basalt / tenancy/src / tenantScoped
Function: tenantScoped()
> tenantScoped<W>(where?): W & object
Defined in: tenancy/src/scoped.ts:60
Fail-closed tenant filter for repository where clauses:
const rows = await db.project.findMany({ where: tenantScoped({ archived: false }) })
The tenant comes from the context and ONLY from the context. A tenantId in where is never used as a fallback: where is routinely built from client input ({ ...req.query }), and with no tenant resolved (tenancy's required defaults to false) that would let the client pick any tenant. tenantId is spread LAST, so a smuggled value cannot override the context tenant either. Throws TenantRequiredError when there is no context tenant — system code that must pin a tenant calls requireTenantId(id) explicitly, or runs inside tenancy.run(id, …).
Type Parameters
W
W extends Record<string, unknown> = Record<string, never>
Parameters
where?
W
Returns
W & object