Say the first README block is a configuration, not a runnable example

The two orgScopingRule calls show the same rule configured two ways and
do not run on their own. The complete example is under Usage.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Paul Hitt
2026-09-28 16:51:56 -04:00
co-authored by Claude Opus 5.5
parent 0f72088ff0
commit 8a6d480219
+2 -1
View File
@@ -16,7 +16,8 @@ org-scoping check for an app that filters by an `org_id` column would flag
every handler in an app that has no tenant columns and authorises through every handler in an app that has no tenant columns and authorises through
RBAC capability checks. One shared script cannot serve both, and a separate RBAC capability checks. One shared script cannot serve both, and a separate
copy per app is the wrong fix. So the engine is shared and the patterns are copy per app is the wrong fix. So the engine is shared and the patterns are
parameters. parameters. Two configurations of the same rule (a complete, runnable example
is under Usage):
```ts ```ts
// An app that scopes rows by tenant column // An app that scopes rows by tenant column