so a partially loaded engine would then serve incomplete records to every user afterward. The damage is silent and nowhere near the rule that caused it.

      Only a Deny is refused. Field security has no runtime exemption for any user, so the system user's own access comes from ordinary rows: snapshot initialization writes it Allow on every field its roles can read, and this guard is what stops that access being taken away again. Allow and No Access both save — Allow is the grant the server depends on, and No Access is neutral, unable to reduce access another role has granted. Refusing those would make it impossible to enable field security on any entity at all, since the standard roles (UI, Developer, Integration) carry entity permissions almost everywhere.

      This is a guard on CONFIGURATION, not a runtime exemption. What is refused is the arrangement that would make the server unable to do its own work. Take the role off the system user and the rule saves.

      The database tier already refuses the equivalent arrangement: CodeGen skips a column DENY for any role a service login belongs to, and warns. This is the same rule for the application tier.

      Parameters

      • roleID: string

        the role the rule targets

      • Optionalrule: FieldPermissionRuleVerbs

        the rule's three verbs; omitted only by callers that are pre-checking a role rather than a specific rule, which are answered as though the rule denied

      Returns string

    • Why this rule's Update/Create verbs may not target this field, or null when they may.

      A read-only field cannot be written through the API by anyone: it is excluded from the generated create input type and from the update SET list, and BaseEntity never marks it dirty. So an Update or Create verb on it is inert in both directions — a Deny prevents nothing that was possible, and an Allow grants nothing that was not. Left to save, it reads on screen as a working permission and silently is not one.

      Read is untouched, deliberately. Restricting READ on a read-only field is legitimate and is one of the main things administrators want: foreign-key display columns are read-only, and "hide which client this contract belongs to" is exactly a read restriction on one. Only the two write verbs are refused.

      Note EntityFieldInfo.ReadOnly is the right predicate here, not IsVirtual: IS-A parent fields are virtual but ARE writable through the child's save chain, and ReadOnly is defined off AllowUpdateAPI precisely to tell those apart from joined display columns.

      Returns string