Interface: RlsConfig
Defined in: server/tenancy/rls.ts:24
DB-level tenancy config — the tables/role/column as they exist in Postgres.
Properties
authoritativeGrants?
readonly optional authoritativeGrants?: boolean;Defined in: server/tenancy/rls.ts:34
Revoke grants from tables omitted from tables. Default true. Disable when this config shares a schema with other features.
currentTenantGuc?
readonly optional currentTenantGuc?: string;Defined in: server/tenancy/rls.ts:51
GUC the current tenant is read from. Default "app.current_org".
policyNamespace?
readonly optional policyNamespace?: string;Defined in: server/tenancy/rls.ts:32
Optional suffix that prevents independent features sharing a role/schema from owning the same policy names.
publicReadGuc?
readonly optional publicReadGuc?: string;Defined in: server/tenancy/rls.ts:62
GUC the public-read bypass is read from (only when publicReadTables is non-empty). Default "app.public_read".
publicReadTables?
readonly optional publicReadTables?: readonly string[];Defined in: server/tenancy/rls.ts:60
Tables (a subset of tables) that get the SELECT-only public-read bypass —
a deliberate cross-tenant read (e.g. an unauthenticated status lookup on
ONE narrow, PII-free table). Empty by default. Scoped per-table, not
schema-wide: only these tables gain the bypass branch, and only for SELECT;
writes are never affected. The bypass is admitted while publicReadGuc is
'on' (set by runWithPublicRead).
role
readonly role: string;Defined in: server/tenancy/rls.ts:26
Non-superuser role the runtime connects as (RLS-subject).
schema?
readonly optional schema?: string;Defined in: server/tenancy/rls.ts:30
Postgres schema the tables live in. Default "public".
tables
readonly tables: readonly string[];Defined in: server/tenancy/rls.ts:28
Tenant tables to protect (DB names, e.g. "permit").
tenantDbColumn?
readonly optional tenantDbColumn?: string;Defined in: server/tenancy/rls.ts:41
The tenant DB column (snake_case) on every table. Default
"organization_id". This is the raw Postgres column the policies key on —
distinct from TenancyConfig.tenantColumn, which is the camelCase Prisma
field the app-layer belt uses. Same logical column, named at two layers.
tenantIdType?
readonly optional tenantIdType?: "uuid" | "text";Defined in: server/tenancy/rls.ts:49
SQL type the tenant id is cast to in the policy predicate. A strict
allowlist — "uuid" (default) or "text" (cuid/varchar/citext ids) — NOT
a free-form string: the value is interpolated into every RLS predicate, so
anything else (e.g. "uuid or true") could inject an always-true clause
and defeat isolation. Need another type? Add it to TENANT_ID_TYPES.