<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Philip Z</title>
    <description>The latest articles on DEV Community by Philip Z (@philipgreat).</description>
    <link>https://dev.to/philipgreat</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3386383%2F6897ef7c-c8f5-44c0-b6cc-4f4dc2409193.png</url>
      <title>DEV Community: Philip Z</title>
      <link>https://dev.to/philipgreat</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/philipgreat"/>
    <language>en</language>
    <item>
      <title>Stop Giving Your AI Agent Raw SQL</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Wed, 30 Sep 2026 15:15:57 +0000</pubDate>
      <link>https://dev.to/philipgreat/stop-giving-your-ai-agent-raw-sql-1h4l</link>
      <guid>https://dev.to/philipgreat/stop-giving-your-ai-agent-raw-sql-1h4l</guid>
      <description>&lt;p&gt;The fastest way to connect an AI agent to application data is often a generic&lt;br&gt;
SQL tool. Give the model a schema, accept a SQL string, run it, and return the&lt;br&gt;
rows.&lt;/p&gt;

&lt;p&gt;That is also where a prototype can quietly become a production security and&lt;br&gt;
maintenance problem.&lt;/p&gt;

&lt;p&gt;The model must understand physical table names, joins, nullable columns,&lt;br&gt;
tenant boundaries, authorization rules, and mutation policy. Database details&lt;br&gt;
become part of the prompt contract. A schema change can invalidate that&lt;br&gt;
contract, and a broadly capable SQL tool exposes much more authority than most&lt;br&gt;
business tasks require.&lt;/p&gt;

&lt;p&gt;TeaQL takes a different approach:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Don't give your AI agent unrestricted SQL. Give it a typed business language.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The open-source &lt;a href="https://github.com/teaql/teaql-ai-sdk" rel="noopener noreferrer"&gt;&lt;code&gt;@teaql/ai-sdk&lt;/code&gt;&lt;/a&gt;&lt;br&gt;
adapter converts an explicit allowlist of business capabilities into native&lt;br&gt;
Vercel AI SDK tools. The model sees operations such as&lt;br&gt;
&lt;code&gt;findSchoolsMissingContact&lt;/code&gt; and &lt;code&gt;updateSchoolContactPhone&lt;/code&gt;. The server keeps the&lt;br&gt;
TeaQL context, runtime resources, authorization state, credentials, and&lt;br&gt;
internal failures.&lt;/p&gt;
&lt;h2&gt;
  
  
  The missing layer beneath an agent SDK
&lt;/h2&gt;

&lt;p&gt;The Vercel AI SDK already provides the agent loop, tool calling, streaming,&lt;br&gt;
model-provider integration, and UI primitives. TeaQL does not reproduce those&lt;br&gt;
features. It supplies the governed business-data layer beneath them:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;User conversation
  -&amp;gt; Vercel AI SDK agent
  -&amp;gt; typed TeaQL business tools
  -&amp;gt; UserContext, policy, audit and runtime services
  -&amp;gt; database
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A generic SQL tool exposes an implementation mechanism:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;executeSql&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;tool&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;description&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Execute SQL against the application database&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;inputSchema&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;object&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;sql&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;string&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;}),&lt;/span&gt;
  &lt;span class="na"&gt;execute&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="k"&gt;async &lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="nx"&gt;sql&lt;/span&gt; &lt;span class="p"&gt;})&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;database&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;sql&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A TeaQL capability exposes an application operation:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;findSchoolsMissingContact&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;defineTeaQLCapability&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;findSchoolsMissingContact&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;description&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Find schools of a given type whose contact phone is explicitly null.&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;inputSchema&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;object&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
    &lt;span class="na"&gt;schoolType&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;enum&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;PRIMARY&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;SECONDARY&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;]),&lt;/span&gt;
  &lt;span class="p"&gt;}),&lt;/span&gt;
  &lt;span class="na"&gt;risk&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;read&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;execute&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;input&lt;/span&gt; &lt;span class="p"&gt;})&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt;
    &lt;span class="nx"&gt;context&lt;/span&gt;
      &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;requireResource&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nx"&gt;SchoolRepository&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;schoolRepository&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
      &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;findMissingContact&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;input&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;schoolType&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The second tool does not ask the model to invent a table name, encode an enum&lt;br&gt;
as the right database value, or decide which columns are safe to return. Its&lt;br&gt;
name and schema describe a bounded business capability.&lt;/p&gt;
&lt;h2&gt;
  
  
  Deny by absence
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;createTeaQLTools&lt;/code&gt; receives the complete set of capabilities available to one&lt;br&gt;
agent. A capability that is not passed to the function does not exist in the&lt;br&gt;
AI SDK toolset.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;tools&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;createTeaQLTools&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;capabilities&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
    &lt;span class="nx"&gt;findSchoolsMissingContact&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;updateSchoolContactPhone&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="p"&gt;],&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;An optional runtime allowlist can narrow that set for a particular user or&lt;br&gt;
agent:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;readOnlyTools&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;createTeaQLTools&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;capabilities&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;schoolCapabilities&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;allow&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;findSchoolsMissingContact&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Unknown allowlist names and duplicate capability names fail during startup.&lt;br&gt;
They do not silently produce a weaker or unexpectedly empty policy.&lt;/p&gt;

&lt;p&gt;This is intentionally different from generating five CRUD tools for every&lt;br&gt;
entity. Large domains can contain hundreds of entities. Automatically exposing&lt;br&gt;
every operation creates tool-selection noise and grants the agent authority it&lt;br&gt;
does not need. TeaQL models the smaller set of operations that make sense for&lt;br&gt;
the agent's job.&lt;/p&gt;
&lt;h2&gt;
  
  
  The model never receives &lt;code&gt;UserContext&lt;/code&gt;
&lt;/h2&gt;

&lt;p&gt;The input schema is model-visible. The TeaQL &lt;code&gt;UserContext&lt;/code&gt; is not.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;context&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;UserContext&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;insertResource&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;dataService&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;dataService&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;insertResource&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;authorization&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;authorization&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;tools&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;createTeaQLTools&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;capabilities&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;context&lt;/code&gt; is captured in the server-side execute closure. It carries trusted&lt;br&gt;
runtime resources, identity and policy selected by the application. The model&lt;br&gt;
cannot construct it, replace its data service, choose another tenant, or add a&lt;br&gt;
permission through tool input.&lt;/p&gt;

&lt;p&gt;This follows a broader TeaQL API rule: business execution receives one trusted&lt;br&gt;
&lt;code&gt;context&lt;/code&gt;; process-level runtime ownership and provider installation are not&lt;br&gt;
mixed into model-generated parameters.&lt;/p&gt;
&lt;h2&gt;
  
  
  Approval and authorization solve different problems
&lt;/h2&gt;

&lt;p&gt;A write capability can request AI SDK approval:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;updateSchoolContactPhone&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;defineTeaQLCapability&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;updateSchoolContactPhone&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;description&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Update one school contact phone with an explicit audit reason.&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;inputSchema&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;object&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
    &lt;span class="na"&gt;schoolId&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;number&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;int&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;positive&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;
    &lt;span class="na"&gt;contactPhone&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;string&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;min&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;max&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;40&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="na"&gt;auditReason&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;z&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;string&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;min&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;max&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;200&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
  &lt;span class="p"&gt;}),&lt;/span&gt;
  &lt;span class="na"&gt;risk&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;write&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;needsApproval&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;execute&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="k"&gt;async &lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;input&lt;/span&gt; &lt;span class="p"&gt;})&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;school&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nf"&gt;loadSchool&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;input&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;schoolId&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nx"&gt;school&lt;/span&gt;
      &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;updateContactPhone&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;input&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;contactPhone&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
      &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;auditAs&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;input&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;auditReason&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
      &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;save&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;},&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Approval asks whether the user authorizes this proposed tool call.&lt;br&gt;
Authorization asks whether the authenticated user is allowed to perform the&lt;br&gt;
operation at all. Audit records what happened and why. Validation determines&lt;br&gt;
whether the proposed state is legal.&lt;/p&gt;

&lt;p&gt;These controls reinforce one another, but they are not interchangeable:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Agent proposes a write
  -&amp;gt; AI SDK approval
  -&amp;gt; TeaQL runtime authorization
  -&amp;gt; domain validation
  -&amp;gt; audited save
  -&amp;gt; persisted result
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A prompt that says "do not update restricted schools" is useful guidance. It&lt;br&gt;
is not a runtime permission boundary.&lt;/p&gt;
&lt;h2&gt;
  
  
  Preserve the persisted result
&lt;/h2&gt;

&lt;p&gt;The included school example starts with a secondary school whose contact phone&lt;br&gt;
is explicitly null and whose optimistic version is &lt;code&gt;1&lt;/code&gt;. After an approved,&lt;br&gt;
audited update, the tool returns the persisted object with the new phone and&lt;br&gt;
version &lt;code&gt;2&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Persisted result: {
  id: 1,
  name: 'Riverside Secondary School',
  schoolType: 'SECONDARY',
  contactPhone: '+1-555-0100',
  version: 2
}
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Returning the authoritative persisted entity matters when a database assigns&lt;br&gt;
an ID, a trigger or default supplies a value, or optimistic versioning changes&lt;br&gt;
state. A write tool should not reconstruct a record from its input and pretend&lt;br&gt;
that it represents the database result.&lt;/p&gt;

&lt;p&gt;TeaQL also distinguishes loaded, explicit null, and not-loaded states. A&lt;br&gt;
partially projected entity cannot safely collapse those states into ordinary&lt;br&gt;
TypeScript &lt;code&gt;undefined&lt;/code&gt; values.&lt;/p&gt;
&lt;h2&gt;
  
  
  Observe failures without leaking them
&lt;/h2&gt;

&lt;p&gt;Tool execution emits lifecycle events that can feed structured logs or an&lt;br&gt;
OpenTelemetry adapter:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;tools&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;createTeaQLTools&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nx"&gt;capabilities&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;onEvent&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;event&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;telemetry&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;record&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;event&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The default events include capability name, risk, tool-call ID and timing.&lt;br&gt;
Inputs are excluded because they may contain sensitive business data.&lt;/p&gt;

&lt;p&gt;When capability execution fails, server telemetry receives the original error.&lt;br&gt;
The model receives a safe message such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;The updateSchoolContactPhone business operation could not be completed.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Applications can map public error messages, but raw connection strings, SQL,&lt;br&gt;
credentials and internal exception details remain on the server.&lt;/p&gt;
&lt;h2&gt;
  
  
  Native Vercel AI SDK integration
&lt;/h2&gt;

&lt;p&gt;The resulting object is an AI SDK &lt;code&gt;ToolSet&lt;/code&gt; and can be passed directly to an&lt;br&gt;
agent:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;UserContext&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;@teaql/teaql&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;ToolLoopAgent&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;ai&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;createTeaQLTools&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;@teaql/ai-sdk&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;context&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;UserContext&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;insertResource&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;schoolRepository&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;repository&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;agent&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;ToolLoopAgent&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;model&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;openai/gpt-5.4&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;instructions&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;Use only the provided business tools. Never invent SQL or database fields.&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;tools&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nf"&gt;createTeaQLTools&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
    &lt;span class="nx"&gt;context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="na"&gt;capabilities&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;schoolCapabilities&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="p"&gt;}),&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The adapter uses AI SDK schemas, metadata, execution and approval semantics.&lt;br&gt;
It does not require the application to adopt a second agent loop.&lt;/p&gt;
&lt;h2&gt;
  
  
  Run the demonstration without an API key
&lt;/h2&gt;

&lt;p&gt;The repository contains a deterministic school-management demonstration. It&lt;br&gt;
uses in-memory SQLite, so no external database, model API key, or signup is&lt;br&gt;
required:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/teaql/teaql-ai-sdk.git
&lt;span class="nb"&gt;cd &lt;/span&gt;teaql-ai-sdk
npm &lt;span class="nb"&gt;install
&lt;/span&gt;npm run example
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The demonstration prints:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;the two model-visible capabilities;&lt;/li&gt;
&lt;li&gt;approval metadata on the write tool;&lt;/li&gt;
&lt;li&gt;schools whose contact value is explicitly null;&lt;/li&gt;
&lt;li&gt;lifecycle events;&lt;/li&gt;
&lt;li&gt;the persisted version change;&lt;/li&gt;
&lt;li&gt;the audit record.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The small SQLite repository is handwritten to keep the adapter demonstration&lt;br&gt;
self-contained. In a generated TeaQL application, its implementation is&lt;br&gt;
replaced by generated Q requests, entities, Save behavior and a Runtime Module.&lt;br&gt;
The AI SDK adapter and its security boundary remain the same.&lt;/p&gt;

&lt;p&gt;The package is published as&lt;br&gt;
&lt;a href="https://www.npmjs.com/package/@teaql/ai-sdk" rel="noopener noreferrer"&gt;&lt;code&gt;@teaql/ai-sdk&lt;/code&gt;&lt;/a&gt; and can be added&lt;br&gt;
to an existing AI SDK application with:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npm &lt;span class="nb"&gt;install&lt;/span&gt; @teaql/ai-sdk @teaql/teaql ai zod
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The GitHub repository remains the source for the complete SQLite demonstration,&lt;br&gt;
release workflow and implementation history.&lt;/p&gt;
&lt;h2&gt;
  
  
  Start with TypeScript, preserve cross-runtime semantics
&lt;/h2&gt;

&lt;p&gt;The initial adapter is TypeScript-first because the Vercel AI SDK is a&lt;br&gt;
TypeScript ecosystem. TeaQL's larger responsibility is preserving one domain&lt;br&gt;
language and equivalent runtime behavior across Java, Rust, TypeScript, Swift,&lt;br&gt;
Python, .NET and Go.&lt;/p&gt;

&lt;p&gt;The intended generation path is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;TeaQL domain model
  -&amp;gt; runtime entities and typed queries
  -&amp;gt; explicit agent capability manifest
  -&amp;gt; AI SDK tools
  -&amp;gt; MCP tools
  -&amp;gt; agent usage Markdown
  -&amp;gt; executable TeaQL Agent Kit verification
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A TypeScript AI SDK application can execute capabilities locally through the&lt;br&gt;
TeaQL TypeScript Runtime. The same capability manifest can later reach another&lt;br&gt;
TeaQL runtime through MCP or the TeaQL Federal Protocol without teaching the&lt;br&gt;
model seven unrelated database APIs.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is available today
&lt;/h2&gt;

&lt;p&gt;The first public repository includes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;native AI SDK &lt;code&gt;ToolSet&lt;/code&gt; creation;&lt;/li&gt;
&lt;li&gt;typed input and output schemas;&lt;/li&gt;
&lt;li&gt;explicit capability and per-agent allowlists;&lt;/li&gt;
&lt;li&gt;trusted server-side &lt;code&gt;UserContext&lt;/code&gt; injection;&lt;/li&gt;
&lt;li&gt;read, write and privileged risk metadata;&lt;/li&gt;
&lt;li&gt;approval support;&lt;/li&gt;
&lt;li&gt;safe error mapping;&lt;/li&gt;
&lt;li&gt;lifecycle events for telemetry;&lt;/li&gt;
&lt;li&gt;configuration validation;&lt;/li&gt;
&lt;li&gt;five automated boundary tests;&lt;/li&gt;
&lt;li&gt;a no-key SQLite demonstration;&lt;/li&gt;
&lt;li&gt;a passing public GitHub Actions workflow.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Generator-produced capability definitions, the hosted interactive demo,&lt;br&gt;
OpenTelemetry export and cross-runtime MCP execution remain follow-up work. The&lt;br&gt;
project documents those limits rather than presenting a thin adapter as a&lt;br&gt;
finished enterprise security system.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it and challenge the boundary
&lt;/h2&gt;

&lt;p&gt;The most useful feedback is not whether another generic tool wrapper can be&lt;br&gt;
added. It is whether the capability boundary remains understandable and&lt;br&gt;
enforceable in a real application:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which business operations should become tools?&lt;/li&gt;
&lt;li&gt;When should an operation require approval?&lt;/li&gt;
&lt;li&gt;Which data must never appear in a model-visible schema or trace?&lt;/li&gt;
&lt;li&gt;How should capability manifests evolve with a domain model?&lt;/li&gt;
&lt;li&gt;Which negative conformance tests would make the security claim credible?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The code, tests and runnable example are available at&lt;br&gt;
&lt;a href="https://github.com/teaql/teaql-ai-sdk" rel="noopener noreferrer"&gt;&lt;code&gt;teaql/teaql-ai-sdk&lt;/code&gt;&lt;/a&gt;. Related work is&lt;br&gt;
maintained in the &lt;a href="https://github.com/teaql/teaql-ts" rel="noopener noreferrer"&gt;TeaQL TypeScript Runtime&lt;/a&gt;,&lt;br&gt;
&lt;a href="https://github.com/teaql/teaql-agent-kit" rel="noopener noreferrer"&gt;TeaQL Agent Kit&lt;/a&gt;, and&lt;br&gt;
&lt;a href="https://github.com/teaql/teaql-conformance" rel="noopener noreferrer"&gt;TeaQL Conformance&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>typescript</category>
      <category>ai</category>
      <category>opensource</category>
      <category>database</category>
    </item>
    <item>
      <title>TeaQL Was 2,000x Faster Than the Obvious SQLx Query—Here’s What Actually Happened</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Wed, 30 Sep 2026 15:14:56 +0000</pubDate>
      <link>https://dev.to/philipgreat/teaql-was-2000x-faster-than-the-obvious-sqlx-query-heres-what-actually-happened-1jjb</link>
      <guid>https://dev.to/philipgreat/teaql-was-2000x-faster-than-the-obvious-sqlx-query-heres-what-actually-happened-1jjb</guid>
      <description>&lt;p&gt;We recently measured two implementations of the same application request over&lt;br&gt;
the MusicBrainz dataset:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Load the newest 100 recordings that have linked works, and load at most ten&lt;br&gt;
work relations for each recording.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The controlled SQLx test returned the same 100 recordings, 103 relation rows,&lt;br&gt;
103 links, 103 link types, and Work-ID checksum through both paths. One took&lt;br&gt;
5,871.169 milliseconds. The other took 2.469 milliseconds—a &lt;strong&gt;2,378×&lt;br&gt;
difference inside SQLx itself&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;TeaQL Rust previously completed the corresponding typed graph workload in&lt;br&gt;
2.864 milliseconds. That does not mean TeaQL has a PostgreSQL driver 2,000×&lt;br&gt;
faster than SQLx. The difference was the amount of work requested from the&lt;br&gt;
database. The expert SQLx control proves it.&lt;/p&gt;
&lt;h2&gt;
  
