feat(02-01): Prisma schema expansion, RLS migration, and PrismaModule
- Add User, Role enum, PasswordResetToken, LdapConfig, LdapFieldMapping models - Expand Tenant model with isActive, users relation, ldapConfig relation - Create RLS migration with tenant isolation policies on all tenant-scoped tables - Create PrismaModule (global), PrismaService, and forTenant extension - Add JWT_SECRET, TESSERA_ADMIN_*, TESSERA_FORCE_CHANGE env vars to docker-compose - Install @nestjs/jwt, @nestjs/passport, passport, argon2, class-validator deps
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
import { PrismaClient } from '@prisma/client';
|
||||
|
||||
/**
|
||||
* Creates a tenant-scoped Prisma client that sets the app.current_tenant
|
||||
* PostgreSQL session variable before every query via RLS.
|
||||
*
|
||||
* Uses parameterized set_config to prevent SQL injection (T-02-05).
|
||||
*/
|
||||
export function forTenant(prisma: PrismaClient, tenantId: string) {
|
||||
return prisma.$extends({
|
||||
query: {
|
||||
$allOperations({ args, query }) {
|
||||
return (prisma as any).$transaction(async (tx: any) => {
|
||||
// Use parameterized query to avoid SQL injection
|
||||
await tx.$executeRawUnsafe(
|
||||
`SELECT set_config('app.current_tenant', $1, true)`,
|
||||
tenantId,
|
||||
);
|
||||
return query(args);
|
||||
});
|
||||
},
|
||||
},
|
||||
});
|
||||
}
|
||||
Reference in New Issue
Block a user