Browse modulesTenancyTypes
Type Alias: TenantBinding
type TenantBinding =
| {
actorId: string | null;
mode: "tenant";
tenantId: string;
}
| {
mode: "public-read";
};Defined in: server/tenancy/context.ts:23
Request-scoped tenant context — the source of truth both tenancy layers read
(see the module README): the app-layer read-scope interceptor
(withTenantScope) and the Postgres RLS backstop (withTenantTransaction,
which pins the app.current_org GUC per request).
The value is SERVER-DERIVED (an auth session, or a trusted header) — never
client input. A consumer binds it for the lifetime of a request with
runWithTenant; everything reached inside (services → repositories → Prisma)
inherits it through AsyncLocalStorage without threading it through signatures.
Three modes:
- tenant — a normal tenant-scoped request. Reads are tenant-filtered; the GUC is the tenant id, so RLS admits only that tenant's rows.
- public-read — the deliberate cross-tenant public exception (e.g. an unauthenticated status lookup returning a PII-free subset). Reads are NOT tenant-filtered and the GUC sets a SELECT-only bypass.
- unbound — no binding (seed / system / an authed request with no active tenant). No filter; no GUC ⇒ RLS FAILS CLOSED (zero rows).