The four privilege keys arrive on separate transient queues, so a late
Privilege.Added or User.Added could resurrect a revoked grant. Services also
fetched /authz before binding their queues, losing revocations published in
between.
Process now orders events by authz-service's global sequenceNo per
(email, company): an event only overrides older facts, User.Removed stamps
every privilege, and events without a sequence number fail closed (additions
dropped, removals held until the next snapshot). Fetch checks the status,
retries 503 while authz-service's read view is behind, reads the
X-Authz-Sequence header and merges the snapshot as facts at that position,
ignoring snapshots older than one already merged. CompaniesByUser returns []
instead of nil.
BREAKING CHANGE: events without SequenceNo no longer grant anything; tests that
seed the handler through Process must set SequenceNo. Call Fetch() after
conn.Start (ADR-0015).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DVGsVQ8AMFR4NZoxyCoEqS
## Summary
- Add `WithAPIKey(key string)` option to `PrivilegeHandler`
- When set, `Fetch()` sends `Authorization: Bearer <key>` header
- Backward compatible: no key = no header (existing behavior)
## Test plan
- [x] Unit test verifying Authorization header is sent
- [x] Unit test verifying no header without key
- [x] Existing tests still pass
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Reviewed-on: https://gitea.unbound.se/shiny/authz_client/pulls/294
Replace read lock with write lock in client.go to ensure thread
safety during the unmarshalling of JSON data. This prevents
concurrent read access and potential data races, improving
the integrity of the privileges data structure.
Add support for the salary privilege in the privilege handler.
Implement associated logic to process and validate the
salary privilege in the test cases. Update the data
structures to include the new privilege and ensure
correct functionality in the privilege processing flow.
Adds a Setup method to PrivilegeHandler that configures AMQP consumers
for user and privilege events. This enables the handling of User.Added,
User.Removed, Privilege.Added, and Privilege.Removed events in a
streamlined manner, enhancing the event-driven capabilities of the
handler.