  
  What TeaQL is
&lt;/h2&gt;

&lt;p&gt;TeaQL is a model-driven application runtime. A semantic model generates&lt;br&gt;
language-native Q APIs for queries, E APIs for loaded expressions, and governed&lt;br&gt;
graph mutation APIs. The same model can target seven runtimes: Rust, Java,&lt;br&gt;
TypeScript, Go, Swift, .NET, and Python.&lt;/p&gt;

&lt;p&gt;Queries carry more than SQL structure. They retain relation bounds, loaded&lt;br&gt;
state, tenant and authorization scope, version policy, and an operational&lt;br&gt;
&lt;code&gt;comment&lt;/code&gt; and &lt;code&gt;purpose&lt;/code&gt;. That additional intent is what made this optimization&lt;br&gt;
possible without turning application code into handcrafted SQL.&lt;/p&gt;
&lt;h2&gt;
  
  
  The obvious single-statement SQLx solution
&lt;/h2&gt;

&lt;p&gt;A capable SQL developer may reach for a window function to express Top-N per&lt;br&gt;
parent:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;WITH&lt;/span&gt; &lt;span class="n"&gt;ranked&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;relation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
         &lt;span class="n"&gt;row_number&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="n"&gt;OVER&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
           &lt;span class="k"&gt;PARTITION&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;relation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;entity0&lt;/span&gt;
           &lt;span class="k"&gt;ORDER&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;relation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;link_order&lt;/span&gt; &lt;span class="k"&gt;ASC&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;relation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;DESC&lt;/span&gt;
         &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;rn&lt;/span&gt;
  &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;l_recording_work&lt;/span&gt; &lt;span class="n"&gt;relation&lt;/span&gt;
  &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;relation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;roots&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;recording&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;
  &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;recording&lt;/span&gt;
  &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;recording&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;
    &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="k"&gt;EXISTS&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
      &lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;ranked&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;ranked&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;entity0&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;recording&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="k"&gt;ORDER&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;recording&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;DESC&lt;/span&gt;
  &lt;span class="k"&gt;LIMIT&lt;/span&gt; &lt;span class="mi"&gt;100&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="p"&gt;...&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;roots&lt;/span&gt;
&lt;span class="k"&gt;LEFT&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="n"&gt;ranked&lt;/span&gt;
  &lt;span class="k"&gt;ON&lt;/span&gt; &lt;span class="n"&gt;ranked&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;entity0&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;roots&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;ranked&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;rn&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mi"&gt;10&lt;/span&gt;
&lt;span class="k"&gt;LEFT&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="n"&gt;link&lt;/span&gt; &lt;span class="p"&gt;...&lt;/span&gt;
&lt;span class="k"&gt;LEFT&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="n"&gt;link_type&lt;/span&gt; &lt;span class="p"&gt;...&lt;/span&gt;
&lt;span class="k"&gt;LEFT&lt;/span&gt; &lt;span class="k"&gt;JOIN&lt;/span&gt; &lt;span class="k"&gt;work&lt;/span&gt; &lt;span class="p"&gt;...;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is readable, set-oriented SQL. It is not an obviously careless query. It&lt;br&gt;
also asks PostgreSQL to rank the complete relation population—about 2.7 million&lt;br&gt;
rows in this fixture—before reducing the graph to 100 roots and 103 relations.&lt;/p&gt;

&lt;p&gt;In the Rust SQLx control, the PostgreSQL median was 5,871.169 ms. An earlier&lt;br&gt;
raw JDBC run measured 5,579.224 ms, confirming that changing the client library&lt;br&gt;
does not remove the database work. DuckDB, whose vectorized analytical engine&lt;br&gt;
fits this global-ranking shape better, completed the earlier query in&lt;br&gt;
808.158 ms.&lt;/p&gt;
&lt;h2&gt;
  
  
  The business request carried a stronger bound
&lt;/h2&gt;

&lt;p&gt;The corresponding TeaQL request describes a bounded object graph. In an&lt;br&gt;
application, we can name and reuse each meaningful graph fragment instead of&lt;br&gt;
repeating the whole nested request at every call site:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;link_type_details&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;LinkTypeRequest&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;link_types_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.select_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.select_description&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.select_link_phrase&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;link_details&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;LinkRequest&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;links_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.select_ended&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.select_link_type_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;link_type_details&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;recording_work_details&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;LRecordingWorkRequest&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;l_recording_works_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.select_link_order&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.select_link_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;link_details&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
        &lt;span class="nf"&gt;.select_entity1_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;works_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.select_name&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
        &lt;span class="nf"&gt;.order_by_link_order_asc&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.order_by_id_desc&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="nf"&gt;.limit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;recordings_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.select_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.select_length&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.have_l_recording_works&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.select_l_recording_work_list_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;recording_work_details&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
    &lt;span class="nf"&gt;.order_by_id_desc&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.limit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;100&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"what: load the MB03 recording-work graph"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.purpose&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"why: render bounded recording-work details"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.execute_for_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;context&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The main request now reads as a composition of business-relevant graph&lt;br&gt;
fragments. The helpers are ordinary typed Rust functions: they can be reused,&lt;br&gt;
tested, extended, and combined like building blocks. They do not hide raw SQL&lt;br&gt;
or switch to a second query system; each still returns a generated TeaQL query&lt;br&gt;
selection that the runtime can govern as one request.&lt;/p&gt;

&lt;p&gt;See the same TeaQL request fully expanded&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;recordings_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.select_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.select_length&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.have_l_recording_works&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.select_l_recording_work_list_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
        &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;l_recording_works_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
            &lt;span class="nf"&gt;.select_link_order&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
            &lt;span class="nf"&gt;.select_link_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
                &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;links_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
                    &lt;span class="nf"&gt;.select_ended&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
                    &lt;span class="nf"&gt;.select_link_type_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
                        &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;link_types_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
                            &lt;span class="nf"&gt;.select_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
                            &lt;span class="nf"&gt;.select_description&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
                            &lt;span class="nf"&gt;.select_link_phrase&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;
                    &lt;span class="p"&gt;),&lt;/span&gt;
            &lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="nf"&gt;.select_entity1_with&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;works_minimal&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.select_name&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
            &lt;span class="nf"&gt;.order_by_link_order_asc&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
            &lt;span class="nf"&gt;.order_by_id_desc&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
            &lt;span class="nf"&gt;.limit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.order_by_id_desc&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.limit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;100&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"what: load the MB03 recording-work graph"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.purpose&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"why: render bounded recording-work details"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.execute_for_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;amp&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="n"&gt;context&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;
&lt;p&gt;The important information is not the Rust syntax. It is the request shape:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;choose 100 matching roots;&lt;/li&gt;
&lt;li&gt;load no more than ten ordered relations for each selected root;&lt;/li&gt;
&lt;li&gt;hydrate only the referenced Link, LinkType, and Work objects;&lt;/li&gt;
&lt;li&gt;preserve version, policy, comment, and purpose semantics throughout.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;TeaQL can select the roots first and constrain relation loading to those roots.&lt;br&gt;
It does not need to rank relations belonging to recordings that cannot appear&lt;br&gt;
on this page.&lt;/p&gt;

&lt;h2&gt;
  
  
  The SQLx control explains the result
&lt;/h2&gt;

&lt;p&gt;We then wrote the optimization explicitly in ordinary SQLx:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;fetch the 100 root recording IDs;&lt;/li&gt;
&lt;li&gt;pass those IDs to a second parameterized query;&lt;/li&gt;
&lt;li&gt;rank only relations whose &lt;code&gt;entity0&lt;/code&gt; belongs to that root set;&lt;/li&gt;
&lt;li&gt;join Link, LinkType, and Work for the bounded rows.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Using one initialized SQLx pool connection, three warmups, and ten sequential&lt;br&gt;
measurements, the medians were:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Implementation&lt;/th&gt;
&lt;th&gt;PostgreSQL median&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;SQLx, natural global-window statement&lt;/td&gt;
&lt;td&gt;5,871.169 ms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SQLx, expert root-first two-stage plan&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;2.469 ms&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;TeaQL Rust, typed governed graph (separate retained run)&lt;/td&gt;
&lt;td&gt;2.864 ms&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The first two rows are the controlled 2,378× comparison. The TeaQL row comes&lt;br&gt;
from a separate retained run and is context, not part of that ratio. It includes&lt;br&gt;
generated typed requests, relation hydration, and identity-graph assembly; the&lt;br&gt;
SQLx control decodes aggregate tuples.&lt;/p&gt;

&lt;h2&gt;
  
  
  How much code did each plan require?
&lt;/h2&gt;

&lt;p&gt;We counted the physical non-blank lines that declare and execute each query.&lt;br&gt;
Imports, connection setup, timing, result gates, and reporting were excluded;&lt;br&gt;
embedded SQL was included because the application owns it.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Implementation&lt;/th&gt;
&lt;th&gt;Query LOC&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;SQLx, natural global window&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SQLx, expert root-first&lt;/td&gt;
&lt;td&gt;34&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;TeaQL, typed graph request (fully expanded)&lt;/td&gt;
&lt;td&gt;27&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The numbers are deliberately unexciting: TeaQL is not winning through a tiny&lt;br&gt;
code-golf example. Its fully expanded typed request is about the same size as&lt;br&gt;
the natural SQL. The composed version moves reusable graph fragments out of the&lt;br&gt;
call site; it improves local readability without pretending that their&lt;br&gt;
definitions vanished. The important difference is what those lines preserve.&lt;br&gt;
The expert SQLx version owns two SQL statements, transfers root IDs, binds the&lt;br&gt;
array, and must keep both stages semantically aligned. TeaQL declares the root&lt;br&gt;
and relation bounds once inside the graph request.&lt;/p&gt;

&lt;p&gt;LOC is formatting-sensitive, and the SQLx benchmark returns aggregate tuples&lt;br&gt;
while TeaQL hydrates entities. It should be read as maintenance surface, not as&lt;br&gt;
a universal productivity score. A fuller hand-written implementation would&lt;br&gt;
also need typed SQLx rows, graph assembly, authorization, tenant isolation,&lt;br&gt;
loaded-state handling, and observability.&lt;/p&gt;

&lt;h2&gt;
  
  
  Performance is only half of the problem
&lt;/h2&gt;

&lt;p&gt;An expert can—and in this benchmark did—write the fast SQLx plan. TeaQL's&lt;br&gt;
advantage is not that manual optimization is impossible. It is that application&lt;br&gt;
developers do not have to discover, implement, and repeatedly preserve it&lt;br&gt;
themselves.&lt;/p&gt;

&lt;p&gt;Every handcrafted optimization creates another enforcement point. The root&lt;br&gt;
query may contain a tenant predicate while the child query accidentally omits&lt;br&gt;
it. The same can happen to authorization scope, soft-delete/version policy,&lt;br&gt;
privacy masking, or trace metadata. Such mistakes are especially easy when an&lt;br&gt;
AI coding agent rewrites a query for performance: the output looks faster and&lt;br&gt;
can still leak another tenant's children.&lt;/p&gt;

&lt;p&gt;TeaQL keeps both stages inside the same governed execution model. This is part&lt;br&gt;
of TeaQL Harness Engineering: reduce the space in which generated code can be&lt;br&gt;
fast but semantically or operationally wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the benchmark proves—and what it does not
&lt;/h2&gt;

&lt;p&gt;It proves that API semantics can give a runtime enough information to avoid a&lt;br&gt;
large amount of unnecessary database work. It also shows why query-count rules&lt;br&gt;
are incomplete: one elegant statement can do much more work than several&lt;br&gt;
bounded statements.&lt;/p&gt;

&lt;p&gt;It does not prove that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;TeaQL has an intrinsically faster PostgreSQL driver than SQLx;&lt;/li&gt;
&lt;li&gt;every window query is slow;&lt;/li&gt;
&lt;li&gt;multiple queries are always preferable;&lt;/li&gt;
&lt;li&gt;these timings generalize to other hardware, datasets, indexes, or databases;&lt;/li&gt;
&lt;li&gt;2,378× is a general TeaQL-versus-SQLx performance ratio.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The controlled result is narrower and more useful:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The obvious SQLx query ranked 2.7 million rows for a page containing 103&lt;br&gt;
relations. Once the business bounds were applied before ranking, most of that&lt;br&gt;
work disappeared.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Reproduce it
&lt;/h2&gt;

&lt;p&gt;The public&lt;br&gt;
&lt;a href="https://github.com/teaql/teaql-runtime-benchmark" rel="noopener noreferrer"&gt;TeaQL runtime benchmark repository&lt;/a&gt;&lt;br&gt;
retains four related evidence packages:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;a href="https://github.com/teaql/teaql-runtime-benchmark/tree/main/benchmarks/B001-rust-orm-musicbrainz" rel="noopener noreferrer"&gt;B001&lt;/a&gt;: Rust TeaQL, Diesel, and SeaORM typed graph workloads;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/teaql/teaql-runtime-benchmark/tree/main/benchmarks/B002-duckdb-musicbrainz-engine" rel="noopener noreferrer"&gt;B002&lt;/a&gt;: raw JDBC across PostgreSQL and DuckDB;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/teaql/teaql-runtime-benchmark/tree/main/benchmarks/B003-java-teaql-musicbrainz" rel="noopener noreferrer"&gt;B003&lt;/a&gt;: Java TeaQL across PostgreSQL and DuckDB;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/teaql/teaql-runtime-benchmark/tree/main/benchmarks/B004-rust-sqlx-musicbrainz" rel="noopener noreferrer"&gt;B004&lt;/a&gt;: natural and expert root-first SQLx plans with a correctness gate.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Each package records source, query shape, environment, warmups, measurements,&lt;br&gt;
cardinalities, and checksums. B004 also contains an executable LOC counter.&lt;/p&gt;

&lt;p&gt;The 2,378× headline is therefore reproducible, but deliberately narrow. The&lt;br&gt;
broader TeaQL claim is about making the good plan declarative, typed, reusable,&lt;br&gt;
and governed.&lt;/p&gt;

</description>
      <category>rust</category>
      <category>performance</category>
      <category>postgres</category>
      <category>database</category>
    </item>
    <item>
      <title>A Stable Rust Tool Facade for Humans and AI: 52 Utilities, Explicit Intent</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Wed, 30 Sep 2026 15:14:12 +0000</pubDate>
      <link>https://dev.to/philipgreat/a-stable-rust-tool-facade-for-humans-and-ai-52-utilities-explicit-intent-4ihn</link>
      <guid>https://dev.to/philipgreat/a-stable-rust-tool-facade-for-humans-and-ai-52-utilities-explicit-intent-4ihn</guid>
      <description>&lt;p&gt;Rust does not have a shortage of good crates.&lt;/p&gt;

&lt;p&gt;There is &lt;code&gt;uuid&lt;/code&gt; for identifiers, &lt;code&gt;chrono&lt;/code&gt; for time, &lt;code&gt;rust_decimal&lt;/code&gt; for exact&lt;br&gt;
decimal arithmetic, &lt;code&gt;serde_json&lt;/code&gt; for JSON, and &lt;code&gt;reqwest&lt;/code&gt; for HTTP. The challenge&lt;br&gt;
in application development is often not finding a capability. It is keeping a&lt;br&gt;
team fluent in many unrelated APIs while preventing infrastructure details from&lt;br&gt;
spreading through business code.&lt;/p&gt;

&lt;p&gt;AI coding makes that problem more visible. A model may understand the operation&lt;br&gt;
we want while mixing together method names from another language, another&lt;br&gt;
version, or another crate. The generated code looks plausible, but the API does&lt;br&gt;
not exist.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/teaql/teaql-rust-utils" rel="noopener noreferrer"&gt;TeaQL Tool&lt;/a&gt; is our attempt to make&lt;br&gt;
that surface smaller and more predictable. It places 52 common utilities behind&lt;br&gt;
one &lt;code&gt;T::xxx()&lt;/code&gt; facade, separates lightweight and dependency-heavy features, and&lt;br&gt;
adds an optional context layer that requires code to state why a value is being&lt;br&gt;
read, calculated, or changed.&lt;/p&gt;

&lt;p&gt;It is partly inspired by libraries such as Hutool, but the interesting question&lt;br&gt;
is not how many helpers we can collect. It is whether a stable, narrow API can&lt;br&gt;
serve both application developers and coding agents without hiding Rust's&lt;br&gt;
underlying ecosystem.&lt;/p&gt;
&lt;h2&gt;
  
  
  The problem is API variance, not missing capability
&lt;/h2&gt;

&lt;p&gt;A typical service quickly needs identifiers, timestamps, money, JSON, regular&lt;br&gt;
expressions, encoding, files, hashing, and HTTP. Using each underlying crate&lt;br&gt;
directly is entirely reasonable, especially when an application needs its full&lt;br&gt;
feature set.&lt;/p&gt;

&lt;p&gt;For repeated business operations, however, every dependency introduces another&lt;br&gt;
construction pattern, error model, naming convention, and upgrade path. The&lt;br&gt;
business layer gradually learns more infrastructure than business semantics.&lt;br&gt;
An AI agent has an even larger API space in which to guess.&lt;/p&gt;

&lt;p&gt;TeaQL Tool does not reimplement the ecosystem. It provides a small facade over&lt;br&gt;
selected, mature crates:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;use&lt;/span&gt; &lt;span class="nn"&gt;teaql_tool&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;id&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.uuid&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;now&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;time&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.now&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;value&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.parse&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;r#"{"name":"TeaQL"}"#&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;digest&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.sha256&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;b"hello"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The caller starts at &lt;code&gt;T&lt;/code&gt;, chooses a semantically named tool, and uses a compact&lt;br&gt;
operation set. The facade can evolve its implementation without requiring every&lt;br&gt;
call site to know which crate performs the work.&lt;/p&gt;
&lt;h2&gt;
  
  
  How the 52 tools are divided
&lt;/h2&gt;

