import type { DB } from '../../data/db/index.js'; /** * SQL types a tenant discriminator column may be. The union members are * literal Postgres type names, so they double as the cast target — a tenant * policy compares the column against the session GUC cast to this type. A * field whose kind is not one of these cannot be a tenant key; the generate * layer rejects it before reaching here (see rls-generate.ts). */ export type TenantKeyType = 'uuid' | 'text' | 'integer' | 'bigint'; export declare function tenantIsolationPolicy(table: string, column?: string, keyType?: TenantKeyType, sessionVar?: string, force?: boolean): string; export declare function enableTenantRls(db: DB, table: string, column?: string, keyType?: TenantKeyType, force?: boolean): Promise; /** The principal axes carried on the request/job context and propagated as GUCs. */ export interface ExpectedPrincipal { readonly tenant: string | null; readonly user: string | null; readonly asOf: string | null; } /** * Cross-checks the application's principal (tenant, user, asOf) against the GUCs * actually set on the Postgres session — defense-in-depth against an * AsyncLocalStorage context swap propagating one principal's identity onto * another's transaction. All three axes are checked together so a mismatch on * any one aborts before a query can read the wrong rows. */ export declare function verifyPrincipalContext(db: DB, expected: ExpectedPrincipal): Promise; //# sourceMappingURL=rls.d.ts.map