MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / assertOwnerPatch

Function assertOwnerPatch

packages/core/sdk/src/owner-policy.ts:196–212  ·  view source on GitHub ↗
(
  tableName: string,
  patch: Record<string, unknown> | undefined,
  context: ExecutorOwnerPolicyContext | undefined,
)

Source from the content-addressed store, hash-verified

194/** Assert a patch (`set`) doesn't move a row out of the bound partition. Only
195 * validates the partition columns that are actually being written. */
196export const assertOwnerPatch = (
197 tableName: string,
198 patch: Record<string, unknown> | undefined,
199 context: ExecutorOwnerPolicyContext | undefined,
200): void => {
201 const ctx = requireContext(tableName, "write", context);
202 assertReachReadOnly(tableName, "write", ctx);
203 if (!patch) return;
204 if (patch.tenant !== undefined && patch.tenant !== ctx.tenant) {
205 policyViolation(`Storage write on table "${tableName}" cannot move a row across tenants.`);
206 }
207 if (patch.owner === "user" && (ctx.subject == null || patch.subject !== ctx.subject)) {
208 policyViolation(
209 `Storage write on table "${tableName}" cannot move a row outside the bound subject.`,
210 );
211 }
212};
213
214export const hasExecutorOwnerPolicy = (table: AnyTable): boolean =>
215 table.policies.some((policy) => policy.name === executorOwnerPolicyName);

Callers 1

ownedExecutorTableFunction · 0.90

Calls 3

requireContextFunction · 0.85
assertReachReadOnlyFunction · 0.85
policyViolationFunction · 0.85

Tested by

no test coverage detected