OptionaladminRoles?: string[]Roles that bypass tenant filtering entirely
OptionalautoExcludeCoreEntities?: booleanWhen true, entities in the __mj core schema are never tenant-filtered
OptionalcontextSource?: "header" | "linkedEntity" | "custom"How the tenant ID is determined for each request
OptionaldefaultTenantColumn?: stringDefault column name containing the tenant identifier
Optionalenabled?: booleanMaster switch — when false (default), no tenant isolation is applied
OptionalentityColumnMappings?: Record<string, string>Per-entity overrides for the tenant column name: { "EntityName": "ColumnName" }
OptionalscopedEntities?: string[]Entities included/excluded from tenant filtering based on scopingStrategy
OptionalscopingStrategy?: "allowlist" | "denylist"Whether scopedEntities is an allowlist or denylist of entities to filter
OptionaltenantHeader?: stringHTTP header name used when contextSource is 'header'
OptionalwriteProtection?: "strict" | "log" | "off"Write protection mode: 'strict' rejects, 'log' warns, 'off' skips validation
Creates Express middleware that resolves and attaches TenantContext to the authenticated user's UserInfo for each request.
This middleware runs in the post-auth slot (after
createUnifiedAuthMiddleware) soreq.userPayloadis available. It reads the tenant ID from the configured source and attaches it directly touserPayload.userRecord.TenantContext.By the time GraphQL resolvers or REST handlers run, the contextUser already has TenantContext set — no deferred pickup via
req['__mj_tenantId']needed.