Commit Graph
6 Commits
Author SHA1 Message Date
argoyleandClaude Opus 5 84e9309901 fix!: order privilege events by sequence number and merge snapshots by position
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
pre-commit / pre-commit (pull_request) Successful in 3m47s
authz_client / vulnerabilities (pull_request) Successful in 1m0s
authz_client / test (pull_request) Successful in 1m10s
The four privilege keys arrive on separate transient queues, so a late
Privilege.Added or User.Added could resurrect a revoked grant. Services also
fetched /authz before binding their queues, losing revocations published in
between.

Process now orders events by authz-service's global sequenceNo per
(email, company): an event only overrides older facts, User.Removed stamps
every privilege, and events without a sequence number fail closed (additions
dropped, removals held until the next snapshot). Fetch checks the status,
retries 503 while authz-service's read view is behind, reads the
X-Authz-Sequence header and merges the snapshot as facts at that position,
ignoring snapshots older than one already merged. CompaniesByUser returns []
instead of nil.

BREAKING CHANGE: events without SequenceNo no longer grant anything; tests that
seed the handler through Process must set SequenceNo. Call Fetch() after
conn.Start (ADR-0015).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DVGsVQ8AMFR4NZoxyCoEqS
2026-09-16 20:27:28 +02:00
argoyle 01f30cfd2b fix: keep existing privileges when User.Added is processed late (#331)
authz_client / test (push) Successful in 58s
Unbound Release / Check Preconditions (push) Successful in 22s
Unbound Release / Create Tag (push) Skipped
authz_client / vulnerabilities (push) Successful in 47s
Unbound Release / Generate Changelog and Handle PR (push) Successful in 32s
Unbound Release / Create Release (push) Successful in 24s
Release / release (push) Successful in 58s
pre-commit / pre-commit (push) Successful in 2m17s
2026-09-16 05:19:03 +00:00
argoyle 6bdf6e1cd3 feat!: consume privilege events with go-messaging-amqp (#327)
Unbound Release / Create Tag (push) Skipped
Unbound Release / Check Preconditions (push) Successful in 29s
authz_client / vulnerabilities (push) Skipped
authz_client / test (push) Skipped
pre-commit / pre-commit (push) Successful in 2m36s
Unbound Release / Create Release (push) Successful in 40s
Unbound Release / Generate Changelog and Handle PR (push) Successful in 37s
Release / release (push) Successful in 2m24s
2026-09-11 21:00:41 +00:00
argoyle 60d9eea9c9 chore: migrate module path to gitea.unbound.se
authz_client / test (pull_request) Successful in 1m56s
authz_client / vulnerabilities (pull_request) Successful in 2m31s
pre-commit / pre-commit (pull_request) Successful in 5m21s
Update module path from git.unbound.se to gitea.unbound.se for Go module
discovery over HTTPS.
2026-01-09 14:30:26 +01:00
argoyle 681afe2626 refactor: update module path to new repository location
authz_client / test (pull_request) Successful in 3m25s
authz_client / vulnerabilities (pull_request) Successful in 3m42s
Remove GitLab CI linter configuration and update module path from 
`gitlab.com/unboundsoftware/shiny/authz_client` to 
`git.unbound.se/shiny/authz_client` in all relevant files. 
These changes reflect a migration to a new hosting service.
2026-01-09 09:28:16 +01:00
argoyle 1fd3ae5123 docs: add CLAUDE.md for Claude Code integration 2025-12-31 22:06:51 +01:00