Files
schalli d0b36c8f22 feat(02-01): Prisma schema expansion, RLS migration, and PrismaModule
- Add User, Role enum, PasswordResetToken, LdapConfig, LdapFieldMapping models
- Expand Tenant model with isActive, users relation, ldapConfig relation
- Create RLS migration with tenant isolation policies on all tenant-scoped tables
- Create PrismaModule (global), PrismaService, and forTenant extension
- Add JWT_SECRET, TESSERA_ADMIN_*, TESSERA_FORCE_CHANGE env vars to docker-compose
- Install @nestjs/jwt, @nestjs/passport, passport, argon2, class-validator deps
2026-06-18 13:22:38 +02:00

38 lines
1.4 KiB
PL/PgSQL

-- Create function to get current tenant from session variable
CREATE OR REPLACE FUNCTION current_tenant_id() RETURNS TEXT AS $$
SELECT current_setting('app.current_tenant', true);
$$ LANGUAGE sql STABLE;
-- Enable RLS on User table
ALTER TABLE "User" ENABLE ROW LEVEL SECURITY;
ALTER TABLE "User" FORCE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation_policy ON "User"
USING ("tenantId" = current_tenant_id());
-- Enable RLS on PasswordResetToken table (via userId -> User -> tenantId)
-- PasswordResetToken does not have a direct tenantId column, so we join through User
ALTER TABLE "PasswordResetToken" ENABLE ROW LEVEL SECURITY;
ALTER TABLE "PasswordResetToken" FORCE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation_policy ON "PasswordResetToken"
USING ("userId" IN (
SELECT "id" FROM "User" WHERE "tenantId" = current_tenant_id()
));
-- Enable RLS on LdapConfig table
ALTER TABLE "LdapConfig" ENABLE ROW LEVEL SECURITY;
ALTER TABLE "LdapConfig" FORCE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation_policy ON "LdapConfig"
USING ("tenantId" = current_tenant_id());
-- Enable RLS on LdapFieldMapping table (via ldapConfigId -> LdapConfig -> tenantId)
ALTER TABLE "LdapFieldMapping" ENABLE ROW LEVEL SECURITY;
ALTER TABLE "LdapFieldMapping" FORCE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation_policy ON "LdapFieldMapping"
USING ("ldapConfigId" IN (
SELECT "id" FROM "LdapConfig" WHERE "tenantId" = current_tenant_id()
));