{
  "executed_at": "2026-09-28T00:02:56.405722+00:00",
  "scope": "Local PostgreSQL + PostgREST; not hosted Supabase",
  "images": {
    "postgres": "postgres:18.6-trixie@sha256:86c951e05bf56c93d95d397747fb8820ac76cc3bedb78f43abd83eedbe3666ae",
    "postgrest": "postgrest/postgrest:v14.14@sha256:d2009b5c9deffc210c8a5592698472fede14fd9f6ca89823c8474ca54d58c012"
  },
  "versions": {
    "postgres": "18.6 (Debian 18.6-1.pgdg13+2)",
    "postgrest": "PostgREST 14.14",
    "docker_server": "29.1.3"
  },
  "source_sha256": {
    "fixture.sql": "71ea271fcaa6929f57ea7bce45a699ea90ac167a8679fcfd0ec2900592f8f26d",
    "run.py": "f946862576fecb0ac8a489734cf30e81a1e849aa0a5108bd2131de0b0e77fbe7"
  },
  "passed": 43,
  "checks": [
    {
      "case": "request role: anon",
      "http_status": 200,
      "observed": {
        "db_role": "anon",
        "subject": null,
        "bypassrls": false,
        "superuser": false,
        "rls_active": true,
        "rls_forced": true,
        "rls_enabled": true,
        "table_owner": "postgres",
        "can_change_org": false,
        "can_change_membership": false
      }
    },
    {
      "case": "request role: employee_a",
      "http_status": 200,
      "observed": {
        "db_role": "authenticated",
        "subject": "10000000-0000-0000-0000-000000000001",
        "bypassrls": false,
        "superuser": false,
        "rls_active": true,
        "rls_forced": true,
        "rls_enabled": true,
        "table_owner": "postgres",
        "can_change_org": false,
        "can_change_membership": false
      }
    },
    {
      "case": "request role: partner_a",
      "http_status": 200,
      "observed": {
        "db_role": "authenticated",
        "subject": "10000000-0000-0000-0000-000000000002",
        "bypassrls": false,
        "superuser": false,
        "rls_active": true,
        "rls_forced": true,
        "rls_enabled": true,
        "table_owner": "postgres",
        "can_change_org": false,
        "can_change_membership": false
      }
    },
    {
      "case": "request role: employee_b",
      "http_status": 200,
      "observed": {
        "db_role": "authenticated",
        "subject": "20000000-0000-0000-0000-000000000001",
        "bypassrls": false,
        "superuser": false,
        "rls_active": true,
        "rls_forced": true,
        "rls_enabled": true,
        "table_owner": "postgres",
        "can_change_org": false,
        "can_change_membership": false
      }
    },
    {
      "case": "request role: partner_b",
      "http_status": 200,
      "observed": {
        "db_role": "authenticated",
        "subject": "20000000-0000-0000-0000-000000000002",
        "bypassrls": false,
        "superuser": false,
        "rls_active": true,
        "rls_forced": true,
        "rls_enabled": true,
        "table_owner": "postgres",
        "can_change_org": false,
        "can_change_membership": false
      }
    },
    {
      "case": "visible contacts: employee_a",
      "http_status": 200,
      "observed": [
        {
          "id": "a1"
        },
        {
          "id": "a2"
        }
      ]
    },
    {
      "case": "visible contacts: partner_a",
      "http_status": 200,
      "observed": [
        {
          "id": "a1"
        }
      ]
    },
    {
      "case": "visible contacts: employee_b",
      "http_status": 200,
      "observed": [
        {
          "id": "b1"
        }
      ]
    },
    {
      "case": "visible contacts: partner_b",
      "http_status": 200,
      "observed": [
        {
          "id": "b1"
        }
      ]
    },
    {
      "case": "visible contacts: outsider",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "anonymous read denied by grants",
      "http_status": 401,
      "observed": {
        "code": "42501",
        "details": null,
        "hint": null,
        "message": "permission denied for table contacts"
      }
    },
    {
      "case": "invalid signature denied",
      "http_status": 401,
      "observed": {
        "code": "PGRST301",
        "details": "None of the keys was able to decode the JWT",
        "hint": null,
        "message": "No suitable key or wrong key type"
      }
    },
    {
      "case": "expired JWT denied",
      "http_status": 401,
      "observed": {
        "code": "PGRST303",
        "details": null,
        "hint": null,
        "message": "JWT expired"
      }
    },
    {
      "case": "privileged role cannot be assumed",
      "http_status": 403,
      "observed": {
        "code": "42501",
        "details": null,
        "hint": null,
        "message": "permission denied to set role \"postgres\""
      }
    },
