Kaizen
Browse modulesTenancyFunctions

Function: assertRlsIsolation()

function assertRlsIsolation(input: RlsIsolationInput): Promise<void>;

Defined in: server/tenancy/isolation-harness.ts:139

Run the DB-level tenant-isolation matrix. Seeds fixtures for two orgs (via the owner exec, bypassing RLS), then — as the non-superuser role — asserts across all four verbs:

  1. a bound tenant sees ONLY its own rows;
  2. a raw WHERE tenant = other still returns zero (the DB enforces it, not the app-layer belt);
  3. unbound context sees zero (fail closed);
  4. a cross-tenant INSERT is rejected with an RLS violation (WITH CHECK), an own-tenant one passes; 4b. a cross-tenant UPDATE affects zero rows (they're invisible via USING); 4c. a cross-tenant DELETE affects zero rows; 4d. reassigning an OWN row to another tenant is rejected (WITH CHECK);
  5. a stray permissive TO PUBLIC USING (true) policy can't widen access (the RESTRICTIVE tenant boundary holds);
  6. if publicRead, the bypass admits cross-tenant SELECT but still no writes.

orgA/orgB must be THROWAWAY test tenant ids — the harness DELETEs every row for them (before and after, as owner) to stay rerun-safe and leave no fixtures behind. Never pass real tenant ids.

Parameters

ParameterType
inputRlsIsolationInput

Returns

Promise<void>

On this page