Skip to main content

execute_unit_scoped

Function execute_unit_scoped 

Source
pub async fn execute_unit_scoped<'q>(
    pool: &PgPool,
    unit: Uuid,
    query: Query<'q, Postgres, PgArguments>,
) -> Result<PgQueryResult, Error>
Expand description

Statement-level org fence for a write whose row belongs to one org node — the hand-written repository path for callers outside a request scope.

Inside a request scope (with_org_request_scope or the legacy with_request_scope) the query runs on the request connection, which already carries both fence variables. Outside one, it opens a short transaction and sets app.scope_unit_ids to exactly unit: the INSERT’s WITH CHECK only tests the row’s own org_unit_id, so the row’s node alone satisfies it — and a read that accidentally rides this helper sees only that node (fail-narrow, never leaky). Reads that need the session’s whole entitlement union must run inside a resolved request scope, not this helper.