Ports the privilege-cache consumers to codeberg.org/messaging/go-messaging-amqp, the AMQP client the Codeberg eventsourced modules use (see docs/design/codeberg-migration.md). Setup() returns the same four per-replica (transient) consumers — User.Added, User.Removed, Privilege.Added, Privilege.Removed — with typed handlers feeding Process.
Breaking (releases as v0.6.0): Setup() returns go-messaging-amqp setups, and Process(msg any) error replaces Process(msg, goamqp.Headers) (any, error). Services stay on v0.5.x until they migrate; their tests that seed privileges via Process need the one-argument call.
Review
Security Expert review: behaviour-preserving — same structs decoded with encoding/json, same ack/drop outcomes, every replica still receives every event (random per-replica queue names), cache race-clean. Its one High was a test gap: wiring Privilege.Removed to the PrivilegeAdded handler passed the suite (every revocation would become a grant). Fixed: the Setup test asserts each key's message type (that mutant now fails), the adapter is exercised for all four events, and process is constrained to the four event types. Documented: don't combine Setup() with WithReconnect (reconnect re-creates per-replica queues, losing revocations sent meanwhile). Deferred to Ambix: the 1 s x-expires on transient queues racing a slow Start (library), no ordering across keys (pre-existing), and payload validation hardening (empty email/company, pre-existing).
## Summary
Ports the privilege-cache consumers to `codeberg.org/messaging/go-messaging-amqp`, the AMQP client the Codeberg `eventsourced` modules use (see `docs/design/codeberg-migration.md`). `Setup()` returns the same four per-replica (transient) consumers — `User.Added`, `User.Removed`, `Privilege.Added`, `Privilege.Removed` — with typed handlers feeding `Process`.
**Breaking** (releases as v0.6.0): `Setup()` returns go-messaging-amqp setups, and `Process(msg any) error` replaces `Process(msg, goamqp.Headers) (any, error)`. Services stay on v0.5.x until they migrate; their tests that seed privileges via `Process` need the one-argument call.
## Review
Security Expert review: behaviour-preserving — same structs decoded with `encoding/json`, same ack/drop outcomes, every replica still receives every event (random per-replica queue names), cache race-clean. Its one High was a test gap: wiring `Privilege.Removed` to the `PrivilegeAdded` handler passed the suite (every revocation would become a grant). Fixed: the Setup test asserts each key's message type (that mutant now fails), the adapter is exercised for all four events, and `process` is constrained to the four event types. Documented: don't combine `Setup()` with `WithReconnect` (reconnect re-creates per-replica queues, losing revocations sent meanwhile). Deferred to Ambix: the 1 s `x-expires` on transient queues racing a slow `Start` (library), no ordering across keys (pre-existing), and payload validation hardening (empty email/company, pre-existing).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
eventsourced and sloth moved to Codeberg, where their AMQP modules use codeberg.org/messaging/go-messaging-amqp instead of goamqp; services migrating to them need authz_client on the same client. Setup() now returns go-messaging-amqp setups: the same four per-replica (transient) consumers, with typed handlers that feed Process.
BREAKING CHANGE: Setup returns go-messaging-amqp setups, and Process(msg any) error replaces Process(msg, goamqp.Headers) (any, error). Services stay on v0.5.x until they migrate (see docs/design/codeberg-migration.md).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
Swapping the handler for Privilege.Removed to PrivilegeAdded passed the suite, and would turn every revocation into a grant. The Setup test now asserts each key's message type, the adapter is exercised for all four events (grant then revoke), and process only accepts the four privilege event types. CLAUDE.md warns against combining Setup() with WithReconnect (per-replica queues are re-created on reconnect, losing revocations sent meanwhile).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
argoyle
scheduled this pull request to auto merge when all checks succeed 2026-09-11 20:57:48 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Ports the privilege-cache consumers to
codeberg.org/messaging/go-messaging-amqp, the AMQP client the Codebergeventsourcedmodules use (seedocs/design/codeberg-migration.md).Setup()returns the same four per-replica (transient) consumers —User.Added,User.Removed,Privilege.Added,Privilege.Removed— with typed handlers feedingProcess.Breaking (releases as v0.6.0):
Setup()returns go-messaging-amqp setups, andProcess(msg any) errorreplacesProcess(msg, goamqp.Headers) (any, error). Services stay on v0.5.x until they migrate; their tests that seed privileges viaProcessneed the one-argument call.Review
Security Expert review: behaviour-preserving — same structs decoded with
encoding/json, same ack/drop outcomes, every replica still receives every event (random per-replica queue names), cache race-clean. Its one High was a test gap: wiringPrivilege.Removedto thePrivilegeAddedhandler passed the suite (every revocation would become a grant). Fixed: the Setup test asserts each key's message type (that mutant now fails), the adapter is exercised for all four events, andprocessis constrained to the four event types. Documented: don't combineSetup()withWithReconnect(reconnect re-creates per-replica queues, losing revocations sent meanwhile). Deferred to Ambix: the 1 sx-expireson transient queues racing a slowStart(library), no ordering across keys (pre-existing), and payload validation hardening (empty email/company, pre-existing).🤖 Generated with Claude Code
https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
Coverage Report
Total coverage: 98%