&lt;p&gt;The workspace contains five crates:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;teaql-tool-core
       │
       ├── teaql-tool-std       26 standard tools
       ├── teaql-tool-extra     26 extension tools
       │
       └── teaql-tool           unified T:: facade
                    │
                    └── teaql-tool-context
                        UserContext and intent adapters
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;teaql-tool-std&lt;/code&gt; contains 26 general-purpose tools: text, time, date ranges,&lt;br&gt;
IDs, money, decimals, JSON, regex, encoding, hashes, files, lists, maps,&lt;br&gt;
validation, masking, emoji, networking, colors, units, trees, and related&lt;br&gt;
operations.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;teaql-tool-extra&lt;/code&gt; contains 26 tools with heavier dependencies or more explicit&lt;br&gt;
IO: HTTP, commands, archives, Excel, CSV, images, email, JWT, encryption,&lt;br&gt;
barcodes, QR codes, templates, an embedded key-value store, caching, a static&lt;br&gt;
file server, a reverse proxy, cron scheduling, and file watching.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;teaql-tool&lt;/code&gt; is intentionally thin. It owns the public facade and feature&lt;br&gt;
selection. The default &lt;code&gt;minimal&lt;/code&gt; feature enables the standard tools; applications&lt;br&gt;
opt into &lt;code&gt;extra&lt;/code&gt; when they need the heavier integrations.&lt;/p&gt;

&lt;p&gt;Until the crates are published independently, the facade can be used from the&lt;br&gt;
Git repository:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight toml"&gt;&lt;code&gt;&lt;span class="nn"&gt;[dependencies]&lt;/span&gt;
&lt;span class="py"&gt;teaql-tool&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="py"&gt;git&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"https://github.com/teaql/teaql-rust-utils"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="py"&gt;features&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s"&gt;"std"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"extra"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;a href="https://github.com/teaql/teaql-rust-utils#%EF%B8%8F-feature-inventory" rel="noopener noreferrer"&gt;project README&lt;/a&gt;&lt;br&gt;
contains the complete inventory and the current context coverage.&lt;/p&gt;
&lt;h2&gt;
  
  
  Why use a facade in Rust?
&lt;/h2&gt;

&lt;p&gt;A facade has a straightforward benefit: discoverability.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;tomorrow&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;time&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.add_days&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;time&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.now&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;encoded&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;codec&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.base64_encode&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;b"Hello"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;masked&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;T&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;desensitize&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.chinese_phone&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"13812345678"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Developers and agents can search one namespace instead of rediscovering a&lt;br&gt;
dependency for every common operation. Naming can remain consistent across&lt;br&gt;
categories, and an underlying dependency upgrade does not automatically become&lt;br&gt;
an application-wide migration.&lt;/p&gt;

&lt;p&gt;The same abstraction has a cost. A facade exposes a deliberately smaller API&lt;br&gt;
than its dependencies. If an application needs detailed &lt;code&gt;reqwest&lt;/code&gt; connection&lt;br&gt;
pool control, the complete &lt;code&gt;chrono&lt;/code&gt; type system, or advanced image encoding&lt;br&gt;
parameters, it should use those crates directly. TeaQL Tool is a business&lt;br&gt;
convenience layer, not a replacement for the Rust ecosystem.&lt;/p&gt;
&lt;h2&gt;
  
  
  Put the reason for an operation in the type flow
&lt;/h2&gt;

&lt;p&gt;A predictable method name reduces API guessing. It does not explain why&lt;br&gt;
application code is reading a file, obtaining the current time, or starting a&lt;br&gt;
command.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;teaql-tool-context&lt;/code&gt; explores a second idea: context-bound tools return wrappers&lt;br&gt;
that require the caller to add intent before extracting a value or executing a&lt;br&gt;
side effect.&lt;/p&gt;

&lt;p&gt;The API distinguishes three meanings:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;comment(...)&lt;/code&gt; explains a calculation;&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;purpose(...)&lt;/code&gt; explains a read;&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;audit_as(...)&lt;/code&gt; describes and executes a side effect.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;use&lt;/span&gt; &lt;span class="nn"&gt;teaql_tool_context&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nn"&gt;prelude&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;now&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="nf"&gt;.time&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.now&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"read the current time for the payment policy"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;deadline&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="nf"&gt;.time&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.add_days&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;now&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;7&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"calculate the payment grace period"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="nf"&gt;.file&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.write_string&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"deadline.txt"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;deadline&lt;/span&gt;&lt;span class="nf"&gt;.to_rfc3339&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
    &lt;span class="nf"&gt;.audit_as&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"export the calculated payment deadline"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Calculation and read wrappers keep their inner values private. Code that needs&lt;br&gt;
the value must explicitly consume the wrapper through the matching intent&lt;br&gt;
method.&lt;/p&gt;

&lt;p&gt;Side effects need a stronger boundary. &lt;code&gt;MustAuditAs&amp;lt;T&amp;gt;&lt;/code&gt; stores a deferred action&lt;br&gt;
rather than an already-computed result:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;MustAuditAs&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;action&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Option&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;Box&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="k"&gt;dyn&lt;/span&gt; &lt;span class="nf"&gt;FnOnce&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;T&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="nb"&gt;Send&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="k"&gt;'static&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;impl&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;MustAuditAs&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;audit_as&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;mut&lt;/span&gt; &lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="k"&gt;impl&lt;/span&gt; &lt;span class="nb"&gt;Into&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;String&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;T&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;action&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="py"&gt;.action&lt;/span&gt;&lt;span class="nf"&gt;.take&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.expect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"action executes once"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nf"&gt;action&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="nf"&gt;.into&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If a caller drops this value without calling &lt;code&gt;.audit_as(...)&lt;/code&gt;, the deferred file&lt;br&gt;
write, command, or email is not performed. Tests cover both paths: execution&lt;br&gt;
after an audit description and no execution after the pending action is dropped.&lt;/p&gt;

&lt;p&gt;These wrappers enforce that intent is supplied at the API boundary. How that&lt;br&gt;
description enters structured logs, traces, or an audit store remains an&lt;br&gt;
application-runtime integration concern. Separating those responsibilities&lt;br&gt;
keeps the type-level contract honest: collect intent first, route it through the&lt;br&gt;
appropriate runtime policy second.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why a smaller API helps coding agents
&lt;/h2&gt;

&lt;p&gt;An LLM can know that a capability exists while still confusing its crate,&lt;br&gt;
version, or exact method name. A facade narrows that generation space:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;entry points follow &lt;code&gt;T::xxx()&lt;/code&gt; or &lt;code&gt;ctx.xxx()&lt;/code&gt;;&lt;/li&gt;
&lt;li&gt;related capabilities use a consistent naming style;&lt;/li&gt;
&lt;li&gt;underlying dependency changes need not propagate into business code;&lt;/li&gt;
&lt;li&gt;wrapper types let the compiler identify missing intent;&lt;/li&gt;
&lt;li&gt;project rules can disallow bypassing context-bound IO in application code.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This does not eliminate hallucinations. It changes the problem from guessing&lt;br&gt;
among many third-party APIs to selecting from a finite, project-owned surface,&lt;br&gt;
then lets the Rust compiler verify the result.&lt;/p&gt;

&lt;p&gt;For us, this is part of a broader harness-engineering principle: if a coding&lt;br&gt;
rule matters repeatedly, move as much of it as possible from prompt prose into&lt;br&gt;
an executable interface.&lt;/p&gt;

&lt;h2&gt;
  
  
  Current boundaries
&lt;/h2&gt;

&lt;p&gt;TeaQL Tool is an early project, and several boundaries are intentional or still&lt;br&gt;
in progress:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The facade covers frequent operations, not every capability of every wrapped
crate.&lt;/li&gt;
&lt;li&gt;Enabling &lt;code&gt;extra&lt;/code&gt; adds networking, image, spreadsheet, SMTP, and server
dependencies; compile time and binary size should be measured rather than
ignored.&lt;/li&gt;
&lt;li&gt;Stable facade names create a compatibility responsibility for maintainers.&lt;/li&gt;
&lt;li&gt;The context layer currently covers all 26 standard tools, 21 extension tools,
and a separate asynchronous HTTP adapter. Cron, proxy, server, and watcher
adapters remain to be added.&lt;/li&gt;
&lt;li&gt;Intent wrappers are an enforcement boundary, but full audit-sink integration
is still runtime-specific work.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The next steps are compatibility and compile-fail tests, feature-level build&lt;br&gt;
measurements, remaining context adapters, and deeper TeaQL runtime audit and&lt;br&gt;
trace integration.&lt;/p&gt;

&lt;h2&gt;
  
  
  A question for the Rust community
&lt;/h2&gt;

&lt;p&gt;Rust's crate ecosystem is strongest when applications can use focused libraries&lt;br&gt;
directly. At the same time, business systems and coding agents benefit from&lt;br&gt;
small, stable, project-owned interfaces.&lt;/p&gt;

&lt;p&gt;Where should that boundary sit?&lt;/p&gt;

&lt;p&gt;Does a Hutool-style facade reduce accidental complexity in a Rust application,&lt;br&gt;
or does it hide crate boundaries that should remain explicit? For AI-generated&lt;br&gt;
code, is a stable, constrained API more valuable than direct access to every&lt;br&gt;
underlying capability?&lt;/p&gt;

&lt;p&gt;TeaQL Tool is open source, and we would value concrete criticism of both the&lt;br&gt;
tool selection and the intent-wrapper design:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/teaql/teaql-rust-utils" rel="noopener noreferrer"&gt;github.com/teaql/teaql-rust-utils&lt;/a&gt;&lt;/p&gt;

</description>
      <category>tutorial</category>
      <category>ai</category>
      <category>productivity</category>
      <category>programming</category>
    </item>
    <item>
      <title>Expanding the TeaQL Ecosystem: Seamless Integration with Axum Web and Redis Distributed Cache</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Sun, 02 Aug 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/philipgreat/expanding-the-teaql-ecosystem-seamless-integration-with-axum-web-and-redis-distributed-cache-4jhc</link>
      <guid>https://dev.to/philipgreat/expanding-the-teaql-ecosystem-seamless-integration-with-axum-web-and-redis-distributed-cache-4jhc</guid>
      <description>&lt;p&gt;As the core architecture of TeaQL continues to mature, we are excited to announce two heavy-weight extension modules to the TeaQL ecosystem: the &lt;strong&gt;Web Module (&lt;code&gt;teaql-web-integration-axum&lt;/code&gt;)&lt;/strong&gt; and the &lt;strong&gt;Red Module (&lt;code&gt;teaql-cache-integration-redis&lt;/code&gt;)&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The addition of these two modules marks a significant milestone. TeaQL not only excels at the low-level data flow and auditing but also starts to provide out-of-the-box, exceptional experiences for developers and AI agents in top-level web request routing and distributed scaling.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. The Web Module: Bridging the HTTP Layer and the Security Sandbox
&lt;/h2&gt;

&lt;p&gt;In traditional architectures, the web layer (controllers/routing) and the underlying business logic layer are often completely disconnected. Developers must manually extract tokens, trace IDs, and User-Agents from HTTP headers, then assemble and pass them down to the service layer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code&gt;teaql-web-integration-axum&lt;/code&gt;&lt;/strong&gt; changes this completely. It seamlessly integrates the Rust community's outstanding Axum web framework with TeaQL's core security sandbox (&lt;code&gt;UserContext&lt;/code&gt;).&lt;/p&gt;

&lt;h3&gt;
  
  
  Feature 1: TeaContext Extractor
&lt;/h3&gt;

&lt;p&gt;We implemented a native Axum extractor in the Web module. When a request hits your router, all critical metadata is automatically parsed from the HTTP message and encapsulated into a high-integrity, tamper-proof &lt;code&gt;UserContext&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Axum router handler&lt;/span&gt;
&lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;async&lt;/span&gt; &lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;load_tasks&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;TeaContext&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Json&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;TaskRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;impl&lt;/span&gt; &lt;span class="n"&gt;IntoResponse&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="c1"&gt;// Here, ctx has already parsed X-User-Id, X-Trace-Id, and the client's IP!&lt;/span&gt;
    &lt;span class="c1"&gt;// Directly proceed to core authorization and audit security base:&lt;/span&gt;
    &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;tasks&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.execute_for_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="na"&gt;.0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="nf"&gt;.unwrap&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

    &lt;span class="nn"&gt;WebResponse&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;of_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Feature 2: Fully Compatible WebResponse
&lt;/h3&gt;

&lt;p&gt;During microservice evolution or frontend refactoring, API incompatibility is a major pain point. Our &lt;code&gt;WebResponse&lt;/code&gt; struct has a built-in &lt;code&gt;IntoResponse&lt;/code&gt; mapping mechanism for automatic status code resolution (including automatic intercepting of &lt;code&gt;AxumTeaError&lt;/code&gt;). More importantly: &lt;strong&gt;its JSON serialization structure perfectly matches the previous Java Legacy API&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Whether it's a frontend application or an AI agent calling the endpoint via OpenAPI, no parser logic needs to be rewritten just because the backend transitioned to Rust.&lt;/p&gt;

&lt;h3&gt;
  
  
  Feature 3: Native Support for Facets (Aggregated Categorization)
&lt;/h3&gt;

&lt;p&gt;In modern e-commerce, dashboards, or complex business queries, we often need to return not just a list of items but also grouped metadata (such as status counts or temporal distributions) for rendering sidebars. In the search domain, this is referred to as &lt;strong&gt;Facets&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;teaql-web-integration-axum&lt;/code&gt; provides first-class support for Facets. It accepts &lt;code&gt;SmartList&lt;/code&gt; directly from the TeaQL Core engine (which comes with multi-dimensional facet data embedded) and formats it into the web response automatically:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Get task list, with the engine calculating status-aggregated facets at the same time&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;smart_list&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.with_status_facets&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.execute_for_smart_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;// Convert it into a standard Web API response containing both data and facets with one line of code&lt;/span&gt;
&lt;span class="nn"&gt;WebResponse&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;from_smart_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;smart_list&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Once the frontend receives the JSON, the &lt;code&gt;data&lt;/code&gt; array is used to render the main list, and the &lt;code&gt;facets&lt;/code&gt; dictionary is immediately ready to populate the sidebar filter options.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. The Red Module: Distributed Cache with a Single Line of Code
&lt;/h2&gt;

&lt;p&gt;As concurrency increases, single-machine in-memory cache often reaches its limits. To address this, we launched the &lt;strong&gt;&lt;code&gt;teaql-cache-integration-redis&lt;/code&gt;&lt;/strong&gt; module.&lt;/p&gt;

&lt;p&gt;The core philosophy of this module is: &lt;strong&gt;do not change any upper-level business code; simply replace the underlying provider to transition smoothly from single-machine to distributed caching&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It fully implements TeaQL's runtime &lt;code&gt;DataStore&lt;/code&gt; trait. Developers and AI agents write the exact same, simple and unified syntax:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Business code always uses this single syntax, independent of physical storage&lt;/span&gt;
&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="nf"&gt;.put&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"daily_task_stats"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;stats_value&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nf"&gt;Some&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;3600&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;stats&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="nf"&gt;.get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"daily_task_stats"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;At the initialization level, the architect only needs to inject the &lt;code&gt;RedisDataStore&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;redis_store&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;RedisDataStore&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;new&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"redis://127.0.0.1:6379/0"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;runtime&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;TeaRuntime&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;builder&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.with_data_store&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;redis_store&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;// Instantly switch to distributed caching&lt;/span&gt;
    &lt;span class="nf"&gt;.build&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Summary: Moving Toward the Ultimate Agentic State
&lt;/h2&gt;

&lt;p&gt;The introduction of these two new modules is far more than just adding a couple of adapters. Their essence lies in &lt;strong&gt;reducing the external entropy of the system&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Web module&lt;/strong&gt; collapses raw, messy HTTP protocols into a structured &lt;code&gt;UserContext&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;Red module&lt;/strong&gt; abstracts complex Redis drivers into a unified &lt;code&gt;DataStore&lt;/code&gt; interface.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;When an AI agent writes business code on top of TeaQL, it only faces one clean pathway: &lt;strong&gt;grab the Context, access data, and return a Response&lt;/strong&gt;. No protocol bickering, no switching between different SDKs.&lt;/p&gt;

&lt;p&gt;TeaQL digests all the low-level heavy lifting inside the framework kernel, allowing the future of software development to truly focus on business value.&lt;/p&gt;

</description>
      <category>rust</category>
      <category>axum</category>
      <category>redis</category>
      <category>web</category>
    </item>
    <item>
      <title>The Return of E Expressions: Fluent Chaining and Structured Panics for AI Auto-Healing</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Sat, 01 Aug 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/philipgreat/the-return-of-e-expressions-fluent-chaining-and-structured-panics-for-ai-auto-healing-54e0</link>
      <guid>https://dev.to/philipgreat/the-return-of-e-expressions-fluent-chaining-and-structured-panics-for-ai-auto-healing-54e0</guid>
      <description>&lt;p&gt;In the evolution of TeaQL, we've constantly navigated the tension between developer ergonomics and idiomatic Rust. Recently, we made a bold decision: we are bringing back the beloved &lt;code&gt;E::&lt;/code&gt; fluent expression chain to Rust.&lt;/p&gt;

&lt;p&gt;But this isn't a simple rollback. We've redesigned it from the ground up with zero-cost reference chaining and introduced a revolutionary structured panic mechanism that turns runtime errors into self-healing instructions for AI agents.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Ping-Pong of API Design
&lt;/h2&gt;

&lt;p&gt;Early in our Rust port, we attempted to replicate Java's &lt;code&gt;E::&lt;/code&gt; expression wrappers. However, to satisfy the borrow checker without complex lifetime annotations, we ended up requiring &lt;code&gt;.clone()&lt;/code&gt; on entire entity graphs. This was unacceptable in Rust.&lt;/p&gt;

