pub struct Tenancy<M> { /* private fields */ }Expand description
How a resource’s rows belong to a tenant.
A resource declares one with ResourceDef::tenancy. A
scoped tenancy names, by lens, the tenant UUID each row is filtered on:
ResourceDef::new().tenancy(Tenancy::column(Post::fields().tenant_id()))
ResourceDef::new().tenancy(Tenancy::via(Comment::fields().post().tenant_id()))A scoped resource answers 403 to a request with no tenant, in every handler, instead of serving unscoped rows or writing rows with no tenant.
Implementations§
Source§impl<M: Model + 'static> Tenancy<M>
impl<M: Model + 'static> Tenancy<M>
Sourcepub fn none() -> Self
pub fn none() -> Self
Rows belong to no tenant: the resource is served as
query states it, to every
request. The default.
Sourcepub fn column<T>(lens: impl Into<Path<M, T>>) -> Self
pub fn column<T>(lens: impl Into<Path<M, T>>) -> Self
Rows carry their tenant in one UUID column of their own model, Uuid
or Option<Uuid>.
The framework filters every loader on it and stamps the request’s tenant into it on create, so the record form must not claim it. Mounting the panel refuses a lens that is not a single field of the model.
Sourcepub fn via<T>(lens: impl Into<Path<M, T>>) -> Self
pub fn via<T>(lens: impl Into<Path<M, T>>) -> Self
Rows inherit their tenant through a relation: lens reaches the parent’s
tenant column, as Comment::fields().post().tenant_id() does.
The framework filters every loader on it. It stamps nothing on create:
a row’s tenant is its parent’s. The lens starts at a belongs_to
relation, and mounting the panel requires the form to write that
relation’s foreign key through a relationship field over a tenant-scoped
resource, whose key the framework re-checks against that resource’s
tenant-scoped query inside the write.