Adds a first-class org target vocabulary shared by every rule kind: a
specific organization, unattributed (objects whose org is NULL), or all.
A role can now be granted the unassigned pile without a global rule.
- rules.scope gains 'unattributed' and 'all'
- user_rules.org_id accepts NULL to target unattributed objects
- org_in_scope partitions the classes: 'unattributed' matches only a NULL
target, tree scopes never match one
- has_permission(user, activity, view) capability probe for UI gating
- current_org_filter() parses morbac.org_ids once into org UUIDs plus the
unattributed-bucket flag (a JSON null element requests it)
- rls_check split by arity so NULL never carries two meanings:
rls_check(activity, view) for tables with no org column,
rls_check(activity, view, row_org_id[, row_user_id]) where a NULL
row_org_id means the record is unattributed
- detect_rule_conflicts is scope-aware, so rules targeting different
object sets no longer collide
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>