Class: OpenLoam::Membership
- Inherits:
-
TenantRecord
- Object
- TenantRecord
- OpenLoam::Membership
- Defined in:
- app/models/open_loam/membership.rb
Overview
Connects an actor (the host app's User) to a tenant with a role. Roles are plain strings ("manager", "employee", ...) — policies interpret them. Tenant-scoped like everything else: asking for someone's role always means "their role in the CURRENT tenant".
Class Method Summary collapse
-
.tenants_for(user) ⇒ Object
The other blessed cross-tenant lookup (see OpenLoam::ApiToken.authenticate).
Class Method Details
.tenants_for(user) ⇒ Object
The other blessed cross-tenant lookup (see OpenLoam::ApiToken.authenticate). "Which tenants may this person enter?" is asked at login, before any tenant is chosen, so it cannot be answered from inside one — which is why it lives in the gem rather than in host app code, where reaching across tenants is a guardrail failure.
Returns a OpenLoam::Tenant relation, so callers can order/filter it further.
21 22 23 24 25 |
# File 'app/models/open_loam/membership.rb', line 21 def self.tenants_for(user) user_id = user.respond_to?(:id) ? user.id : user OpenLoam::Tenant.where(id: unscoped.where(user_id: user_id).select(:tenant_id)).order(:name) end |