pub async fn execute_unit_scoped<'q>(
pool: &PgPool,
unit: Uuid,
query: Query<'q, Postgres, PgArguments>,
) -> Result<PgQueryResult, Error>Expand description
Statement-level org fence for a write whose row belongs to one org node — the hand-written repository path for callers outside a request scope.
Inside a request scope (with_org_request_scope or the legacy
with_request_scope) the query runs on the
request connection, which already carries both fence variables. Outside one, it opens a
short transaction and sets app.scope_unit_ids to exactly unit: the INSERT’s
WITH CHECK only tests the row’s own org_unit_id, so the row’s node alone satisfies it —
and a read that accidentally rides this helper sees only that node (fail-narrow, never
leaky). Reads that need the session’s whole entitlement union must run inside a resolved
request scope, not this helper.