TypeScript Debugging and Observability
Attach SQLExecutionEvidenceStore only to a server-created SQL client. Its
entries contain trusted parameters, so project them through the
safeSQLEvidence(...) helper from generated Debug Assist before exposing any
diagnostic result.
const store = new SQLExecutionEvidenceStore();
client.setRuntimeTelemetrySink(store);
store.enableSelect();
const rows = await Q.schools()
.comment("Diagnose the school search")
.purpose("Verify filters, facets, and relation loading")
.executeForList(context);
const safe = safeSQLEvidence(store.snapshot());
Use enableAll(), enableSelect(), enableMutation(), and disable(); mode
changes clear old entries. The default TextDiagnosticSQLLogSink is
operator-only. Replace it with setDiagnosticSQLLogSink(...) or remove it by
passing undefined. Query and mutation logging can be disabled independently
with setQueryLoggingEnabled(false) and
setMutationLoggingEnabled(false).
Use TypeScript advanced data operations for the
Facet, aggregate, deep relation, Top-N, and audited save requests. Correlate
tracePath and metric aliases with safe SQL timing/count evidence. Keep
debugSQL and parameters out of errors, browser responses, and telemetry.
setAuditSink(...) delivers application audit events independently from
RuntimeTelemetry. Install OpenTelemetry with
dataService.setRuntimeTelemetry(telemetry) and configure the TFP client the
same way when used.
Tenant qualification: the current composition API stores requestPolicy in
UserContext, but core prepareQuery() does not automatically consume that
resource. Enforce tenant scope in the trusted server adapter or custom data
service, reject governance keys from payloads, and retain negative tests for
Query, Facet, aggregate, relation, Mutation, and federation paths.
Finish with the shared checklist.