pub enum TableKeys {
Uniform,
PerTable(BTreeMap<String, ResolvedScope>),
PerTableTarget {
keys: BTreeMap<String, ResolvedScope>,
public: BTreeMap<String, Vec<PublicTermSql>>,
write: BTreeSet<String>,
require_public: bool,
},
}Expand description
Per-table tenant-key resolution for a Scope (PLAN-tenancy-principal D2/D3). Legacy / no
project schema ⇒ Uniform: every table scopes on Scope::column.
A present project schema ⇒ PerTable: the authoritative table → ResolvedScope map — Column(col) scopes that table on col (TenantKeyed identity tables
on their own PK), Unscoped a global table (no predicate), TenantOrSession { tenant, session }
the R3 anonymous-first disjunct on two disjoint columns; a table absent from the map is
refused (OrmError::TenancyUndeclared, deny-by-default).
Variants§
Uniform
PerTable(BTreeMap<String, ResolvedScope>)
PerTableTarget
A target read/write (R4/D8): the same per-table tenant keys as PerTable, PLUS (when
require_public) a per-table PUBLIC-subset
confinement conjoined onto every accessed table. Built only by the host for a
TenancyClass::Target fetch; never by a guest.
Fields
keys: BTreeMap<String, ResolvedScope>public: BTreeMap<String, Vec<PublicTermSql>>write: BTreeSet<String>Target WRITE SET-allowlist (5b), deny-by-default. The columns a target INSERT/UPDATE
may set. Empty ⇒ read-only — any write force-scoped under this variant is refused
(OrmError::TargetWriteNotGranted). Non-empty ⇒ an INSERT force-stamps tenant = B and
(when require_public) the public-visibility columns and accepts ONLY these columns from
the guest; an UPDATE confines its WHERE to tenant = B AND <public> and may set ONLY
these columns; a DELETE is always refused. The tenant/visibility columns are never in this
set, so a target write can neither change ownership nor flip a row’s visibility.
require_public: boolWhether a per-table PUBLIC subset is mandatory (R4/D8 5c ruling A). true for the
anonymous target sources (domain/handle): a table accessed with no declared
public subset is refused (OrmError::PublicSubsetUndeclared) — for an unauthenticated
actor the visibility predicate is the ONLY guard against reaching B’s private rows.
false for a capability-only field: the host-verified, audience-bound capability
(naming tid = B + the granted scope) IS the authorization, so a table with no declared
subset confines to tenant = B alone (no visibility conjunct, no refusal) and the app’s
within-tenant per-client filter stays in-guest. A table that DOES declare a subset is still
confined by it either way. Never all; still exactly one tenant B.