Function: createTableDecisionSink()
function createTableDecisionSink(options?: AccessRepositoriesOptions): OnDecision;Defined in: server/access/table-decision-sink.ts:35
Opt-in, table-backed onDecision adapter. Wires the consumer-facing audit
hook to the shipped rbac_decision_log table (via DecisionLogRepository)
in one line:
createAccessServices({
getActorId,
audit: "sensitive",
onDecision: createTableDecisionSink(),
});The default audit boundary remains the no-op hook — passing this sink is what
turns on table persistence. It is fire-and-forget: each
qualifying decision is appended through the ambient transaction machinery
(joining an existing transaction when present), and any write failure
is swallowed here (in addition to AccessService wrapping the hook), so a
hook rejection cannot alter a returned can() decision. A SQL failure can
still abort a shared outer transaction; this adapter provides no savepoint
or independent durable commit.
Consumers wanting their own store (different DB, queue, retention, PII
redaction) skip this and pass their own onDecision instead.
Parameters
| Parameter | Type |
|---|---|
options | AccessRepositoriesOptions |