&lt;p&gt;Our first reaction was to swing the pendulum the other way. We introduced &lt;code&gt;eval_xxx()&lt;/code&gt; methods and the &lt;code&gt;EvalResult&lt;/code&gt; enum, forcing developers to use combinators like &lt;code&gt;.and_then()&lt;/code&gt; to safely traverse graphs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="nf"&gt;.eval_platform&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.and_then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"platform"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="nf"&gt;.eval_company&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.and_then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"company"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="nf"&gt;.eval_name&lt;/span&gt;&lt;span class="p"&gt;()));&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;While this was memory-safe and zero-cost, it destroyed the developer experience. As we often say: &lt;strong&gt;"Fluent expressions are mental candy for humans."&lt;/strong&gt; Writing deeply nested closures just to read a nested property felt punishing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Bringing Back &lt;code&gt;E::&lt;/code&gt; (The Right Way)
&lt;/h2&gt;

&lt;p&gt;We realized we could have our cake and eat it too. By carefully crafting lifetime-bound wrapper structs in the code generator, we brought back the &lt;code&gt;E::&lt;/code&gt; syntax without any of the &lt;code&gt;.clone()&lt;/code&gt; overhead. &lt;/p&gt;

&lt;p&gt;You can now write fluent chains in multiple ways depending on your error-handling preference:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// 1. Strict evaluation (Panics with structured AI diagnostic if missing)&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;E&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;user&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.get_platform&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.get_company&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.get_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.unwrap&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

&lt;span class="c1"&gt;// 2. Safe Optional evaluation (Returns None if logically missing or naturally Null)&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="nf"&gt;Some&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;E&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;user&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.get_platform&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.get_company&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.get_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.eval&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nd"&gt;println!&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Found name: {}"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;// 3. Fluent fallback (Provides a default if missing or Null)&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;E&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;user&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.get_platform&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.get_company&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.get_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.or_else&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Unknown Company"&lt;/span&gt;&lt;span class="nf"&gt;.to_string&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Under the hood, all of these are zero-cost abstractions that simply pass references along the chain until the final terminator (&lt;code&gt;unwrap&lt;/code&gt;, &lt;code&gt;eval&lt;/code&gt;, or &lt;code&gt;or_else&lt;/code&gt;) is called.&lt;/p&gt;

&lt;h2&gt;
  
  
  Strict Panics: Rust's Bottom Line
&lt;/h2&gt;

&lt;p&gt;But what happens if you try to traverse a relation that wasn't loaded from the database? In Java, you might get a silent null or a late &lt;code&gt;NullPointerException&lt;/code&gt;. In our previous &lt;code&gt;eval_xxx&lt;/code&gt; iteration, you got a safe &lt;code&gt;EvalResult::NotLoaded&lt;/code&gt; enum.&lt;/p&gt;

&lt;p&gt;With the return of &lt;code&gt;E::&lt;/code&gt;, we decided to embrace a core Rust philosophy: &lt;strong&gt;Fail fast and fail loudly.&lt;/strong&gt; &lt;/p&gt;

&lt;p&gt;If you access an unloaded relation, the expression evaluates to a panic. But this is not your typical panic. It is a &lt;strong&gt;Structured Logic Bug Panic&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Designing for AI: The Structured Panic
&lt;/h2&gt;

&lt;p&gt;When building AI-native frameworks, errors shouldn't just halt execution; they should provide the exact recipe to fix the bug.&lt;/p&gt;

&lt;p&gt;When an &lt;code&gt;E::&lt;/code&gt; expression encounters an unloaded relation, it triggers a highly structured diagnostic panic that looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;================================================================================
☕ TeaQL Logic Bug Detected ☕
Severity: FATAL - System halted to prevent undefined business logic.

[Human Message]
You attempted to access a relation that was not loaded in the initial query.
Root Entity: User(id=42)
Attempted Path: platform.company.name

[Diagnostic Context]
original_expr_with_broken_point: E::user(id=42).get_platform().get_company()&amp;lt;broken&amp;gt;.get_name()
missing_preload: select_company()
suggested_fix: .select_platform_with(Q::platforms().select_company())

================================================================================
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  The Magic of &lt;code&gt;&amp;lt;broken&amp;gt;&lt;/code&gt;
&lt;/h3&gt;

&lt;p&gt;The most crucial addition here is the &lt;code&gt;original_expr_with_broken_point&lt;/code&gt; field. By injecting a visual &lt;code&gt;&amp;lt;broken&amp;gt;&lt;/code&gt; marker exactly where the chain failed, we provide immense context. &lt;/p&gt;

&lt;p&gt;When an AI agent (like our coding assistants) runs a test and hits this panic, it doesn't need to guess where the data is missing. It reads the structured payload, spots the &lt;code&gt;&amp;lt;broken&amp;gt;&lt;/code&gt; marker, and immediately knows that the &lt;code&gt;company&lt;/code&gt; relation needs to be loaded. It even gets the exact &lt;code&gt;suggested_fix&lt;/code&gt; to append to its query builder.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;By combining zero-cost reference wrappers with highly structured, AI-readable panics, we've achieved the holy grail of framework design:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Human Ergonomics:&lt;/strong&gt; Developers get the "mental candy" of fluent &lt;code&gt;.get_foo().get_bar()&lt;/code&gt; chaining.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Performance:&lt;/strong&gt; Zero allocations, purely reference-driven.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI Auto-Healing:&lt;/strong&gt; When things break, the framework hands the AI the exact instructions needed to rewrite its query and heal the code automatically.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;In the AI era, an error is no longer a dead end—it's just a prompt for the next self-correction.&lt;/p&gt;

</description>
      <category>rust</category>
      <category>ainative</category>
      <category>orm</category>
      <category>teaql</category>
    </item>
    <item>
      <title>Kernel-Level Audit &amp; Privacy: Building Resilient Audit Chains in the AI Coding Era</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Fri, 31 Jul 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/philipgreat/kernel-level-audit-privacy-building-resilient-audit-chains-in-the-ai-coding-era-mg0</link>
      <guid>https://dev.to/philipgreat/kernel-level-audit-privacy-building-resilient-audit-chains-in-the-ai-coding-era-mg0</guid>
      <description>&lt;p&gt;In the era of AI Coding, business code may be co-generated and modified by human developers, AI agents, or automated tools.&lt;br&gt;
This brings a new challenge:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;While business logic is becoming increasingly easy to generate automatically, the audit chain must not become fragile as a result.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Traditional audit systems often rely on business code to actively record logs. However, in AI Coding scenarios, this approach carries clear risks:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;AI might forget to write audit logs;&lt;/li&gt;
&lt;li&gt;AI might accidentally disable logs;&lt;/li&gt;
&lt;li&gt;AI might generate code that bypasses audits;&lt;/li&gt;
&lt;li&gt;Business code might unintentionally record sensitive plain text;&lt;/li&gt;
&lt;li&gt;A &lt;code&gt;custom audit hook&lt;/code&gt; might access raw data it shouldn't see;&lt;/li&gt;
&lt;li&gt;Long strings, JSON payloads, or execution logs might cause audit log bloating or even out-of-memory (OOM) errors.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Therefore, TeaQL underwent a low-level refactoring to move auditing capabilities into the framework kernel rather than leaving them entirely to the business code. We established the following core principles:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Audit must be kernel-level.
Business code may enrich audit trails, but it cannot erase them.
Sensitive fields do not disappear; only their plain text disappears.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  1. Kernel-Level Auditing to Prevent Mistakes Automatically
&lt;/h2&gt;

&lt;p&gt;Humans don't have the energy to make every possible mistake; our primary targets for defense are actually AI and automatically generated code. If an AI can write business logic, it is equally capable of mistakenly wiping out the audit chain or unintentionally logging sensitive plain text (such as passwords, tokens, etc.).&lt;/p&gt;

&lt;p&gt;To guard against this, the TeaQL auditing system cannot be altered arbitrarily from the outside. In the TeaQL Rust Runtime, every data mutation (Insert/Update/Delete) is automatically triggered by the kernel.&lt;/p&gt;

&lt;h3&gt;
  
  
  Dual-Channel Design: Isolating Internal Auditing from Custom Hooks
&lt;/h3&gt;

&lt;p&gt;In previous versions, we provided a unified &lt;code&gt;ctx.set_event_sink()&lt;/code&gt;, but this introduced conflicts. If a client overrode the sink to implement WebSocket push notifications, the infrastructure-level compliance audit logs would be lost.&lt;/p&gt;

&lt;p&gt;To solve this, we strictly isolate internal system auditing from custom external user hooks:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Immutable Internal Auditing (Raw Event Sink)&lt;/strong&gt;:
&lt;code&gt;set_event_sink&lt;/code&gt; has been demoted to a &lt;code&gt;pub(crate)&lt;/code&gt; internal behavior and is controlled solely by environment variables (e.g., &lt;code&gt;TEAQL_AUDIT_ENABLED&lt;/code&gt;). AI-generated business code or client-side code &lt;strong&gt;can never&lt;/strong&gt; modify or disable internal compliance auditing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Secure External Customization (Custom Event Sink)&lt;/strong&gt;:
We provide a clear public API: &lt;code&gt;ctx.set_custom_event_sink()&lt;/code&gt;. This is the sole hook left open to the outside, allowing users to intercept log messages and perform further business processing (such as updating the UI in our robot kanban demo).&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  2. The Evolution from RawAuditEvent to SafeAuditEvent
&lt;/h2&gt;

&lt;p&gt;Isolating the sinks is not enough on its own. While internal compliance audits can write directly to databases or log collectors, &lt;strong&gt;events exposed to the external custom sink must be safe&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;If we were to pass the complete raw event stream to a custom sink, it would mean client code or AI-generated logic could easily access raw sensitive data they shouldn't see, or crash the memory with bloated text.&lt;/p&gt;

&lt;p&gt;To completely solve this, we split the event model into two layers:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;code&gt;RawAuditEvent&lt;/code&gt;: Contains 100% complete mutation data and raw requests, &lt;strong&gt;restricted for internal low-level use only&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;SafeAuditEvent&lt;/code&gt;: A sanitized, masked, and truncated event model &lt;strong&gt;exposed to the outside&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Metadata-Based Automatic Masking and Truncation
&lt;/h3&gt;

&lt;p&gt;The core philosophy of TeaQL is: &lt;strong&gt;Model is the Single Source of Truth.&lt;/strong&gt;&lt;br&gt;
By adding specific metadata attributes in the XML model, the code generator automatically generates Rust data structure descriptors (&lt;code&gt;EntityDescriptor&lt;/code&gt;) containing safety policies.&lt;/p&gt;

&lt;p&gt;In the latest &lt;code&gt;model.xml&lt;/code&gt;, developers can define masking and truncation rules directly on the Entity:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight xml"&gt;&lt;code&gt;&lt;span class="nt"&gt;&amp;lt;task_execution_log&lt;/span&gt;
    &lt;span class="na"&gt;task=&lt;/span&gt;&lt;span class="s"&gt;"task()"&lt;/span&gt;
    &lt;span class="na"&gt;action=&lt;/span&gt;&lt;span class="s"&gt;"string()"&lt;/span&gt;
    &lt;span class="na"&gt;detail=&lt;/span&gt;&lt;span class="s"&gt;"string()"&lt;/span&gt;
    &lt;span class="na"&gt;_audit_mask_fields=&lt;/span&gt;&lt;span class="s"&gt;"detail"&lt;/span&gt;
    &lt;span class="na"&gt;_audit_value_max_len=&lt;/span&gt;&lt;span class="s"&gt;"2048"&lt;/span&gt;
    &lt;span class="na"&gt;_data_service=&lt;/span&gt;&lt;span class="s"&gt;"meilisearch"&lt;/span&gt;
    &lt;span class="na"&gt;_name=&lt;/span&gt;&lt;span class="s"&gt;"Task Execution Log"&lt;/span&gt;
&lt;span class="nt"&gt;/&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;When a &lt;code&gt;RawAuditEvent&lt;/code&gt; is passed to the &lt;code&gt;CustomEventSink&lt;/code&gt;, the kernel-space &lt;code&gt;UserContext&lt;/code&gt; retrieves the security descriptor for the corresponding entity via the &lt;code&gt;MetadataStore&lt;/code&gt; and converts the &lt;code&gt;RawAuditEvent&lt;/code&gt; into a &lt;code&gt;SafeAuditEvent&lt;/code&gt; (a lock-free, highly efficient conversion process).&lt;/p&gt;

&lt;p&gt;This conversion process automatically performs two core defenses:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Field-Level Masking&lt;/strong&gt;:&lt;br&gt;
If a field is listed in &lt;code&gt;_audit_mask_fields&lt;/code&gt; (such as passwords or sensitive content), TeaQL &lt;strong&gt;does not&lt;/strong&gt; delete the field from the audit record. Instead, it replaces its value with &lt;code&gt;*** MASKED ***&lt;/code&gt;. This preserves the principle that "sensitive fields do not disappear; only their plain text disappears," keeping the audit trail intact.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Automatic Long-Text Truncation&lt;/strong&gt;:&lt;br&gt;
If a field contains a multi-megabyte JSON payload or error stack, sending it directly to an external hook could trigger an OOM error. TeaQL automatically truncates long strings in the safe event to a specified length based on &lt;code&gt;_audit_value_max_len&lt;/code&gt;, appending &lt;code&gt;...(truncated)&lt;/code&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  3. Preventative Design in Modeling: A Fail-Fast Linter for AI
&lt;/h2&gt;

&lt;p&gt;Kernel-level interception at runtime is not enough. If an AI or developer &lt;strong&gt;forgets&lt;/strong&gt; to add the &lt;code&gt;_audit_mask_fields&lt;/code&gt; tag to highly sensitive fields like &lt;code&gt;password&lt;/code&gt; or &lt;code&gt;ssn&lt;/code&gt; during the modeling phase (when writing XML), plain text would still leak at runtime.&lt;/p&gt;

&lt;p&gt;To address this, we have natively integrated a &lt;strong&gt;KSML Static Analysis and Evaluation Linter&lt;/strong&gt; into the compile and code generation phase of TeaQL.&lt;/p&gt;

&lt;p&gt;When a model is submitted to the framework, the &lt;code&gt;PrivacyAuditEvaluationRule&lt;/code&gt; automatically performs lexical evaluations on all fields. Built specifically for Agentic Coding, this mechanism supports "fail-fast and self-healing":&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Blocking Errors (Error)&lt;/strong&gt;: When core high-risk privacy fields (like &lt;code&gt;password&lt;/code&gt;, &lt;code&gt;token&lt;/code&gt;, or &lt;code&gt;ssn&lt;/code&gt;) are detected without masking, the engine &lt;strong&gt;blocks code generation&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Actionable Fix Examples&lt;/strong&gt;: The engine no longer throws cold stack traces; instead, it outputs clear snippets showing how to fix the issue. Whether a human is viewing the CLI or an AI is parsing a JSON response, they receive precise instructions:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="w"&gt;   &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
     &lt;/span&gt;&lt;span class="nl"&gt;"ruleId"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"KSML-PRIVACY-001-ERR"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
     &lt;/span&gt;&lt;span class="nl"&gt;"title"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"High Sensitivity Data Unmasked"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
     &lt;/span&gt;&lt;span class="nl"&gt;"message"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"The field 'password' in entity 'user' contains highly sensitive keywords. You MUST mask it.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;Fix Example: Update your XML entity definition:&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;&amp;lt;user ... _audit_mask_fields=&lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s2"&gt;password&lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s2"&gt; /&amp;gt;"&lt;/span&gt;&lt;span class="w"&gt;
   &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Soft Warnings &amp;amp; Suggestions&lt;/strong&gt;: For secondary sensitive fields like &lt;code&gt;user_email&lt;/code&gt; or &lt;code&gt;phone&lt;/code&gt;, the system does not block generation but packages warnings into &lt;code&gt;.teaql/evaluation_report.json&lt;/code&gt;. The IDE plugin or an AI's subsequent task can read this report to display warning lines in the XML editor.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;With the rise of AI Coding, &lt;strong&gt;defensive design&lt;/strong&gt; is no longer just about protecting against human typos—it's about keeping automated systems from running out of control in edge cases.&lt;/p&gt;

&lt;p&gt;By (1) isolating the immutable compliance sink and (2) introducing the &lt;code&gt;SafeAuditEvent&lt;/code&gt; automatically sanitized via model metadata, TeaQL builds an impassable barrier: &lt;strong&gt;no matter what business code the AI generates, it can never bypass audit baselines, nor can it accidentally leak sensitive data.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>rust</category>
      <category>architecture</category>
      <category>security</category>
      <category>audit</category>
    </item>
    <item>
      <title>TeaQL Java Runtime: Modular Refactor, Multi-Framework Ready, Rust-Aligned</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Fri, 31 Jul 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/philipgreat/teaql-java-runtime-modular-refactor-multi-framework-ready-rust-aligned-35no</link>
      <guid>https://dev.to/philipgreat/teaql-java-runtime-modular-refactor-multi-framework-ready-rust-aligned-35no</guid>
      <description>&lt;p&gt;We refactored the TeaQL Java runtime (&lt;code&gt;teaql-java&lt;/code&gt;) to achieve three goals:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;JPMS module boundaries&lt;/strong&gt; — seal internal packages, expose only what generated code needs&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Spring Boot independence&lt;/strong&gt; — run without Spring Boot using a plain &lt;code&gt;main()&lt;/code&gt; function&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rust alignment&lt;/strong&gt; — dual-layer audit logging, compile-time query enforcement, &lt;code&gt;RequestPolicy&lt;/code&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Why Refactor?
&lt;/h2&gt;

&lt;p&gt;The Java runtime had grown organically. All classes lived in flat packages — any code could access &lt;code&gt;RepositoryAdaptor&lt;/code&gt;, &lt;code&gt;GLobalResolver&lt;/code&gt;, &lt;code&gt;GraphMutationEngine&lt;/code&gt;, and other internals. The Rust version had already solved this with proper module boundaries and ownership-based safety. We wanted the same discipline in Java.&lt;/p&gt;

&lt;h2&gt;
  
  
  Architecture: Three Layers
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;┌──────────────────────────────────────────────────┐
│ Layer 1: Application                             │
│   Spring Boot App / Plain Java App / Android App │
│   ↕ limited interfaces                           │
├──────────────────────────────────────────────────┤
│ Layer 2: Generated Code (teaql-code-gen output)  │
│   Entity, Request(Q), Checker, BaseService       │
│   ↕ limited interfaces                           │
├──────────────────────────────────────────────────┤
│ Layer 3: Runtime (teaql modules)                 │
│   public API + sealed internal implementation     │
└──────────────────────────────────────────────────┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  JPMS Module Boundaries
&lt;/h2&gt;

