-- Idempotent demo seed + the cross-entity Admin/Ops bypass policy. -- Both belong to the *shared* layer rather than to any one app: -- * The seed primes the shared database so either the storefront or the -- admin app shows something on first boot. -- * The bypass policy applies across every type, so it has to live where -- every app can see it. -- Runs once when the shared `wo db serve` daemon comes up — each app connects -- over the wire and inherits the already-seeded state. policy admin-ops-bypass applies_to: Order, Product, Customer, Purchase when: $session.role == Admin or $session.role == Ops effect: skip-row-filters on startup do: seed() fn seed() { if count(Customer{ email == "admin@shop.test" }) == 0 { insert Customer { email: "admin@shop.test", name: "Ops Admin", role: Admin }; } if count(Product{ sku == "SKU-WIDGET" }) == 0 { insert Product { sku: "SKU-WIDGET", name: "Widget", price: 1999, meta: { description: "A classic widget.", images: ["/static/widget.jpg"], attributes: { colour: "blue", size: "M", material: "steel" } }, inventory: { on_hand: 50, reserved: 0, reorder_at: 10 } }; insert Product { sku: "SKU-GIZMO", name: "Gizmo", price: 4999, meta: { description: "A premium gizmo.", images: ["/static/gizmo.jpg"], attributes: { colour: "black", size: "L", material: "aluminium" } }, inventory: { on_hand: 12, reserved: 0, reorder_at: 3 } }; } }