Kaizen
Browse modulesTenancyFunctions

Function: buildRlsStatements()

function buildRlsStatements(config: RlsConfig): string[];

Defined in: server/tenancy/rls.ts:113

Build the SQL that installs RLS for a tenant schema. Returns a SINGLE statement: one DO block that creates the runtime role, grants, and (per protected table) ENABLE + policies. One statement = atomic under any executor (incl. an autocommit pool.query, where BEGIN/COMMIT across separate statements would land on different pooled connections) — a mid-apply failure rolls the whole thing back, never leaving a half-configured schema. Idempotent/re-runnable. Pure — drop it in a migration or hand it to applyRlsPolicies. Must run as a privileged role.

Parameters

ParameterType
configRlsConfig

Returns

string[]

On this page