( tableName: string, patch: Record<string, unknown> | undefined, context: ExecutorOwnerPolicyContext | undefined, )
| 194 | /** Assert a patch (`set`) doesn't move a row out of the bound partition. Only |
| 195 | * validates the partition columns that are actually being written. */ |
| 196 | export const assertOwnerPatch = ( |
| 197 | tableName: string, |
| 198 | patch: Record<string, unknown> | undefined, |
| 199 | context: ExecutorOwnerPolicyContext | undefined, |
| 200 | ): void => { |
| 201 | const ctx = requireContext(tableName, "write", context); |
| 202 | assertReachReadOnly(tableName, "write", ctx); |
| 203 | if (!patch) return; |
| 204 | if (patch.tenant !== undefined && patch.tenant !== ctx.tenant) { |
| 205 | policyViolation(`Storage write on table "${tableName}" cannot move a row across tenants.`); |
| 206 | } |
| 207 | if (patch.owner === "user" && (ctx.subject == null || patch.subject !== ctx.subject)) { |
| 208 | policyViolation( |
| 209 | `Storage write on table "${tableName}" cannot move a row outside the bound subject.`, |
| 210 | ); |
| 211 | } |
| 212 | }; |
| 213 | |
| 214 | export const hasExecutorOwnerPolicy = (table: AnyTable): boolean => |
| 215 | table.policies.some((policy) => policy.name === executorOwnerPolicyName); |
no test coverage detected