61122ce437
Issue #11 asks for a tenant column so a multi-tenant caller can isolate rows in the database. Widened to caller-defined dimensions in general, but only the caller's own: model name and friends keep their existing columns, and the library writes nothing into the new container. Two independent findings force tenant_id to be a real column rather than a key inside JSON. An RLS policy on meta->>'tenant_id' parses fine, but the planner discards statistics for non-LEAKPROOF functions under RLS, and ->> is not marked leakproof; the pgsql-general report that hit this ended up moving the indexed column out of JSONB. Separately, the planner has no usable statistics for JSONB at all -- @> falls back to a hardcoded 0.1% selectivity. A configurable promoted-column whitelist is rejected: when two downstreams infer different types for the same key, the second ADD COLUMN is silently skipped by IF NOT EXISTS and the wrong type is written from then on, without an error. The library stops at the column plus a documented policy template. It must never enable RLS itself -- with no matching policy that is default-deny, which would silently fail every write for the two downstreams that are not multi-tenant.