Skip to content

Scope materialized views to a tenant - #25

Merged
venkat1701 merged 3 commits into
mainfrom
feat/tenant-scoped-views
Oct 4, 2026
Merged

venkat1701 merged 3 commits into
mainfrom
feat/tenant-scoped-views

Conversation

@venkat1701

@venkat1701 venkat1701 commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #11

Views now belong to the tenant of the admin who created them. Descriptor gained a tenant field, and:

  • The initial build only looks at atoms from that tenant.
  • Feed deltas only update cells for that tenant's atoms. An existing cell is always updated, so deletes still go through after the atom record is gone.
  • View names are unique per tenant, and SHOW VIEWS, VIEW and REFRESH VIEW only see your own tenant.
  • Continuous views refresh internally as system inside the view's tenant, so the tenant checks in the computation (Reader.edge and friends) still hold.

While doing this I noticed create and refresh always wrote as the internal system principal. The executor's admin check was the only guard. Both now take the caller's principal, and the executor passes the session's through.

Behaviour change worth knowing: a view created by the default-tenant admin now only covers default-tenant data instead of everything. That matches how every other read in HStore is scoped.

The descriptor encoding gained the tenant field. Nothing is released yet, so I didn't add a migration for existing view descriptors.

materializedViewsStayInsideTheirTenant in SecurityTest covers a tenant admin and the default admin each building a view over their own data, refreshes after new commits, a continuous view, and an admin trying to read another tenant's view by name. Full ./mvnw install passes locally.

@venkat1701
venkat1701 force-pushed the feat/tenant-scoped-views branch 2 times, most recently from d9441b3 to 16c242e Compare October 4, 2026 06:42
A view now records the tenant of the admin who created it. Builds and
feed deltas only cover that tenant's atoms, names and listings are per
tenant, and continuous refreshes run inside the view's tenant.

Creating and refreshing a view used to write as the internal system
principal; both now take the caller's principal, and the executor passes
the session's through.
@venkat1701
venkat1701 force-pushed the feat/tenant-scoped-views branch from 16c242e to 5eed17d Compare October 4, 2026 08:23
@venkat1701
venkat1701 merged commit 37bd32c into main Oct 4, 2026
@venkat1701
venkat1701 deleted the feat/tenant-scoped-views branch October 6, 2026 00:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Materialized views can't be scoped to a tenant

1 participant