Part of UniERP — an open-source, self-hostable multi-tenant application platform. Repository map · Architecture · Contributing · Security
Layer L2 — Runtime of the UniERP platform. Depends on: L0.
The Prisma multi-file schema, migrations, RLS policies, seeds, and the tenant-isolation test generator.
This repository owns the only layer of tenant isolation that is proof rather than convention: RLS ENABLE and FORCE on every tenant table, an application role that is NOBYPASSRLS, and a generated two-tenant test per table. Isolation tests must connect as the application role — a test run as the owner passes against a table with no policy at all.
A repository may depend only on published artifacts of a strictly lower layer — never sideways within a layer, never upward. A cycle is not discouraged; it is unrepresentable, because the lower layer's package cannot name the higher one.
See the platform overview for the full map, and
PLATFORM_ARCHITECTURE.md § 4.2 for
the reasoning.
AGPL-3.0.