&lt;p&gt;We added &lt;code&gt;module-info.java&lt;/code&gt; across the Java runtime modules. The core &lt;code&gt;teaql&lt;/code&gt; module exports only what generated code needs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="n"&gt;module&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="c1"&gt;// === Public API (generated code uses these) ===&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;checker&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;criteria&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;meta&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;translation&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;web&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;value&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;lock&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;log&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;

    &lt;span class="c1"&gt;// === Sealed internals (precise authorization) ===&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;repository&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;sql&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;memory&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;sql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;portable&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;exports&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;internal&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;autoconfigure&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;io&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;teaql&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;sql&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Internal packages&lt;/strong&gt; stay outside the normal application API surface:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;graph&lt;/code&gt; — mutation engine&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;event&lt;/code&gt; — event classes&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;xls&lt;/code&gt; — Excel export&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;idgenerator&lt;/code&gt; — ID generation&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;parser&lt;/code&gt; — expression parsers&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;internal&lt;/code&gt; — &lt;code&gt;RepositoryAdaptor&lt;/code&gt;, &lt;code&gt;GLobalResolver&lt;/code&gt;, &lt;code&gt;TempRequest&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Translator implementations under &lt;code&gt;language&lt;/code&gt; are public runtime types, with&lt;br&gt;
narrow reflective access where framework integration needs it.&lt;/p&gt;

&lt;p&gt;We moved 5 classes from &lt;code&gt;io.teaql.data&lt;/code&gt; to &lt;code&gt;io.teaql.data.internal&lt;/code&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;RepositoryAdaptor&lt;/code&gt; — graph save orchestrator&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;GLobalResolver&lt;/code&gt; — static resolver holder&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;TempRequest&lt;/code&gt; — temporary query wrapper&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;RequestAggregationCacheKey&lt;/code&gt; — cache key&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;SimpleChineseViewTranslator&lt;/code&gt; — internal translator&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;
  
  
  Spring Boot Independence
&lt;/h2&gt;

&lt;p&gt;We created a &lt;code&gt;TQLResolver&lt;/code&gt; interface that replaces Spring's &lt;code&gt;ApplicationContext&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kd"&gt;interface&lt;/span&gt; &lt;span class="nc"&gt;TQLResolver&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="no"&gt;T&lt;/span&gt; &lt;span class="nf"&gt;getBean&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;Class&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;clazz&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nc"&gt;List&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nf"&gt;getBeans&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;Class&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;clazz&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="no"&gt;T&lt;/span&gt; &lt;span class="nf"&gt;getBean&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="nc"&gt;Repository&lt;/span&gt; &lt;span class="nf"&gt;resolveRepository&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt; &lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="nc"&gt;EntityDescriptor&lt;/span&gt; &lt;span class="nf"&gt;resolveEntityDescriptor&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt; &lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For non-Spring environments, a simple &lt;code&gt;Map&lt;/code&gt;-based implementation works:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;static&lt;/span&gt; &lt;span class="kd"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;SimpleResolver&lt;/span&gt; &lt;span class="kd"&gt;implements&lt;/span&gt; &lt;span class="nc"&gt;TQLResolver&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="kd"&gt;private&lt;/span&gt; &lt;span class="kd"&gt;final&lt;/span&gt; &lt;span class="nc"&gt;Map&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;Class&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;?&amp;gt;,&lt;/span&gt; &lt;span class="nc"&gt;Object&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;beans&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;HashMap&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&amp;gt;();&lt;/span&gt;
    &lt;span class="kd"&gt;private&lt;/span&gt; &lt;span class="kd"&gt;final&lt;/span&gt; &lt;span class="nc"&gt;Map&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nc"&gt;Repository&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;?&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;repos&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;HashMap&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&amp;gt;();&lt;/span&gt;

    &lt;span class="nd"&gt;@Override&lt;/span&gt; &lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="no"&gt;T&lt;/span&gt; &lt;span class="nf"&gt;getBean&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;Class&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;clazz&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;clazz&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;cast&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;beans&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;get&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;clazz&lt;/span&gt;&lt;span class="o"&gt;));&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
    &lt;span class="nd"&gt;@Override&lt;/span&gt; &lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="nc"&gt;Repository&lt;/span&gt; &lt;span class="nf"&gt;resolveRepository&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt; &lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;repos&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;get&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A robot-kanban demo app runs with a plain &lt;code&gt;main()&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kd"&gt;static&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt;&lt;span class="o"&gt;[]&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="nc"&gt;DataSource&lt;/span&gt; &lt;span class="n"&gt;dataSource&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;createDataSource&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt; &lt;span class="c1"&gt;// SQLite&lt;/span&gt;
    &lt;span class="nc"&gt;EntityMetaFactory&lt;/span&gt; &lt;span class="n"&gt;metaFactory&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;SimpleEntityMetaFactory&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
    &lt;span class="c1"&gt;// ... register metadata, repositories, checkers&lt;/span&gt;

    &lt;span class="nc"&gt;TQLResolver&lt;/span&gt; &lt;span class="n"&gt;resolver&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;SimpleResolver&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;metaFactory&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;repos&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;checkers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;config&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="nc"&gt;GLobalResolver&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;registerResolver&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;resolver&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;

    &lt;span class="nc"&gt;UserContext&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;UserContext&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
    &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;setRequestPolicy&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;PurposeRequestPolicy&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
    &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;setLogManager&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;LogManager&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;

    &lt;span class="c1"&gt;// Use Q/E API&lt;/span&gt;
    &lt;span class="no"&gt;Q&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;taskStatuses&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt;
        &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"查询任务状态"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
        &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"展示看板"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
        &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;executeForList&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Compile-Time Query Enforcement
&lt;/h2&gt;

&lt;p&gt;In Rust, you literally cannot call &lt;code&gt;execute_for_list&lt;/code&gt; without setting &lt;code&gt;comment&lt;/code&gt; — the type system prevents it. In Java, we achieve similar约束 with &lt;code&gt;ExecutableRequest&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="c1"&gt;// purpose() is the terminal method — returns ExecutableRequest&lt;/span&gt;
&lt;span class="no"&gt;Q&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;tasks&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;filterByName&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"xxx"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"查询任务"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"展示看板"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;     &lt;span class="c1"&gt;// → ExecutableRequest&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;executeForList&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;    &lt;span class="c1"&gt;// only ExecutableRequest has this&lt;/span&gt;

&lt;span class="c1"&gt;// Without purpose(): no ExecutableRequest, no executeForList&lt;/span&gt;
&lt;span class="no"&gt;Q&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;tasks&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;executeForList&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;  &lt;span class="c1"&gt;// compile error&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;purpose()&lt;/code&gt; method validates that &lt;code&gt;comment&lt;/code&gt; is set:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="nc"&gt;ExecutableRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nf"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt; &lt;span class="n"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;comment&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="n"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;isEmpty&lt;/span&gt;&lt;span class="o"&gt;())&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;throw&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nf"&gt;RepositoryException&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;
            &lt;span class="s"&gt;"[PURPOSE FAILED] Missing .comment() on "&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;getTypeName&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
    &lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;purpose&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;ExecutableRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&amp;gt;(&lt;/span&gt;&lt;span class="k"&gt;this&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  RequestPolicy (Rust Alignment)
&lt;/h2&gt;

&lt;p&gt;We ported Rust's &lt;code&gt;RequestPolicy&lt;/code&gt; trait to Java:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kd"&gt;interface&lt;/span&gt; &lt;span class="nc"&gt;RequestPolicy&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;default&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;enforceSelect&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;UserContext&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nc"&gt;SearchRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;?&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;query&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{}&lt;/span&gt;
    &lt;span class="k"&gt;default&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;enforceInsert&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;UserContext&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nc"&gt;Entity&lt;/span&gt; &lt;span class="n"&gt;entity&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{}&lt;/span&gt;
    &lt;span class="k"&gt;default&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;enforceUpdate&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;UserContext&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nc"&gt;Entity&lt;/span&gt; &lt;span class="n"&gt;entity&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{}&lt;/span&gt;
    &lt;span class="k"&gt;default&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;enforceDelete&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;UserContext&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nc"&gt;Entity&lt;/span&gt; &lt;span class="n"&gt;entity&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{}&lt;/span&gt;
    &lt;span class="k"&gt;default&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;enforceRecover&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;UserContext&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nc"&gt;Entity&lt;/span&gt; &lt;span class="n"&gt;entity&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;PurposeRequestPolicy&lt;/code&gt; enforces both query purpose and audit comments:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;setRequestPolicy&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;PurposeRequestPolicy&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;

&lt;span class="c1"&gt;// Rejects: no purpose&lt;/span&gt;
&lt;span class="no"&gt;Q&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;taskStatuses&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"x"&lt;/span&gt;&lt;span class="o"&gt;).&lt;/span&gt;&lt;span class="na"&gt;executeForList&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="c1"&gt;// → [PURPOSE REQUIRED] Query on TaskStatus rejected.&lt;/span&gt;

&lt;span class="c1"&gt;// Rejects: no auditAs&lt;/span&gt;
&lt;span class="n"&gt;entity&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;save&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="c1"&gt;// → [AUDIT REQUIRED] insert on Task rejected.&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Dual-Layer Audit &amp;amp; Logging
&lt;/h2&gt;

&lt;p&gt;The Rust design has two layers: a raw file log controlled by environment variables, and customizable app-level sinks with masked data. We ported this exactly.&lt;/p&gt;

&lt;h3&gt;
  
  
  Layer 1: Runtime (Environment Variables, No Code)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nv"&gt;TEAQL_LOG_ENDPOINT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;/var/log/teaql.log  &lt;span class="c"&gt;# file path&lt;/span&gt;
&lt;span class="nv"&gt;TEAQL_LOG_FORMAT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;human                 &lt;span class="c"&gt;# human | json&lt;/span&gt;
&lt;span class="nv"&gt;TEAQL_LOG_SELECT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;true&lt;/span&gt;                  &lt;span class="c"&gt;# log SELECT queries&lt;/span&gt;
&lt;span class="nv"&gt;TEAQL_LOG_MUTATION&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;true&lt;/span&gt;                &lt;span class="c"&gt;# log mutations&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Writes &lt;strong&gt;raw, unmasked&lt;/strong&gt; SQL and audit information. No code customization.&lt;/p&gt;

&lt;h3&gt;
  
  
  Layer 2: App Layer (Customizable, Masked)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="nc"&gt;LogManager&lt;/span&gt; &lt;span class="n"&gt;logManager&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;LogManager&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;

&lt;span class="c1"&gt;// Audit sink: receives masked events&lt;/span&gt;
&lt;span class="n"&gt;logManager&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;addAuditSink&lt;/span&gt;&lt;span class="o"&gt;((&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;event&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;saveToDatabase&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;event&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;sendToMessageQueue&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;event&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="o"&gt;});&lt;/span&gt;

&lt;span class="c1"&gt;// Log sink: receives masked SQL logs&lt;/span&gt;
&lt;span class="n"&gt;logManager&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;addLogSink&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;entry&lt;/span&gt; &lt;span class="o"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;showOnUI&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;entry&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="o"&gt;});&lt;/span&gt;

&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;setLogManager&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;logManager&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Masking (Aligned with Rust)
&lt;/h3&gt;

&lt;p&gt;The masking algorithm matches Rust's &lt;code&gt;mask_audit_value&lt;/code&gt; and &lt;code&gt;limit_audit_value&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Field-level masking (from EntityDescriptor._audit_mask_fields)&lt;/span&gt;
&lt;span class="n"&gt;maskAuditValue&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"12345678"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="err"&gt;→&lt;/span&gt; &lt;span class="s"&gt;"12****78"&lt;/span&gt;
&lt;span class="n"&gt;maskAuditValue&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"1234"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;     &lt;span class="err"&gt;→&lt;/span&gt; &lt;span class="s"&gt;"****"&lt;/span&gt;

&lt;span class="c1"&gt;// Length truncation (from EntityDescriptor._audit_value_max_len)&lt;/span&gt;
&lt;span class="n"&gt;limitAuditValue&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"very long string..."&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;200&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="err"&gt;→&lt;/span&gt; &lt;span class="s"&gt;"head...tail"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Configuration comes from the entity model:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight xml"&gt;&lt;code&gt;&lt;span class="nt"&gt;&amp;lt;task_execution_log&lt;/span&gt;
    &lt;span class="na"&gt;_audit_mask_fields=&lt;/span&gt;&lt;span class="s"&gt;"detail"&lt;/span&gt;
    &lt;span class="na"&gt;_audit_value_max_len=&lt;/span&gt;&lt;span class="s"&gt;"2048"&lt;/span&gt;
&lt;span class="nt"&gt;/&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Multi-Framework Support via TeaQLDatabase
&lt;/h2&gt;

&lt;p&gt;We introduced &lt;code&gt;TeaQLDatabase&lt;/code&gt; as the universal database abstraction layer. Portable runtimes share the same SQL repository shape (&lt;code&gt;PortableSQLRepository&lt;/code&gt;), only the database driver differs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Entity → PortableSQLRepository → TeaQLDatabase → Database
              ↑                    ↑
        Reuses SQL building    Abstraction layer
        (ExpressionHelper)     Android: SQLiteDatabase
                               Quarkus: AgroalDataSource
                               Micronaut: DataSource
                               JVM test: JDBC
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Android
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="nc"&gt;TeaQLDatabase&lt;/span&gt; &lt;span class="n"&gt;db&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;AndroidDatabase&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sqLiteDatabase&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Quarkus (CDI integration)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight xml"&gt;&lt;code&gt;&lt;span class="nt"&gt;&amp;lt;dependency&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;groupId&amp;gt;&lt;/span&gt;io.teaql&lt;span class="nt"&gt;&amp;lt;/groupId&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;artifactId&amp;gt;&lt;/span&gt;teaql-quarkus&lt;span class="nt"&gt;&amp;lt;/artifactId&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/dependency&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="nd"&gt;@Inject&lt;/span&gt;
&lt;span class="nc"&gt;TeaQLDatabase&lt;/span&gt; &lt;span class="n"&gt;db&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;TeaQLProducer&lt;/code&gt; provides default beans via CDI &lt;code&gt;@Produces&lt;/code&gt;. Application can override any bean.&lt;/p&gt;

&lt;h3&gt;
  
  
  Micronaut (Bean Factory integration)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight xml"&gt;&lt;code&gt;&lt;span class="nt"&gt;&amp;lt;dependency&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;groupId&amp;gt;&lt;/span&gt;io.teaql&lt;span class="nt"&gt;&amp;lt;/groupId&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;artifactId&amp;gt;&lt;/span&gt;teaql-micronaut&lt;span class="nt"&gt;&amp;lt;/artifactId&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;/dependency&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="nd"&gt;@Inject&lt;/span&gt;
&lt;span class="nc"&gt;TeaQLDatabase&lt;/span&gt; &lt;span class="n"&gt;db&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;TeaQLFactory&lt;/code&gt; provides default beans via &lt;code&gt;@Factory&lt;/code&gt; + &lt;code&gt;@Bean&lt;/code&gt;. Application can override any bean.&lt;/p&gt;

&lt;h3&gt;
  
  
  Plain Java (no framework)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="nc"&gt;TeaQLDatabase&lt;/span&gt; &lt;span class="n"&gt;db&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;QuarkusDatabase&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;dataSource&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt; &lt;span class="c1"&gt;// or any JDBC DataSource&lt;/span&gt;
&lt;span class="nc"&gt;EntityMetaFactory&lt;/span&gt; &lt;span class="n"&gt;metaFactory&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;SimpleEntityMetaFactory&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
&lt;span class="c1"&gt;// ... register metadata, repositories, checkers&lt;/span&gt;

&lt;span class="nc"&gt;TQLResolver&lt;/span&gt; &lt;span class="n"&gt;resolver&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;SimpleResolver&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;metaFactory&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;repos&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;checkers&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;config&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;span class="nc"&gt;GLobalResolver&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;registerResolver&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;resolver&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Key change: &lt;code&gt;ExpressionHelper.toSql()&lt;/code&gt; now accepts &lt;code&gt;SQLColumnResolver&lt;/code&gt; instead of &lt;code&gt;SQLRepository&lt;/code&gt;, so &lt;code&gt;PortableSQLRepository&lt;/code&gt; can reuse the expression parsing logic without depending on spring-jdbc.&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary Table
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Feature&lt;/th&gt;
&lt;th&gt;Rust&lt;/th&gt;
&lt;th&gt;Java&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Module boundaries&lt;/td&gt;
&lt;td&gt;Cargo workspace&lt;/td&gt;
&lt;td&gt;JPMS &lt;code&gt;module-info.java&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Query enforcement&lt;/td&gt;
&lt;td&gt;Compile-time (ownership)&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;ExecutableRequest&lt;/code&gt; + &lt;code&gt;purpose()&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;RequestPolicy&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;RequestPolicy&lt;/code&gt; trait&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;RequestPolicy&lt;/code&gt; interface&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit masking&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;audit_mask_fields&lt;/code&gt; per entity&lt;/td&gt;
&lt;td&gt;Same, via &lt;code&gt;EntityDescriptor&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SQL log&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;LogManager&lt;/code&gt; + env vars&lt;/td&gt;
&lt;td&gt;Same&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;App sinks&lt;/td&gt;
&lt;td&gt;&lt;code&gt;SafeAuditEventSink&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;AuditEventSink&lt;/code&gt; + &lt;code&gt;LogSink&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Non-Boot runtime&lt;/td&gt;
&lt;td&gt;Native&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;TQLResolver&lt;/code&gt; + &lt;code&gt;SimpleResolver&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Android-style portable SQL&lt;/td&gt;
&lt;td&gt;N/A&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;teaql-sql-portable&lt;/code&gt; + &lt;code&gt;TeaQLDatabase&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Quarkus support&lt;/td&gt;
&lt;td&gt;N/A&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;teaql-quarkus&lt;/code&gt; + CDI Producer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Micronaut support&lt;/td&gt;
&lt;td&gt;N/A&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;teaql-micronaut&lt;/code&gt; + Bean Factory&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DB abstraction&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;TeaQLDatabase&lt;/code&gt; trait&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;TeaQLDatabase&lt;/code&gt; interface&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The Java runtime is now modular, Spring Boot optional, multi-framework ready (Spring Boot / Quarkus / Micronaut / Android / Plain Java), and aligned with the Rust architecture on all critical design points.&lt;/p&gt;

</description>
      <category>java</category>
      <category>quarkus</category>
      <category>micronaut</category>
      <category>audit</category>
    </item>
    <item>
      <title>Enforcing Request Policy at the Runtime Boundary</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Thu, 30 Jul 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/philipgreat/enforcing-request-policy-at-the-runtime-boundary-1ff7</link>
      <guid>https://dev.to/philipgreat/enforcing-request-policy-at-the-runtime-boundary-1ff7</guid>
      <description>&lt;p&gt;In a multi-tenant business system, the dangerous query is often not obviously&lt;br&gt;
dangerous.&lt;/p&gt;

&lt;p&gt;A developer writes a useful request:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="no"&gt;Q&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;candidates&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;selectName&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;selectEmail&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;filterBySkill&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Java"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;page&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Query candidates"&lt;/span&gt;&lt;span class="o"&gt;).&lt;/span&gt;&lt;span class="na"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Load data"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;executeForList&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The request looks typed, generated, and harmless. But in a platform like Multi&lt;br&gt;
Talent, a candidate belongs to a customer account, a workspace, a recruiter&lt;br&gt;
team, and often a legal region. A useful query becomes unsafe if it can see&lt;br&gt;
outside those boundaries.&lt;/p&gt;

&lt;p&gt;That is why TeaQL treats request execution as a runtime boundary, not just a&lt;br&gt;
method call.&lt;/p&gt;
&lt;h2&gt;
  
  
  The Multi Talent Problem
&lt;/h2&gt;

&lt;p&gt;Imagine Multi Talent as a SaaS platform for recruiting agencies and enterprise&lt;br&gt;
hiring teams.&lt;/p&gt;

&lt;p&gt;The same TeaQL model may include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;candidates;&lt;/li&gt;
&lt;li&gt;talent profiles;&lt;/li&gt;
&lt;li&gt;resumes and attachments;&lt;/li&gt;
&lt;li&gt;interview records;&lt;/li&gt;
&lt;li&gt;offer workflows;&lt;/li&gt;
&lt;li&gt;customer accounts;&lt;/li&gt;
&lt;li&gt;recruiter teams;&lt;/li&gt;
&lt;li&gt;regional compliance metadata.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The query language should stay expressive. A team should be able to search&lt;br&gt;
candidates by skill, location, availability, interview status, and related job&lt;br&gt;
opening.&lt;/p&gt;

&lt;p&gt;But every query must also respect infrastructure and customer boundaries:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;customer A must never read customer B's candidates;&lt;/li&gt;
&lt;li&gt;a recruiter can only see candidates assigned to their team or allowed pool;&lt;/li&gt;
&lt;li&gt;regional data residency policy may limit which records can be loaded;&lt;/li&gt;
&lt;li&gt;raw SQL escape hatches should not bypass tenant rules;&lt;/li&gt;
&lt;li&gt;unlimited list requests should not become infrastructure abuse.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Those rules should not be copied into every controller.&lt;/p&gt;
&lt;h2&gt;
  
  
  The Wrong Place for the Rule
&lt;/h2&gt;

&lt;p&gt;One option is to add filters wherever a query is written:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="no"&gt;Q&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;candidates&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;filterByCustomer&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;currentCustomer&lt;/span&gt;&lt;span class="o"&gt;())&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;filterByRecruiterTeam&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;currentTeam&lt;/span&gt;&lt;span class="o"&gt;())&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;filterBySkill&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Java"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Query candidates"&lt;/span&gt;&lt;span class="o"&gt;).&lt;/span&gt;&lt;span class="na"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Load data"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;executeForList&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This works until one path forgets the filter. It also asks every feature author&lt;br&gt;
to understand every infrastructure and data-protection rule.&lt;/p&gt;

&lt;p&gt;Another option is to hide the query behind service methods. That can work for&lt;br&gt;
some workflows, but TeaQL deliberately gives teams a generated request language.&lt;br&gt;
The runtime should make that language safe instead of forcing teams to abandon&lt;br&gt;
it.&lt;/p&gt;
&lt;h2&gt;
  
  
  The Runtime Boundary
&lt;/h2&gt;

&lt;p&gt;TeaQL Java runtime exposes a dedicated &lt;code&gt;UserContext&lt;/code&gt; extension point for this&lt;br&gt;
final step:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;protected&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt; &lt;span class="kd"&gt;extends&lt;/span&gt; &lt;span class="nc"&gt;Entity&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nc"&gt;SearchRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nf"&gt;enforceRequestPolicy&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;SearchRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Every normal request execution path goes through this hook before the request is&lt;br&gt;
submitted to the repository:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;SearchRequest
  -&amp;gt; UserContext
  -&amp;gt; enforceRequestPolicy(...)
  -&amp;gt; Repository
  -&amp;gt; database provider
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That placement matters. It is late enough to see the actual request that is&lt;br&gt;
about to execute, but still early enough to change it or reject it.&lt;/p&gt;

&lt;p&gt;TeaQL Rust has the same runtime-boundary idea through &lt;code&gt;RequestPolicy&lt;/code&gt; on&lt;br&gt;
&lt;code&gt;UserContext&lt;/code&gt;. The Rust hook is platform-scoped and runs after entity-scoped&lt;br&gt;
repository behavior, so it can make the final decision before the request&lt;br&gt;
reaches the provider.&lt;/p&gt;
&lt;h2&gt;
  
  
  A Multi Talent Policy
&lt;/h2&gt;

&lt;p&gt;A Multi Talent project can extend its generated context and enforce the policy&lt;br&gt;
once:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kd"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;MultiTalentUserContext&lt;/span&gt; &lt;span class="kd"&gt;extends&lt;/span&gt; &lt;span class="nc"&gt;MultiTalentGeneratedUserContext&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;

    &lt;span class="nd"&gt;@Override&lt;/span&gt;
    &lt;span class="kd"&gt;protected&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt; &lt;span class="kd"&gt;extends&lt;/span&gt; &lt;span class="nc"&gt;Entity&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nc"&gt;SearchRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nf"&gt;enforceRequestPolicy&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;SearchRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="no"&gt;T&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;request&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="kd"&gt;super&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;enforceRequestPolicy&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;

        &lt;span class="nc"&gt;String&lt;/span&gt; &lt;span class="n"&gt;type&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getTypeName&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;

        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Candidate"&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;equals&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="s"&gt;"TalentProfile"&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;equals&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;))&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;appendSearchCriteria&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;
                    &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;createBasicSearchCriteria&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;
                            &lt;span class="s"&gt;"customerAccount"&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt;
                            &lt;span class="nc"&gt;Operator&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;EQUAL&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt;
                            &lt;span class="n"&gt;currentCustomerAccount&lt;/span&gt;&lt;span class="o"&gt;()));&lt;/span&gt;

            &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;appendSearchCriteria&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;
                    &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;createBasicSearchCriteria&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;
                            &lt;span class="s"&gt;"recruiterTeam"&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt;
                            &lt;span class="nc"&gt;Operator&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;IN&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt;
                            &lt;span class="n"&gt;visibleRecruiterTeams&lt;/span&gt;&lt;span class="o"&gt;()));&lt;/span&gt;
        &lt;span class="o"&gt;}&lt;/span&gt;

        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"ResumeAttachment"&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;equals&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;))&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
            &lt;span class="n"&gt;enforceRegionalAccess&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
        &lt;span class="o"&gt;}&lt;/span&gt;

        &lt;span class="n"&gt;rejectDangerousRequestShape&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;auditSensitiveRead&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;

        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The example is intentionally centralized. Feature code can still express the&lt;br&gt;
business query:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="no"&gt;Q&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;candidates&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;selectName&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;selectEmail&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;filterBySkill&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Java"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;page&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Query candidates"&lt;/span&gt;&lt;span class="o"&gt;).&lt;/span&gt;&lt;span class="na"&gt;purpose&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Load data"&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;executeForList&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The runtime adds the customer and team boundaries before the repository sees&lt;br&gt;
the request.&lt;/p&gt;
&lt;h2&gt;
  
  
  Protecting More Than Rows
&lt;/h2&gt;

&lt;p&gt;The hook is not only about tenant IDs.&lt;/p&gt;

&lt;p&gt;In a real platform, request policy can protect infrastructure as well as data:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;reject &lt;code&gt;rawSql&lt;/code&gt; for normal users;&lt;/li&gt;
&lt;li&gt;cap page size for list views;&lt;/li&gt;
&lt;li&gt;block &lt;code&gt;unlimited()&lt;/code&gt; on high-volume entities;&lt;/li&gt;
&lt;li&gt;add region or data residency predicates;&lt;/li&gt;
&lt;li&gt;require extra audit for sensitive reads;&lt;/li&gt;
&lt;li&gt;remove unsafe relation loading for restricted roles;&lt;/li&gt;
&lt;li&gt;attach request comments or markers for tracing.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;private&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;rejectDangerousRequestShape&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;SearchRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;?&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getRawSql&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;currentUserCanUseRawSql&lt;/span&gt;&lt;span class="o"&gt;())&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;throw&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nf"&gt;AccessDeniedException&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Raw SQL is not allowed for this user"&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;

    &lt;span class="nc"&gt;Slice&lt;/span&gt; &lt;span class="n"&gt;slice&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getSlice&lt;/span&gt;&lt;span class="o"&gt;();&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;slice&lt;/span&gt; &lt;span class="o"&gt;!=&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;slice&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getSize&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;200&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;slice&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;setSize&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;200&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is infrastructure protection. It prevents one feature path from turning&lt;br&gt;
into a full-table scan, an accidental data export, or an expensive cross-tenant&lt;br&gt;
aggregation.&lt;/p&gt;
&lt;h2&gt;
  
  
  Why UserContext Is the Right Place
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;UserContext&lt;/code&gt; already knows the runtime facts needed to enforce policy:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;the current customer or tenant;&lt;/li&gt;
&lt;li&gt;the current operator;&lt;/li&gt;
&lt;li&gt;roles, teams, and permissions;&lt;/li&gt;
&lt;li&gt;request headers and trace ID;&lt;/li&gt;
&lt;li&gt;client IP and proxy chain;&lt;/li&gt;
&lt;li&gt;environment-level beans and services;&lt;/li&gt;
&lt;li&gt;audit and logging services.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Repositories should not need to know every business permission model.&lt;br&gt;
Controllers should not need to repeat low-level safety rules. The generated&lt;br&gt;
request API should remain readable.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;UserContext&lt;/code&gt; is the convergence point.&lt;/p&gt;
&lt;h2&gt;
  
  
  Auditing Sensitive Reads
&lt;/h2&gt;

&lt;p&gt;Because the hook sees the final request, it is also a useful place to audit&lt;br&gt;
sensitive reads:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;private&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;auditSensitiveRead&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;SearchRequest&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;?&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(!&lt;/span&gt;&lt;span class="s"&gt;"Candidate"&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;equals&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getTypeName&lt;/span&gt;&lt;span class="o"&gt;()))&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;

    &lt;span class="n"&gt;auditTrail&lt;/span&gt;&lt;span class="o"&gt;().&lt;/span&gt;&lt;span class="na"&gt;recordRead&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;traceId&lt;/span&gt;&lt;span class="o"&gt;(),&lt;/span&gt;
            &lt;span class="n"&gt;currentCustomerAccountId&lt;/span&gt;&lt;span class="o"&gt;(),&lt;/span&gt;
            &lt;span class="n"&gt;currentUserId&lt;/span&gt;&lt;span class="o"&gt;(),&lt;/span&gt;
            &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;getTypeName&lt;/span&gt;&lt;span class="o"&gt;(),&lt;/span&gt;
            &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;comment&lt;/span&gt;&lt;span class="o"&gt;(),&lt;/span&gt;
            &lt;span class="n"&gt;getClientIp&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This does not replace business-level audit records such as "approved offer" or&lt;br&gt;
"revoked recruiter access." It complements them by making sensitive data access&lt;br&gt;
observable at the runtime boundary.&lt;/p&gt;
&lt;h2&gt;
  
  
  The Design Principle
&lt;/h2&gt;

&lt;p&gt;Generated APIs should make business intent visible.&lt;/p&gt;

&lt;p&gt;Runtime policy should make that intent safe to execute.&lt;/p&gt;

&lt;p&gt;In Multi Talent, a query for candidates should read like a query for candidates.&lt;br&gt;
It should not be filled with repeated customer, team, residency, audit, and&lt;br&gt;
infrastructure rules. Those rules belong at the boundary where a request is&lt;br&gt;
submitted to the runtime.&lt;/p&gt;

&lt;p&gt;That is what &lt;code&gt;enforceRequestPolicy&lt;/code&gt; is for.&lt;/p&gt;

&lt;p&gt;In Rust, the same idea is expressed as a &lt;code&gt;RequestPolicy&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;use&lt;/span&gt; &lt;span class="nn"&gt;teaql_core&lt;/span&gt;&lt;span class="p"&gt;::{&lt;/span&gt;&lt;span class="n"&gt;Expr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;SelectQuery&lt;/span&gt;&lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="k"&gt;use&lt;/span&gt; &lt;span class="nn"&gt;teaql_runtime&lt;/span&gt;&lt;span class="p"&gt;::{&lt;/span&gt;&lt;span class="n"&gt;RequestPolicy&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;RuntimeError&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;UserContext&lt;/span&gt;&lt;span class="p"&gt;};&lt;/span&gt;

&lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;MultiTalentPolicy&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;impl&lt;/span&gt; &lt;span class="n"&gt;RequestPolicy&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;MultiTalentPolicy&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;enforce_select&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
        &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;UserContext&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="n"&gt;query&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;mut&lt;/span&gt; &lt;span class="n"&gt;SelectQuery&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Result&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;RuntimeError&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nd"&gt;matches!&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;query&lt;/span&gt;&lt;span class="py"&gt;.entity&lt;/span&gt;&lt;span class="nf"&gt;.as_str&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="s"&gt;"Candidate"&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="s"&gt;"TalentProfile"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;customer_id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;
                &lt;span class="py"&gt;.get_named_resource&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;u64&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"customer_account_id"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
                &lt;span class="nf"&gt;.copied&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
                &lt;span class="nf"&gt;.ok_or_else&lt;/span&gt;&lt;span class="p"&gt;(||&lt;/span&gt; &lt;span class="nn"&gt;RuntimeError&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;Policy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"missing customer account"&lt;/span&gt;&lt;span class="nf"&gt;.to_owned&lt;/span&gt;&lt;span class="p"&gt;()))&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

            &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;tenant_filter&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Expr&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;eq&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"customer_account_id"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;customer_id&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
            &lt;span class="n"&gt;query&lt;/span&gt;&lt;span class="py"&gt;.filter&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;Some&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;match&lt;/span&gt; &lt;span class="n"&gt;query&lt;/span&gt;&lt;span class="py"&gt;.filter&lt;/span&gt;&lt;span class="nf"&gt;.take&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
                &lt;span class="nf"&gt;Some&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;existing&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;existing&lt;/span&gt;&lt;span class="nf"&gt;.and_expr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;tenant_filter&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
                &lt;span class="nb"&gt;None&lt;/span&gt; &lt;span class="k"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;tenant_filter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="p"&gt;});&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;query&lt;/span&gt;&lt;span class="py"&gt;.raw_sql&lt;/span&gt;&lt;span class="nf"&gt;.is_some&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="nf"&gt;Err&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nn"&gt;RuntimeError&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;Policy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
                &lt;span class="s"&gt;"raw SQL is not allowed for normal users"&lt;/span&gt;&lt;span class="nf"&gt;.to_owned&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;
            &lt;span class="p"&gt;));&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;

        &lt;span class="nf"&gt;Ok&lt;/span&gt;&lt;span class="p"&gt;(())&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Register it during runtime assembly:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;teaql_runtime&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nn"&gt;UserContext&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;new&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.with_module&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nn"&gt;multi_talent&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;module_with_behaviors_and_checkers&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
    &lt;span class="nf"&gt;.with_request_policy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;MultiTalentPolicy&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Java uses &lt;code&gt;UserContext.enforceRequestPolicy&lt;/code&gt;. Rust uses &lt;code&gt;RequestPolicy&lt;/code&gt;. The&lt;br&gt;
design principle is the same: TeaQL projects get a final, explicit place to&lt;br&gt;
protect the platform and the customer's data before a request reaches the&lt;br&gt;
repository.&lt;/p&gt;

</description>
      <category>teaql</category>
      <category>security</category>
      <category>multitenant</category>
      <category>usercontext</category>
    </item>
    <item>
      <title>TeaQL Showcase: See What Your Business Code Actually Does</title>
      <dc:creator>Philip Z</dc:creator>
      <pubDate>Wed, 29 Jul 2026 12:00:00 +0000</pubDate>
      <link>https://dev.to/philipgreat/teaql-showcase-see-what-your-business-code-actually-does-1lnm</link>
      <guid>https://dev.to/philipgreat/teaql-showcase-see-what-your-business-code-actually-does-1lnm</guid>
      <description>&lt;p&gt;Instead of hiding database behavior behind an opaque ORM, this demo shows the full execution path of a domain action:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;Command&lt;/code&gt; → &lt;code&gt;Domain transition&lt;/code&gt; → &lt;code&gt;SQL&lt;/code&gt; → &lt;code&gt;Audit diff&lt;/code&gt; → &lt;code&gt;Event log&lt;/code&gt; → &lt;code&gt;UI projection&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F61z4wqwhbz9qnjib67yx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F61z4wqwhbz9qnjib67yx.png" alt="TeaQL task board demo" width="799" height="437"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The task board intentionally uses a tiny domain model so the runtime behavior is easy to follow. TeaQL itself is designed for significantly larger business domains, where understanding domain transitions, generated SQL, audit trails and query execution paths becomes even more important.&lt;/p&gt;

&lt;p&gt;To make the idea concrete, we built a terminal-based Kanban board using Ratatui + SQLite. When you move a task from &lt;em&gt;Planned&lt;/em&gt; to &lt;em&gt;Ready&lt;/em&gt;, TeaQL shows the generated SQL, optimistic concurrency update, audit trail, lifecycle event, and refreshed status facets — all in real time.&lt;/p&gt;

