Documents refresh_hierarchy_cache, is_rule_valid and org_in_scope, and
corrects the get_org_scope scope list which still omitted unattributed
and all.
Replaces em dashes and other typographic unicode with ASCII throughout
the schema comments, the test suite and the documentation. Comments and
prose are ASCII only.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds a first-class org target vocabulary shared by every rule kind: a
specific organization, unattributed (objects whose org is NULL), or all.
A role can now be granted the unassigned pile without a global rule.
- rules.scope gains 'unattributed' and 'all'
- user_rules.org_id accepts NULL to target unattributed objects
- org_in_scope partitions the classes: 'unattributed' matches only a NULL
target, tree scopes never match one
- has_permission(user, activity, view) capability probe for UI gating
- current_org_filter() parses morbac.org_ids once into org UUIDs plus the
unattributed-bucket flag (a JSON null element requests it)
- rls_check split by arity so NULL never carries two meanings:
rls_check(activity, view) for tables with no org column,
rls_check(activity, view, row_org_id[, row_user_id]) where a NULL
row_org_id means the record is unattributed
- detect_rule_conflicts is scope-aware, so rules targeting different
object sets no longer collide
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>