Phase B: RLS kernel (alloy_app + FORCE RLS + PG isolation) #1
Loading…
Reference in a new issue
No description provided.
Delete branch "finish/phase-b-rls"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Phase B multi-tenant security kernel (roadmap B1–B6):
alloy_app(no superuser / no BYPASSRLS) + grantsFORCE ROW LEVEL SECURITYon all tenant tablesset_configinbackend/app/core/rls.pyonlyapp.auth_user_by_email, password-reset SECURITY DEFINER helpers)alloy, pytest asalloy_app(service hostpostgres)docs/repo-conventions.md(merge/PR protocol for finish spine)Not in this PR (residuals): B7 authz unify, B8 refresh/logout, B9 RBAC matrix — see
docs/residual-review-findings/finish-phase-b-rls.md.Evidence
docs/plans/2026-08-01-phase-b-rls/VERIFY.md204unit (not postgres);5postgres (alloy_app)ALLOY_DATABASE_URLfailstest_app_role_is_not_superuserOps after merge
Test plan
Spec / plan
docs/specs/2026-08-01-phase-b-rls/SPEC.md