Interface: RlsIsolationInput
Defined in: server/tenancy/isolation-harness.ts:21
Properties
admin
readonly admin: RowExec;Defined in: server/tenancy/isolation-harness.ts:23
Owner/privileged exec (bypasses RLS) — seeds both orgs' fixtures + the stray-policy probe.
app
readonly app: RowExec;Defined in: server/tenancy/isolation-harness.ts:26
Exec connected AS the non-superuser, RLS-subject runtime role. MUST be a dedicated (non-pooled) connection — the checks pin session GUCs on it.
currentTenantGuc?
readonly optional currentTenantGuc?: string;Defined in: server/tenancy/isolation-harness.ts:42
GUC the tenant is pinned in. Default "app.current_org".
orgA
readonly orgA: string;Defined in: server/tenancy/isolation-harness.ts:32
Two distinct tenant ids to seed and cross-check.
orgB
readonly orgB: string;Defined in: server/tenancy/isolation-harness.ts:33
publicRead?
readonly optional publicRead?: boolean;Defined in: server/tenancy/isolation-harness.ts:46
Whether table was scaffolded with the public-read bypass. Default false.
publicReadGuc?
readonly optional publicReadGuc?: string;Defined in: server/tenancy/isolation-harness.ts:44
GUC the public-read bypass is pinned in. Default "app.public_read".
schema?
readonly optional schema?: string;Defined in: server/tenancy/isolation-harness.ts:28
Postgres schema containing table. Defaults to the connection search path.
seedRow
readonly seedRow: (org: string, tag: string) => Record<string, unknown>;Defined in: server/tenancy/isolation-harness.ts:38
Build one fixture row for org as a column→value map (must include the
tenant column). Called for A and B; the harness INSERTs it via admin.
Parameters
| Parameter | Type |
|---|---|
org | string |
tag | string |
Returns
Record<string, unknown>
table
readonly table: string;Defined in: server/tenancy/isolation-harness.ts:30
The tenant table to probe.
tenantDbColumn?
readonly optional tenantDbColumn?: string;Defined in: server/tenancy/isolation-harness.ts:40
Tenant DB column. Default "organization_id".