(
row: DispatchSubscription,
event: P,
): P | null {
// Asked of every delivery, so the families that can never answer are
// turned away on a token comparison rather than a subject parse.
if (!isKvToken(row.token)) return event;
const handle = kvHandleFromSubject(row.subject);
if (handle === null) return event;
const key = relativeToKvShareRoot(
row.permission,
(event as ProjectedKvEvent).key,
);
if (key === null) return null;
return { ...event, subject: `kv:${handle}:${key}`, key };
}
/** Op filter first — a comparison, where the glob is not. */
#passes(
row: DispatchSubscription,
subject: MatchSpec,
op: SubjectOp,
matchOn: string,
context: EventContextBase,
): boolean {
if (row.op !== null && row.op !== op) return false;
if (!row.match) return true;
const matcher = this.#matcherFor(row, subject.matchSeparator);
return matchScopesFor(row, context, matchOn).some(
([anchorPath, target]) => {
const scoped = subject.matchScope(anchorPath, target);
return scoped !== null && matcher.test(scoped);
},
);
}
/**
* Re-run each surviving row's access against the node the event is about,
* not against its anchor: a filter that reaches into something the holder
* cannot list must not deliver from it, and a share revoked after the
* subscription was made must stop delivering at once rather than when the
* row is next touched.
*
* Last of the filters, because it is the only one that can cost a lookup.
* Two layers keep that lookup rare: the cross-event cache, keyed by the
* permission cache's own generation, answers a subscription being written
* to repeatedly without asking anything; and within one event, rows sharing
* an identity and a grant share one decision — which is what a fan-out over
* one folder is.
*/
async #stillAuthorized(
rows: DispatchSubscription[],
context: FsEventContext,
): Promise