appdata.instance.ensure-app-owned-policies ​
Apply owner-only write policies to an app's app-owned tables on its own instance; idempotent, and a no-op for apps on the shared plane
Close cross-owner writes on an app's app-owned tables, on its instance.
Before virtual-engine's split policies an app-owned table carried one FOR ALL policy that admitted any end-user of the app, and its live view's soft-delete rule ran as the superuser and ignored policies altogether. So any end-user could update or delete every app-owned row, directly through the Data API or through this library's own instance path.
structure.apply emits the fixed shape, but only when the owning org re-applies, and a structure cannot be replayed. This applies just the policies, the delete rule and the owner defaults (compile_app_owned_rls_ddl) to every app-owned table the catalog knows, one table per statement batch so a catalog table that never reached the instance is reported instead of failing the rest.
Idempotent: DROP/CREATE POLICY and RULE, ALTER COLUMN SET DEFAULT.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-appdata |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID |
identity_app_uuid | uuid | Yes | — | Identity app the credential reads; must own an appdata namespace in this organization |
request_id | string | No | — | Caller request id for audit correlation |
actor | string | No | — | — |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
identity_app_uuid | uuid | Yes | — | — |
backend_kind | string | Yes | — | shared |
statements_applied | integer | No | — | DDL statements executed on the instance |
tables_secured | list | No | — | App-owned tables now carrying the owner-only write policies |
tables_skipped | list | No | — | App-owned tables in the catalog with no table on the instance |
failure_reason | string | No | — | Engine-stamped failure reason |
failed_at_state | string | No | — | State when the workflow failed |
failed_step | string | No | — | Failed DAG step name |
failed_layer | integer | No | — | Failed DAG layer index |
error | string | No | — | Engine-stamped exception message |
error_type | string | No | — | Engine-stamped exception class name |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | complete | Ensure credential |
completed | No | Yes | Yes | — | Credential ensured |
failed | No | Yes | No | — | Ensure failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | complete | completed | — |
pending | fail | failed | — |
Outcomes ​
| Outcome | Type | Description | State Data Keys |
|---|---|---|---|
ensured | SUCCESS | Apply owner-only write policies to an app's app-owned tables on its own instance; idempotent, and a no-op for apps on the shared plane | backend_kind, statements_applied, tables_secured |
failed | FAILURE | Appdata workflow failed | failure_reason |
API Usage ​
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "appdata.instance.ensure-app-owned-policies",
"initial_data": {
"organization_uuid": "value",
"identity_app_uuid": "value"
}
}