pub async fn with_org_request_scope<F, R>(
pool: &PgPool,
scope: OrgScope,
f: F,
) -> Result<R, Error>where
F: Future<Output = R>,Expand description
Run f with a request-dedicated connection carrying the session’s org scope.
Sets app.scope_unit_ids (the entitlement-union fence), the legacy app.company_id
(equality fence, resolved from the acting node’s company ancestry), and app.acting_unit_id
(the acting-unit DEFAULT source for inserts on decorated tables, ADR-0029) at the session
level, so org-re-keyed and not-yet-re-keyed tables are both fenced correctly for the whole
request — including ID-only lookups, which ride the connection rather than the query text.
Mirrors with_request_scope’s reset discipline:
all three variables are cleared unconditionally before the connection returns to the pool,
even when a REQUEST_CONN clone outlives the scope — a clone that runs queries after the
reset does so unscoped (fail-closed), never with the previous session’s scope.