Browse modulesTenancyFunctions
Function: assertRlsIsolation()
function assertRlsIsolation(input: RlsIsolationInput): Promise<void>;Defined in: server/tenancy/isolation-harness.ts:139
Run the DB-level tenant-isolation matrix. Seeds fixtures for two orgs (via the owner exec, bypassing RLS), then — as the non-superuser role — asserts across all four verbs:
- a bound tenant sees ONLY its own rows;
- a raw
WHERE tenant = otherstill returns zero (the DB enforces it, not the app-layer belt); - unbound context sees zero (fail closed);
- a cross-tenant INSERT is rejected with an RLS violation (
WITH CHECK), an own-tenant one passes; 4b. a cross-tenant UPDATE affects zero rows (they're invisible viaUSING); 4c. a cross-tenant DELETE affects zero rows; 4d. reassigning an OWN row to another tenant is rejected (WITH CHECK); - a stray permissive
TO PUBLIC USING (true)policy can't widen access (the RESTRICTIVE tenant boundary holds); - if
publicRead, the bypass admits cross-tenant SELECT but still no writes.
orgA/orgB must be THROWAWAY test tenant ids — the harness DELETEs every
row for them (before and after, as owner) to stay rerun-safe and leave no
fixtures behind. Never pass real tenant ids.
Parameters
| Parameter | Type |
|---|---|
input | RlsIsolationInput |
Returns
Promise<void>