Skip to content

basalt / tenancy/src / tenantScoped

Function: tenantScoped() ​

> tenantScoped<W>(where?): W & object

Defined in: tenancy/src/scoped.ts:60

Fail-closed tenant filter for repository where clauses:

const rows = await db.project.findMany({ where: tenantScoped({ archived: false }) })

The tenant comes from the context and ONLY from the context. A tenantId in where is never used as a fallback: where is routinely built from client input ({ ...req.query }), and with no tenant resolved (tenancy's required defaults to false) that would let the client pick any tenant. tenantId is spread LAST, so a smuggled value cannot override the context tenant either. Throws TenantRequiredError when there is no context tenant — system code that must pin a tenant calls requireTenantId(id) explicitly, or runs inside tenancy.run(id, …).

Type Parameters ​

W ​

W extends Record<string, unknown> = Record<string, never>

Parameters ​

where? ​

W

Returns ​

W & object

Released under the MIT License.