Kaizen
Browse modulesTenancyInterfaces

Interface: RlsConfig

Defined in: server/tenancy/rls.ts:24

DB-level tenancy config — the tables/role/column as they exist in Postgres.

Properties

authoritativeGrants?

readonly optional authoritativeGrants?: boolean;

Defined in: server/tenancy/rls.ts:34

Revoke grants from tables omitted from tables. Default true. Disable when this config shares a schema with other features.


currentTenantGuc?

readonly optional currentTenantGuc?: string;

Defined in: server/tenancy/rls.ts:51

GUC the current tenant is read from. Default "app.current_org".


policyNamespace?

readonly optional policyNamespace?: string;

Defined in: server/tenancy/rls.ts:32

Optional suffix that prevents independent features sharing a role/schema from owning the same policy names.


publicReadGuc?

readonly optional publicReadGuc?: string;

Defined in: server/tenancy/rls.ts:62

GUC the public-read bypass is read from (only when publicReadTables is non-empty). Default "app.public_read".


publicReadTables?

readonly optional publicReadTables?: readonly string[];

Defined in: server/tenancy/rls.ts:60

Tables (a subset of tables) that get the SELECT-only public-read bypass — a deliberate cross-tenant read (e.g. an unauthenticated status lookup on ONE narrow, PII-free table). Empty by default. Scoped per-table, not schema-wide: only these tables gain the bypass branch, and only for SELECT; writes are never affected. The bypass is admitted while publicReadGuc is 'on' (set by runWithPublicRead).


role

readonly role: string;

Defined in: server/tenancy/rls.ts:26

Non-superuser role the runtime connects as (RLS-subject).


schema?

readonly optional schema?: string;

Defined in: server/tenancy/rls.ts:30

Postgres schema the tables live in. Default "public".


tables

readonly tables: readonly string[];

Defined in: server/tenancy/rls.ts:28

Tenant tables to protect (DB names, e.g. "permit").


tenantDbColumn?

readonly optional tenantDbColumn?: string;

Defined in: server/tenancy/rls.ts:41

The tenant DB column (snake_case) on every table. Default "organization_id". This is the raw Postgres column the policies key on — distinct from TenancyConfig.tenantColumn, which is the camelCase Prisma field the app-layer belt uses. Same logical column, named at two layers.


tenantIdType?

readonly optional tenantIdType?: "uuid" | "text";

Defined in: server/tenancy/rls.ts:49

SQL type the tenant id is cast to in the policy predicate. A strict allowlist — "uuid" (default) or "text" (cuid/varchar/citext ids) — NOT a free-form string: the value is interpolated into every RLS predicate, so anything else (e.g. "uuid or true") could inject an always-true clause and defeat isolation. Need another type? Add it to TENANT_ID_TYPES.

On this page