&lt;p&gt;The app also cross-compiles as a standalone statically linked binary for &lt;code&gt;armv7&lt;/code&gt; router environments, with no external runtime dependencies.&lt;/p&gt;

&lt;p&gt;✨ &lt;strong&gt;Powered by native &lt;code&gt;rusqlite&lt;/code&gt;&lt;/strong&gt;: The TeaQL code generator natively supports &lt;code&gt;rusqlite&lt;/code&gt;, producing 100% Rust-native SQLite execution code that compiles directly into your binary with zero external driver overhead.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Try it instantly in two ways:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Hosted SaaS demo:&lt;/strong&gt; open the multi-tenant Robot Task Board at &lt;a href="https://lab-robot-task-board-rust.teaql.io/" rel="noopener noreferrer"&gt;lab-robot-task-board-rust.teaql.io&lt;/a&gt;. The hosted version is designed as a SaaS-style multi-tenant deployment, so different tenants can try the same TeaQL-powered task board without sharing one local database instance.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Local Docker demo:&lt;/strong&gt; run the server locally when you want to inspect the runtime behavior on your own machine.
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;docker run &lt;span class="nt"&gt;--rm&lt;/span&gt; &lt;span class="nt"&gt;-it&lt;/span&gt; teaql/robot-task-board:minimal
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The demo app source is available at &lt;a href="https://github.com/teaql/robot-task-board" rel="noopener noreferrer"&gt;teaql/robot-task-board&lt;/a&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  TeaQL for Rust
&lt;/h2&gt;

&lt;p&gt;TeaQL is coming to Rust.&lt;/p&gt;

&lt;p&gt;We have now open-sourced the Rust-based TeaQL generator and runtime foundation. You can find the source code at &lt;a href="https://github.com/teaql/teaql-forge-rs" rel="noopener noreferrer"&gt;teaql/teaql-forge-rs&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;For a faster hands-on experience, run the server directly with Docker:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;docker run &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="nt"&gt;--name&lt;/span&gt; teaql-forge-server &lt;span class="nt"&gt;-p&lt;/span&gt; 8080:8080 teaql/teaql-forge-rs:latest
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The project is still in its early stage. Our goal is to explore how TeaQL's domain query model can work naturally in Rust, and how it can help developers build domain-driven business applications with clearer models, safer queries, and better local tooling.&lt;/p&gt;

&lt;p&gt;The early open-source line will focus on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a lightweight TeaQL generator for Rust&lt;/li&gt;
&lt;li&gt;basic domain model definitions&lt;/li&gt;
&lt;li&gt;query model and request structures&lt;/li&gt;
&lt;li&gt;runtime foundation for local execution&lt;/li&gt;
&lt;li&gt;simple examples and demo applications&lt;/li&gt;
&lt;li&gt;a developer-friendly project structure for the Rust ecosystem&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This project is not intended to be a large framework from day one. We want to start small, make the basic ideas clear, and let developers understand how TeaQL can fit into Rust projects naturally. The early version will focus on clarity, simplicity, and practical usage.&lt;/p&gt;

&lt;p&gt;Rust is a good fit for TeaQL's next step because it provides strong type safety, high performance, local-first deployment, single-binary distribution, good support for CLI and developer tools, and a growing ecosystem for business and infrastructure software.&lt;/p&gt;

&lt;p&gt;TeaQL for Rust is an open-source Rust-based direction for TeaQL, starting with a lightweight generator and runtime foundation for building domain-driven business applications.&lt;/p&gt;

&lt;p&gt;For this task board demo, the TeaQL runtime crates, generated Rust code, and Rust-focused generator foundation are open source. The source code is available at &lt;a href="https://github.com/teaql/teaql-forge-rs" rel="noopener noreferrer"&gt;teaql/teaql-forge-rs&lt;/a&gt;, and the Docker image above gives you the quickest way to try the server.&lt;/p&gt;




&lt;h2&gt;
  
  
  📁 Project Structure
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;robot-task-board/
├── src/
│   ├── app.rs           # Core Application State
│   ├── commands.rs      # User command parsing (`/add`, `/mv`, etc)
│   ├── logging.rs       # TeaQL Audit Sink &amp;amp; Logging extensions
│   ├── main.rs          # Event loop &amp;amp; application entry point
│   ├── models.rs        # Lightweight models &amp;amp; DTOs for the UI
│   ├── service.rs       # Domain behavior, Aggregate Roots &amp;amp; TeaQL queries
│   ├── startup.rs       # Animated startup / bootstrap rendering
│   ├── tui.rs           # Terminal initialization and restoration
│   ├── ui.rs            # Ratatui layout, syntax-highlighted log rendering
│   └── utils.rs         # System info (CPU/memory) from /proc
├── models/
│   └── model.xml        # Generated by AI via teaql-agent-kit (https://github.com/teaql/teaql-agent-kit), validated &amp;amp; auto-healed via the `teaql eval` command
├── generate-lib/
│   └── lib/             # Auto-generated TeaQL domain library (Generated via `teaql gen-lib models/model.xml`)
├── Cargo.toml
└── README.md
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  🔬 Why TeaQL? (10 Applied Scenarios)
&lt;/h2&gt;

&lt;p&gt;This application exercises &lt;strong&gt;10 distinct TeaQL capabilities&lt;/strong&gt; across its CRUD and query workflows. Each scenario below maps a TeaQL API to its concrete usage in this app and the exact SQL it produces.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 1: Schema Bootstrap (&lt;code&gt;ensure_rusqlite_schema_for&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Automatically creates or migrates all database tables and seeds initial reference data (status values, platform) from the domain model — zero manual SQL.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// service.rs — One-line schema setup&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="k"&gt;mut&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;robot_kanban&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;module_with_behaviors_and_checkers&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.into_context&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="nf"&gt;.use_rusqlite_provider&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;inner_executor&lt;/span&gt;&lt;span class="nf"&gt;.clone&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;span class="nf"&gt;ensure_rusqlite_schema_for&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; &lt;code&gt;TaskService::new()&lt;/code&gt; — on first run, creates &lt;code&gt;task_data&lt;/code&gt;, &lt;code&gt;task_status_data&lt;/code&gt;, and &lt;code&gt;platform_data&lt;/code&gt; tables with seed data; on subsequent runs, applies any schema changes from the model.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Bonus (Sample Data):&lt;/strong&gt; Beyond schema creation, the framework also auto-generates a &lt;code&gt;sample_data&lt;/code&gt; module from your model. This allows developers to inject structured, type-safe mock entities with a single function call for rapid prototyping and unit testing, without writing a single raw &lt;code&gt;INSERT&lt;/code&gt; statement:&lt;/p&gt;


&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Scaffold a batch of dummy tasks and execution logs in one line&lt;/span&gt;
&lt;span class="nn"&gt;robot_kanban&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;generate_sample_data&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;SampleDataPlan&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;small&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/blockquote&gt;




&lt;h3&gt;
  
  
  Scenario 2: JSON-Based Dynamic Filtering (&lt;code&gt;filter_with_json&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Accepts a JSON object to dynamically construct WHERE clauses at runtime. An empty &lt;code&gt;{}&lt;/code&gt; acts as a wildcard (no filter), enabling a single code path for both search and full-load.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// service.rs — Unified search/load query&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;search_json&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="nf"&gt;Some&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;ref&lt;/span&gt; &lt;span class="n"&gt;term&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;search_term&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;escaped_name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;serde_json&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nn"&gt;Value&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;String&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;term&lt;/span&gt;&lt;span class="nf"&gt;.clone&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
    &lt;span class="nd"&gt;format!&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;r#"{{"name": {}}}"#&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;escaped_name&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;   &lt;span class="c1"&gt;// → {"name": "calibrate"}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="s"&gt;r#"{}"#&lt;/span&gt;&lt;span class="nf"&gt;.to_owned&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;                            &lt;span class="c1"&gt;// → {} (wildcard)&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;

&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;select&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.filter_with_json&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;search_json&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Input&lt;/th&gt;
&lt;th&gt;JSON&lt;/th&gt;
&lt;th&gt;Generated SQL&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;No search&lt;/td&gt;
&lt;td&gt;&lt;code&gt;{}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;SELECT ... FROM task_data WHERE (version &amp;gt; 0)&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;calibrate&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;{"name": "calibrate"}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;SELECT ... FROM task_data WHERE (version &amp;gt; 0) AND (name LIKE '%calibrate%')&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; &lt;code&gt;/search&lt;/code&gt; or &lt;code&gt;/s&lt;/code&gt; command — filters the Kanban board in real-time.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 3: Faceted Aggregation (&lt;code&gt;facet_by_status_as&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Attaches a sub-query that computes aggregate counts grouped by a relation (status), all within a single database round-trip alongside the main entity query.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// service.rs — Single query fetches tasks + status counts&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;select&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;search_comment&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.filter_with_json&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;search_json&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.facet_by_status_as&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"status_stats"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="c1"&gt;// This sub-query could easily be extracted into a semantic helper method&lt;/span&gt;
        &lt;span class="c1"&gt;// e.g. `TaskStatusRequest::build_count_stats()` for reuse across the app&lt;/span&gt;
        &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;task_status&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Count status"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.count_tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;all_tasks&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;select&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Query tasks"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.purpose&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Load data"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.execute_for_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="py"&gt;.ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;// Access facet results from the same SmartList&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="nf"&gt;Some&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;facet_list&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;all_tasks&lt;/span&gt;&lt;span class="nf"&gt;.facet&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"status_stats"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;record&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="n"&gt;facet_list&lt;/span&gt;&lt;span class="nf"&gt;.iter&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;status_id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;record&lt;/span&gt;&lt;span class="nf"&gt;.get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"id"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;record&lt;/span&gt;&lt;span class="nf"&gt;.get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"count_tasks"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;💡 Pro Tip (Semantic Encapsulation):&lt;/strong&gt; Notice how &lt;code&gt;Q::task_status().count_tasks()&lt;/code&gt; is passed directly. Because TeaQL queries are strongly-typed data structures, you can effortlessly extract these aggregations into reusable, semantic helper methods.&lt;/p&gt;


&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// 1. Encapsulate the query logic into a reusable semantic method&lt;/span&gt;
&lt;span class="k"&gt;impl&lt;/span&gt; &lt;span class="n"&gt;TaskStatusRequest&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;build_count_stats&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;Self&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;task_status&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Count status"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.count_tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;// 2. Compose it cleanly in your main business logic&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;select&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.filter_with_json&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;search_json&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.facet_by_status_as&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"status_stats"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nn"&gt;TaskStatusRequest&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;build_count_stats&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;


&lt;p&gt;This allows you to compose massive, multi-layered TeaQL queries dynamically without polluting your business logic. &lt;em&gt;(Note: The &lt;code&gt;E::&lt;/code&gt; Expression API provides the exact same composability for field-level conditions and evaluations!)&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;strong&gt;Generated SQL (3 queries in one round-trip):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="c1"&gt;-- 1. Main entity query&lt;/span&gt;
&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;version&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;status_id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;platform&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;platform_id&lt;/span&gt;
  &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;task_data&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="c1"&gt;-- 2. Facet: load status reference data&lt;/span&gt;
&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;code&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;color&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;display_order&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;progress&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;task_status_data&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="c1"&gt;-- 3. Facet: aggregate task counts per status&lt;/span&gt;
&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;COUNT&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;count_tasks&lt;/span&gt;
  &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;task_data&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;status&lt;/span&gt; &lt;span class="k"&gt;IN&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1001&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1002&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1003&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1004&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="k"&gt;GROUP&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; Board reload — the Planned/Process/Done count badges and task lists are all populated from this single query.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 4: Entity Factory (&lt;code&gt;Q::tasks().comment("Create tasks").new_entity()&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Creates a new entity instance pre-wired with the runtime context, ready for field population and persistence.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// task/logic.rs — Encapsulated factory method with DDD validation&lt;/span&gt;
&lt;span class="k"&gt;impl&lt;/span&gt; &lt;span class="n"&gt;Task&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;create&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cmd&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;CreateTaskCommand&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;next_id&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;u64&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;UserContext&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Result&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="k"&gt;Self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;AppError&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="k"&gt;mut&lt;/span&gt; &lt;span class="n"&gt;task&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Create tasks"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.new_entity&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.update_id&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;next_id&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="nf"&gt;.update_name&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cmd&lt;/span&gt;&lt;span class="py"&gt;.name&lt;/span&gt;&lt;span class="nf"&gt;.clone&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
            &lt;span class="nf"&gt;.update_version&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1_i64&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
            &lt;span class="nf"&gt;.update_status_to_planned&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;  &lt;span class="c1"&gt;// Safe API: raw update_status_id(1) is blocked by the compiler&lt;/span&gt;
            &lt;span class="nf"&gt;.update_platform_id&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1_u64&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="nf"&gt;Ok&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Generated SQL:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;INSERT&lt;/span&gt; &lt;span class="k"&gt;INTO&lt;/span&gt; &lt;span class="n"&gt;task_data&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;version&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;platform&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="k"&gt;VALUES&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;'calibrate sensor'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; bare input &lt;code&gt;&amp;lt;name&amp;gt;&lt;/code&gt; or &lt;code&gt;/add&lt;/code&gt; command — creates a new task in Planned status.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 5: ID Space Generation (&lt;code&gt;RusqliteIdSpaceGenerator&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Generates globally unique, monotonically increasing IDs per entity type using a dedicated SQLite sequence table — no auto-increment column needed.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// service.rs — add_task()&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;next_id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="py"&gt;.ctx.next_id_for&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;Task&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; bare input &lt;code&gt;&amp;lt;name&amp;gt;&lt;/code&gt; or &lt;code&gt;/add&lt;/code&gt; command — each new task receives a unique ID from the &lt;code&gt;Task&lt;/code&gt; ID space.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;💡 Pro Tip: The Universal &lt;code&gt;UserContext&lt;/code&gt;&lt;/strong&gt;&lt;br&gt;
Notice how we retrieve the ID generator from &lt;code&gt;self.ctx&lt;/code&gt;? The &lt;code&gt;UserContext&lt;/code&gt; object is pervasive throughout your application's domain layer and request lifecycle. Because it is visible everywhere, it acts as the perfect dependency injection container.&lt;/p&gt;

&lt;p&gt;You can integrate any external resources directly into &lt;code&gt;UserContext&lt;/code&gt;, such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Redis caching layers&lt;/li&gt;
&lt;li&gt;  External API clients&lt;/li&gt;
&lt;li&gt;  Email / SMS service clients&lt;/li&gt;
&lt;li&gt;  Internationalization (i18n) resources&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Simply use &lt;code&gt;ctx.insert_resource(...)&lt;/code&gt; at initialization, and use extension traits to expose type-safe, domain-specific methods anywhere in your business logic.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h3&gt;
  
  
  Scenario 6: Domain Behavior &amp;amp; Cascading Save (DDD Aggregate Root)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Allows attaching rich domain logic directly to generated entities using Rust's Native Extension Traits, and securely saving the entire Aggregate Root graph in a single atomic transaction.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// service.rs — Executing a DDD behavior&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="k"&gt;mut&lt;/span&gt; &lt;span class="n"&gt;task&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Query tasks"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.purpose&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Load data"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.with_id_is&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Query task_status"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.purpose&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Load data"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.execute_for_one&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="py"&gt;.ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;// 1. Invoke pure domain method (updates internal state)&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;next_status&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.transition_status&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;cmd&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;// 2. Generate a child log entity via domain behavior&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="k"&gt;log&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.generate_execution_log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"STATUS_CHANGED"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;detail&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="py"&gt;.ctx&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="c1"&gt;// 3. Attach the child to the Aggregate Root's collection&lt;/span&gt;
&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.task_execution_log_list_mut&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.push&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;log&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.set_comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Move task status"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="c1"&gt;// 4. Graph persistence: Recursively saves the Task AND inserts the new child Log!&lt;/span&gt;
&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.save&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="py"&gt;.ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; &lt;code&gt;/mv&lt;/code&gt; command — enabling clean, expressive state mutations directly on &lt;code&gt;Task&lt;/code&gt; objects.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 7: Partial Projections &amp;amp; Aggregations (&lt;code&gt;return_type::&amp;lt;T&amp;gt;()&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Tells TeaQL to deserialize query results into a custom data transfer object (DTO) instead of the default generated entity. This is vital when executing partial selects or complex groupings where the returned shape no longer matches the full entity.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Define a custom DTO for aggregations or partial fields&lt;/span&gt;
&lt;span class="nd"&gt;#[derive(TeaqlEntity)]&lt;/span&gt;
&lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;StatusStats&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="n"&gt;status&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;i32&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="n"&gt;task_count&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;i64&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;// Fetch custom projection instead of raw Task&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;stats&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.select_status&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.count_id_as&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"task_count"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.group_by_status&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="py"&gt;.return_type&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;StatusStats&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Query tasks"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.purpose&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Load data"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.execute_for_list&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; High-performance dashboard rendering — avoids full-entity deserialization overhead when projecting lightweight summaries or grouped counts.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 8: Audited Soft-Delete (mark_as_delete)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Deletes an entity using the rich domain object rather than raw IDs. By chaining &lt;code&gt;mark_as_delete()&lt;/code&gt; and &lt;code&gt;set_comment()&lt;/code&gt; directly on the entity, TeaQL enforces optimistic concurrency (via the entity's current &lt;code&gt;version&lt;/code&gt;) and gracefully propagates the deletion context to the &lt;code&gt;EntityEventSink&lt;/code&gt; for audit logging.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// service.rs — delete_task()&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;task_name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.to_string&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.mark_as_delete&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.set_comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nd"&gt;format!&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Delete task '{}'"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;task_name&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
&lt;span class="n"&gt;task&lt;/span&gt;&lt;span class="nf"&gt;.save&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="py"&gt;.ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="k"&gt;.await&lt;/span&gt;&lt;span class="o"&gt;?&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Generated SQL:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;UPDATE&lt;/span&gt; &lt;span class="n"&gt;task_data&lt;/span&gt; &lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt; &lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="k"&gt;version&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;TeaQL uses a soft-delete pattern — &lt;code&gt;version&lt;/code&gt; is set to a negative value rather than removing the row, preserving audit history.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; &lt;code&gt;/del&lt;/code&gt; command.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 9: Comment Chain Propagation (&lt;code&gt;.comment()&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; Attaches human-readable intent annotations to queries. When queries have nested sub-queries (e.g., facets), comments propagate down the chain with &lt;code&gt;-&amp;gt;&lt;/code&gt; separators, creating a full trace of query intent.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// service.rs — Comments propagate through facet sub-queries&lt;/span&gt;
&lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;select&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Get active tasks"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;                       &lt;span class="c1"&gt;// Parent comment&lt;/span&gt;
    &lt;span class="nf"&gt;.filter_with_json&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;search_json&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;.facet_by_status_as&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"status_stats"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="nn"&gt;Q&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;task_status&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.comment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Count status"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;       &lt;span class="c1"&gt;// Child comment&lt;/span&gt;
            &lt;span class="nf"&gt;.count_tasks&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Resulting log trace chain:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[Get active tasks]                                → main task query
[Get active tasks-&amp;gt;status_stats-&amp;gt;Count status]    → facet status lookup
[Get active tasks-&amp;gt;status_stats-&amp;gt;Count status]    → facet aggregate count
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The TUI renders these traces in real-time with syntax-highlighted colors — timestamp, user context (&lt;code&gt;[philip]&lt;/code&gt;), comment chains, result summaries, and elapsed times are each distinctly colored:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[12:06:00.225]-[philip]-[0.184ms]-[DEBUG]-SqlLogEntry - [Get active tasks] - [5*Task] SELECT ... 
[12:06:00.226]-[philip]-[0.138ms]-[DEBUG]-SqlLogEntry - [Get active tasks-&amp;gt;status_stats-&amp;gt;Count status] - [3*TaskStatus] SELECT ... 
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Applied in:&lt;/strong&gt; Every query in the application — enables real-time SQL auditing from the TUI log panel.&lt;/p&gt;




&lt;h3&gt;
  
  
  Scenario 10: Entity Audit Subsystem (&lt;code&gt;EntityEventSink&lt;/code&gt;)
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it does:&lt;/strong&gt; TeaQL automatically hooks into the persistence lifecycle to track fine-grained Entity Events (Create, Update, Delete, Recover) and computes precise field-level diffs (&lt;code&gt;old_value&lt;/code&gt; ➔ &lt;code&gt;new_value&lt;/code&gt;).&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;&lt;span class="c1"&gt;// logging.rs — Implement the sink to intercept framework audit events&lt;/span&gt;
&lt;span class="k"&gt;pub&lt;/span&gt; &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;AppAuditSink&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;impl&lt;/span&gt; &lt;span class="n"&gt;EntityEventSink&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;AppAuditSink&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;fn&lt;/span&gt; &lt;span class="nf"&gt;on_event&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="k"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;UserContext&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;event&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;EntityEvent&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Result&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="n"&gt;RuntimeError&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;short_user&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="c1"&gt;// ... format changes and output to TUI Log Area and app.log&lt;/span&gt;
        &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;change&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;event&lt;/span&gt;&lt;span class="py"&gt;.changes&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
            &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;detail_line&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nd"&gt;format!&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
                &lt;span class="s"&gt;"[{}]-[{}]-[AUDIT]-  -&amp;gt; Field [{}]: {} ➔ {}"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                &lt;span class="n"&gt;timestamp&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;change&lt;/span&gt;&lt;span class="py"&gt;.field&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;change&lt;/span&gt;&lt;span class="py"&gt;.old_value&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;change&lt;/span&gt;&lt;span class="py"&gt;.new_value&lt;/span&gt;
            &lt;span class="p"&gt;);&lt;/span&gt;
        &lt;span class="p"&gt;}&lt;/span&gt;
        &lt;span class="nf"&gt;Ok&lt;/span&gt;&lt;span class="p"&gt;(())&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c1"&gt;// Attach it during runtime initialization&lt;/span&gt;
&lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="nf"&gt;.set_event_sink&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;AppAuditSink&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Resulting log output:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[12:04:23.529]-[philip]-[AUDIT]-Entity [Task(1)] was UPDATED. [Move task 'My New Task' status from PLANNED to READY]
[12:04:23.529]-[philip]-[AUDIT]-  -&amp;gt; Field [status]: PLANNED ➔ READY
[12:04:23.529]-[philip]-[AUDIT]-  -&amp;gt; Field [version]: 1 ➔ 2
[12:04:23.530]-[philip]-[AUDIT]-Entity [TaskExecutionLog(2)] was CREATED. [Move task 'My New Task' status from PLANNED to READY]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvonhpgl0lzf9iegih8ff.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvonhpgl0lzf9iegih8ff.png" alt="TeaQL audit trail demo" width="800" height="183"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Next Steps / Coming Soon:&lt;/strong&gt; &lt;br&gt;
In the next phase, we will introduce the &lt;strong&gt;&lt;code&gt;audit ignore&lt;/code&gt;&lt;/strong&gt; feature. By adding an attribute in the &lt;code&gt;model.xml&lt;/code&gt;, developers will be able to explicitly exclude sensitive data (like passwords, PII, or internal tokens) from being captured or diffed by the audit subsystem.&lt;/p&gt;


&lt;h3&gt;
  
  
  Scenario Summary
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;#&lt;/th&gt;
&lt;th&gt;TeaQL API&lt;/th&gt;
&lt;th&gt;App Feature&lt;/th&gt;
&lt;th&gt;Command&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;&lt;code&gt;ensure_rusqlite_schema_for&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Auto-create tables &amp;amp; seed data&lt;/td&gt;
&lt;td&gt;Startup&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;code&gt;filter_with_json&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Dynamic search / wildcard load&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/s&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;&lt;code&gt;facet_by_status_as&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Status count aggregation&lt;/td&gt;
&lt;td&gt;Board reload&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Q::tasks().comment("Create tasks").new_entity()&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Create task with defaults&lt;/td&gt;
&lt;td&gt;&lt;code&gt;&amp;lt;name&amp;gt;&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;&lt;code&gt;RusqliteIdSpaceGenerator&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Unique ID generation&lt;/td&gt;
&lt;td&gt;&lt;code&gt;&amp;lt;name&amp;gt;&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Extension Traits&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Domain Behavior Injection (DDD)&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;/mv&lt;/code&gt;, &lt;code&gt;/del&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;&lt;code&gt;.return_type::&amp;lt;T&amp;gt;()&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Custom partial projection &amp;amp; stats DTOs&lt;/td&gt;
&lt;td&gt;Optimization&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;&lt;code&gt;EntityStatus::UpdatedDeleted&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Audited soft-delete with concurrency&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/del&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;&lt;code&gt;.comment()&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Query intent tracing&lt;/td&gt;
&lt;td&gt;All queries&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;&lt;code&gt;EntityEventSink&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Field-level lifecycle diffs &amp;amp; Audit&lt;/td&gt;
&lt;td&gt;All mutations&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;


&lt;h2&gt;
  
  
  📐 Architecture
&lt;/h2&gt;
&lt;h3&gt;
  
  
  3-Layer Separation
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Layer&lt;/th&gt;
&lt;th&gt;File&lt;/th&gt;
&lt;th&gt;Responsibility&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;UI / Presentation&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;ui.rs&lt;/code&gt;, &lt;code&gt;startup.rs&lt;/code&gt;, &lt;code&gt;tui.rs&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Ratatui layout, startup animation, log syntax highlighting, terminal management&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Application Layer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;main.rs&lt;/code&gt;, &lt;code&gt;app.rs&lt;/code&gt;, &lt;code&gt;commands.rs&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;App state, command parsing, event loop orchestration&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Service &amp;amp; Domain&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;service.rs&lt;/code&gt;, &lt;code&gt;logging.rs&lt;/code&gt;, &lt;code&gt;models.rs&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;TeaQL queries, DDD aggregate roots, audit sinks, view models&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;code&gt;main.rs&lt;/code&gt; has no direct dependency on TeaQL types — it only interacts with &lt;code&gt;TaskService&lt;/code&gt;, &lt;code&gt;TaskModel&lt;/code&gt;, and &lt;code&gt;MoveResult&lt;/code&gt;.&lt;/p&gt;
&lt;h3&gt;
  
  
  DDD Aggregate Root
&lt;/h3&gt;

&lt;p&gt;Generated &lt;code&gt;Task&lt;/code&gt; entities act as Data Transfer Objects but are extended with native &lt;code&gt;impl Task&lt;/code&gt; methods to encapsulate business logic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;Task::create()&lt;/code&gt;&lt;/strong&gt; — factory method with validation&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;Task::transition_status()&lt;/code&gt;&lt;/strong&gt; — automatic next-status resolution&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;Task::generate_execution_log()&lt;/code&gt;&lt;/strong&gt; — encapsulation of internal event generation&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;
  
  
  Domain Model
&lt;/h3&gt;

&lt;p&gt;Defined in &lt;code&gt;models/model.xml&lt;/code&gt;, the TeaQL domain model declares two entities with a status relation:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight xml"&gt;&lt;code&gt;&lt;span class="nt"&gt;&amp;lt;task_status&lt;/span&gt;
    &lt;span class="na"&gt;name=&lt;/span&gt;&lt;span class="s"&gt;"Planned|Ready|Executing|Verified"&lt;/span&gt;
    &lt;span class="na"&gt;code=&lt;/span&gt;&lt;span class="s"&gt;"PLANNED|READY|EXECUTING|VERIFIED"&lt;/span&gt;
    &lt;span class="na"&gt;_features=&lt;/span&gt;&lt;span class="s"&gt;"status"&lt;/span&gt;
    &lt;span class="na"&gt;_identified_by=&lt;/span&gt;&lt;span class="s"&gt;"code"&lt;/span&gt; &lt;span class="nt"&gt;/&amp;gt;&lt;/span&gt;

&lt;span class="nt"&gt;&amp;lt;task&lt;/span&gt;
    &lt;span class="na"&gt;name=&lt;/span&gt;&lt;span class="s"&gt;"Task Name|[1,200]"&lt;/span&gt;
    &lt;span class="na"&gt;status=&lt;/span&gt;&lt;span class="s"&gt;"task_status()"&lt;/span&gt;
    &lt;span class="na"&gt;_features=&lt;/span&gt;&lt;span class="s"&gt;"custom"&lt;/span&gt; &lt;span class="nt"&gt;/&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  🤖 Taming AI via Service-Generated APIs
&lt;/h3&gt;

&lt;p&gt;A hidden paradigm shift in this architecture is how naturally it tames AI coding assistants. The workflow forms a highly predictable closed loop:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;AI Generation:&lt;/strong&gt; An AI easily drafts the declarative domain model (&lt;code&gt;model.xml&lt;/code&gt;) from raw business requirements. To automate this process entirely, we built the &lt;a href="https://github.com/teaql/teaql-agent-kit" rel="noopener noreferrer"&gt;teaql-agent-kit&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Translation Service:&lt;/strong&gt; A dedicated background service takes this model and translates it into a dense, strictly-typed Rust API layer.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;High-Obedience Implementation:&lt;/strong&gt; When the AI helps you write application logic, it relies entirely on these generated, compiler-enforced APIs.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This generated layer acts as an absolute guardrail against common AI hallucinations:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Safe Setters (No Magic Numbers):&lt;/strong&gt; Instead of &lt;code&gt;task.update_status_id(1)&lt;/code&gt; (which is natively blocked by the compiler), the AI is forced to use the semantic &lt;code&gt;task.update_status_to_planned()&lt;/code&gt;. It cannot hallucinate invalid foreign keys.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Safe Getters (The &lt;code&gt;E::&lt;/code&gt; Expression API):&lt;/strong&gt; Deeply nested or nullable data retrieval in Rust often causes AI to write buggy &lt;code&gt;.unwrap()&lt;/code&gt; chains. TeaQL provides a monadic expression API:
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight rust"&gt;&lt;code&gt;  &lt;span class="k"&gt;use&lt;/span&gt; &lt;span class="nn"&gt;robot_kanban&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;E&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

  &lt;span class="c1"&gt;// Safe optional-chaining: swallows nulls gracefully and eliminates type mismatch&lt;/span&gt;
  &lt;span class="k"&gt;let&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nn"&gt;E&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;task_status&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;status&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="nf"&gt;.get_name&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.eval&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="nf"&gt;.unwrap_or&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;raw_str&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The AI gets perfect auto-completion for legitimate fields (&lt;code&gt;.get_name()&lt;/code&gt;) and produces zero runtime panics.&lt;/p&gt;




&lt;h2&gt;
  
  
  🛠 Commands
&lt;/h2&gt;

&lt;p&gt;Commands use a slash (&lt;code&gt;/&lt;/code&gt;) prefix. &lt;strong&gt;Any bare text (without a slash) is treated as a quick-add for a new task.&lt;/strong&gt;&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Command&lt;/th&gt;
&lt;th&gt;Shortcut&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;th&gt;Example&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;&amp;lt;name&amp;gt;&lt;/code&gt; / &lt;code&gt;/add &amp;lt;name&amp;gt;&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;Create a new task in Planned status&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;calibrate sensor&lt;/code&gt; or &lt;code&gt;/add calibrate&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;/move &amp;lt;id&amp;gt; [status]&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/mv&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Transition task status (planned/ready/executing/verified; default: next)&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;/move 3&lt;/code&gt; or &lt;code&gt;/mv 3 ready&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;/search &amp;lt;keyword&amp;gt;&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/s&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Filter tasks by keyword (empty to clear)&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;/search calibrate&lt;/code&gt; or &lt;code&gt;/s&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;/delete &amp;lt;id&amp;gt;&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/del&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Permanently delete a task&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/delete 3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;/exit&lt;/code&gt; / &lt;code&gt;/quit&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/q&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Quit the application&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/exit&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;&lt;code&gt;ESC&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Immediate exit&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Up/Dn&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Scroll Action Logs viewport&lt;/td&gt;
&lt;td&gt;—&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  ⚙️ Prerequisites
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Rust toolchain&lt;/strong&gt; (1.70+)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;TeaQL Runtime Packages&lt;/strong&gt; — the following crates are expected to be available (e.g., via relative path or git submodule):

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;teaql-core&lt;/code&gt;, &lt;code&gt;teaql-runtime&lt;/code&gt;, &lt;code&gt;teaql-macros&lt;/code&gt;, &lt;code&gt;teaql-sql&lt;/code&gt;, &lt;code&gt;teaql-provider-rusqlite&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;A Note on Open Source:&lt;/strong&gt; The TeaQL Rust generator and runtime foundation are now open source at &lt;a href="https://github.com/teaql/teaql-forge-rs" rel="noopener noreferrer"&gt;teaql/teaql-forge-rs&lt;/a&gt;. For a faster experience, you can also run &lt;code&gt;docker run -d --name teaql-forge-server -p 8080:8080 teaql/teaql-forge-rs:latest&lt;/code&gt; and try the server directly.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For cross-compilation&lt;/strong&gt;: &lt;code&gt;cargo-zigbuild&lt;/code&gt; and the &lt;code&gt;armv7-unknown-linux-musleabihf&lt;/code&gt; target&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; TeaQL runtime crates are published on &lt;a href="https://crates.io/crates/teaql-core" rel="noopener noreferrer"&gt;crates.io&lt;/a&gt;. No local checkout is needed — &lt;code&gt;cargo build&lt;/code&gt; will fetch them automatically.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  🚀 Build &amp;amp; Run
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Local Development
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Check compilation&lt;/span&gt;
cargo check

&lt;span class="c"&gt;# Run the TUI&lt;/span&gt;
cargo run

&lt;span class="c"&gt;# Run the TUI in compact mode (hides the SQL log area)&lt;/span&gt;
cargo run &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;-c&lt;/span&gt;

&lt;span class="c"&gt;# Build optimized release binary&lt;/span&gt;
cargo build &lt;span class="nt"&gt;--release&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  ARMv7 Cross-Compilation
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Static cross-compile for armv7 routers&lt;/span&gt;
cargo zigbuild &lt;span class="nt"&gt;--release&lt;/span&gt; &lt;span class="nt"&gt;--target&lt;/span&gt; armv7-unknown-linux-musleabihf
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The output binary is at &lt;code&gt;target/armv7-unknown-linux-musleabihf/release/robot-task-board&lt;/code&gt; — upload directly to a router and run with zero dependencies.&lt;/p&gt;

&lt;h3&gt;
  
  
  Running Tests
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cargo &lt;span class="nb"&gt;test&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Tests cover:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Comment propagation&lt;/strong&gt; — verifies TeaQL comment chains propagate through facet sub-queries&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CRUD lifecycle&lt;/strong&gt; — add → reload → verify → delete → verify&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DDD transitions&lt;/strong&gt; — Planned → Ready → Executing → Verified with automatic and explicit status moves&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  💬 What We'd Love Feedback On
&lt;/h2&gt;

&lt;p&gt;We're building TeaQL because we believe developers shouldn't have to choose between clean Domain-Driven Design and raw SQL performance/visibility.&lt;/p&gt;

&lt;p&gt;If you try out this Kanban board or look at the code:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Does the query tracing (&lt;code&gt;.comment()&lt;/code&gt;) actually help you understand what the app is doing?&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;How do you feel about defining your domain in &lt;code&gt;model.xml&lt;/code&gt; vs writing Rust structs directly?&lt;/strong&gt; We'd love your thoughts on the DX of declarative modeling.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Upcoming Feature:&lt;/strong&gt; We are working on an &lt;code&gt;audit ignore&lt;/code&gt; attribute to exclude PII/sensitive data from the &lt;code&gt;EntityEventSink&lt;/code&gt;. How do you currently handle this in your stack?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Drop a comment on HN, open an issue, or reach out! &lt;/p&gt;

&lt;p&gt;&lt;em&gt;(P.S. TeaQL was originally born out of our need to manage complex workflows and data at scale. Check out the framework behind this at &lt;a href="https://teaql.io/" rel="noopener noreferrer"&gt;teaql.io&lt;/a&gt; — if you're building physical infra or complex business logic, come say hi!)&lt;/em&gt;&lt;/p&gt;

</description>
      <category>teaql</category>
      <category>showcase</category>
      <category>rust</category>
      <category>sqlite</category>
    </item>
  </channel>
</rss>
