Setup() registers one transient consumer per routing key, and each mints its
own queue drained by its own goroutine, so User.Added and Privilege.Added for the
same company can be processed in either order. Process(*UserAdded) replaced the
company entry with empty privileges, so a Privilege.Added handled first lost its
privilege until the next Fetch(), which only runs at service start.
Create the entry only when it is missing instead, matching authz-service's own
aggregate and read view, which both leave an existing user entry alone. This also
makes a User.Added redelivery harmless.
Seen as authz-service #826 acceptance-test failures: a new company's Admin grant
vanished, so company-service's CreateCompany callback waited out its 30s timeout
and the company page stayed empty.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XMvdB7bcwn1CrQKM4dCshM
## Summary
- Add `WithAPIKey(key string)` option to `PrivilegeHandler`
- When set, `Fetch()` sends `Authorization: Bearer <key>` header
- Backward compatible: no key = no header (existing behavior)
## Test plan
- [x] Unit test verifying Authorization header is sent
- [x] Unit test verifying no header without key
- [x] Existing tests still pass
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Reviewed-on: https://gitea.unbound.se/shiny/authz_client/pulls/294
Replace read lock with write lock in client.go to ensure thread
safety during the unmarshalling of JSON data. This prevents
concurrent read access and potential data races, improving
the integrity of the privileges data structure.
Add support for the salary privilege in the privilege handler.
Implement associated logic to process and validate the
salary privilege in the test cases. Update the data
structures to include the new privilege and ensure
correct functionality in the privilege processing flow.
Adds a Setup method to PrivilegeHandler that configures AMQP consumers
for user and privilege events. This enables the handling of User.Added,
User.Removed, Privilege.Added, and Privilege.Removed events in a
streamlined manner, enhancing the event-driven capabilities of the
handler.