Skip to content

feat(tenancy): guard test – every app table has forced RLS #29

Description

@Fluory

Goal

A new table can never silently skip tenant isolation: CI fails when any table in schema app lacks forced RLS or a company policy.

Acceptance criteria

  • Integration test enumerates all tables in schema app (pg_class/pg_policy) and asserts RLS enabled + forced and a company_id policy
  • Documented allow-list for tables that are deliberately global (empty by default; each entry needs a reason)
  • Runs in verify

Not part of this task

  • Changing existing policies

Affected areas

  • src/features/tenancy/
  • tests/integration/

Test plan

Criterion Check
guard integration test; plus a deliberately unprotected temp table in the test proves the guard fails

Security/Privacy affected?

Yes – tenant isolation (ADR-0001 D7).

Epic: #18 · Architecture: docs/decisions/ADR-0001-pilot-architecture.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

featureNew capabilityreadyDefinition of Ready met – may be claimedsecuritySecurity or privacy relevant

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions