pub async fn resolve_org_scope(
conn: &mut PgConnection,
acting_unit: Uuid,
additional_entitled: &[Uuid],
) -> Result<OrgScope, OrgScopeError>Expand description
Resolve a session’s scope from the org tree.
acting_unit is the node the session acts at (from the signed token / tenant registry).
additional_entitled are further nodes the session holds entitlements for (e.g. a group
admin entitled to a sister company) — each contributes its whole subtree. The resolved scope
is the union of those subtrees plus the root node.
org_units is unfenced by design (it IS the scoping substrate), so this runs on any
connection of the tenant database regardless of fence state.