Browse modulesTenancyFunctions
Function: assertRlsEnabled()
function assertRlsEnabled(input: RlsDeploymentInput): Promise<void>;Defined in: server/tenancy/coverage.ts:114
Throw if any managed table isn't actually protected at the DB level: RLS not
ENABLED, still FORCEd, or ANY of the five role-qualified policies the
scaffold creates (taproot_<role>_{base,sel,ins,upd,del}) absent. All five
are required — a
partial revert that dropped _ins/_upd/_del would leave the permissive
_base + restrictive _sel in place, so reads look scoped while writes are
wide open. Catches "listed in tables but the scaffold never ran, was
reverted, or RLS was disabled" — which the coverage guard (config-only) and a
single-table isolation run both miss.
Parameters
| Parameter | Type |
|---|---|
input | RlsDeploymentInput |
Returns
Promise<void>