    {
      "case": "foreign organization read filtered",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "unassigned same-org contact filtered",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "organization header grants no rights",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "user metadata grants no employee role",
      "http_status": 200,
      "observed": [
        {
          "id": "a1"
        }
      ]
    },
    {
      "case": "private schema is not exposed",
      "http_status": 406,
      "observed": {
        "code": "PGRST106",
        "details": null,
        "hint": "Only the following schemas are exposed: api",
        "message": "Invalid schema: private"
      }
    },
    {
      "case": "employee update allowed",
      "http_status": 200,
      "observed": [
        {
          "id": "a1",
          "name": "Alpha updated"
        }
      ]
    },
    {
      "case": "employee update persisted",
      "http_status": 200,
      "observed": [
        {
          "name": "Alpha updated"
        }
      ]
    },
    {
      "case": "partner update filtered",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "partner update left state unchanged",
      "http_status": 200,
      "observed": [
        {
          "name": "Alpha updated"
        }
      ]
    },
    {
      "case": "cross-org update filtered",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "cross-org update left state unchanged",
      "http_status": 200,
      "observed": [
        {
          "name": "Beta assigned"
        }
      ]
    },
    {
      "case": "anonymous insert denied",
      "http_status": 401,
      "observed": {
        "code": "42501",
        "details": null,
        "hint": null,
        "message": "permission denied for table contacts"
      }
    },
    {
      "case": "partner insert denied",
      "http_status": 403,
      "observed": {
        "code": "42501",
        "details": null,
        "hint": null,
        "message": "new row violates row-level security policy for table \"contacts\""
      }
    },
    {
      "case": "cross-org insert denied",
      "http_status": 403,
      "observed": {
        "code": "42501",
        "details": null,
        "hint": null,
        "message": "new row violates row-level security policy for table \"contacts\""
      }
    },
    {
      "case": "denied inserts absent: employee_a",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "denied inserts absent: employee_b",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "own-org insert allowed",
      "http_status": 201,
      "observed": [
        {
          "id": "a3"
        }
      ]
    },
    {
      "case": "own-org insert persisted",
      "http_status": 200,
      "observed": [
        {
          "name": "Alpha new"
        }
      ]
    },
    {
      "case": "tenant reassignment denied by column grant",
      "http_status": 403,
      "observed": {
        "code": "42501",
        "details": null,
        "hint": null,
        "message": "permission denied for table contacts"
      }
    },
    {
      "case": "partner reassignment denied by column grant",
      "http_status": 403,
      "observed": {
        "code": "42501",
        "details": null,
        "hint": null,
        "message": "permission denied for table contacts"
      }
    },
    {
      "case": "tenant unchanged after reassignment attempt",
      "http_status": 200,
      "observed": [
        {
          "org_id": "a0000000-0000-0000-0000-000000000001",
          "partner_id": "10000000-0000-0000-0000-000000000002"
        }
      ]
    },
    {
      "case": "partner delete filtered",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "partner delete left contact present",
      "http_status": 200,
      "observed": [
        {
          "id": "a1"
        }
      ]
    },
    {
      "case": "cross-org delete filtered",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "cross-org delete left contact present",
      "http_status": 200,
      "observed": [
        {
          "id": "b1"
        }
      ]
    },
    {
      "case": "own-org delete allowed",
      "http_status": 200,
      "observed": [
        {
          "id": "a3"
        }
      ]
    },
    {
      "case": "own-org delete persisted",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "withdrawn membership hides rows with unchanged JWT",
      "http_status": 200,
      "observed": []
    },
    {
      "case": "employee still reads after partner withdrawal",
      "http_status": 200,
      "observed": [
        {
          "id": "a1"
        },
        {
          "id": "a2"
        }
      ]
    }
  ]
}
