Member Junction
    Preparing search index...

    Function createTenantPreSaveHook

    • Creates a PreSaveHook that validates the tenant column on writes.

      In 'strict' mode, rejects saves where the tenant column value doesn't match the user's TenantContext. In 'log' mode, warns but allows. In 'off' mode, this hook is a no-op.

      Parameters

      • config: {
            adminRoles?: string[];
            autoExcludeCoreEntities?: boolean;
            contextSource?: "header" | "linkedEntity" | "custom";
            defaultTenantColumn?: string;
            enabled?: boolean;
            entityColumnMappings?: Record<string, string>;
            scopedEntities?: string[];
            scopingStrategy?: "allowlist" | "denylist";
            tenantHeader?: string;
            writeProtection?: "strict" | "log" | "off";
        }
        • OptionaladminRoles?: string[]

          Roles that bypass tenant filtering entirely

        • OptionalautoExcludeCoreEntities?: boolean

          When true, entities in the __mj core schema are never tenant-filtered

        • OptionalcontextSource?: "header" | "linkedEntity" | "custom"

          How the tenant ID is determined for each request

        • OptionaldefaultTenantColumn?: string

          Default column name containing the tenant identifier

        • Optionalenabled?: boolean

          Master switch — when false (default), no tenant isolation is applied

        • OptionalentityColumnMappings?: Record<string, string>

          Per-entity overrides for the tenant column name: { "EntityName": "ColumnName" }

        • OptionalscopedEntities?: string[]

          Entities included/excluded from tenant filtering based on scopingStrategy

        • OptionalscopingStrategy?: "allowlist" | "denylist"

          Whether scopedEntities is an allowlist or denylist of entities to filter

        • OptionaltenantHeader?: string

          HTTP header name used when contextSource is 'header'

        • OptionalwriteProtection?: "strict" | "log" | "off"

          Write protection mode: 'strict' rejects, 'log' warns, 'off' skips validation

      Returns PreSaveHook