feat!: consume privilege events with go-messaging-amqp #327

Merged
argoyle merged 2 commits from feat/go-messaging-amqp into main 2026-09-11 21:00:43 +00:00
Owner

Summary

Ports the privilege-cache consumers to codeberg.org/messaging/go-messaging-amqp, the AMQP client the Codeberg eventsourced modules use (see docs/design/codeberg-migration.md). Setup() returns the same four per-replica (transient) consumers — User.Added, User.Removed, Privilege.Added, Privilege.Removed — with typed handlers feeding Process.

Breaking (releases as v0.6.0): Setup() returns go-messaging-amqp setups, and Process(msg any) error replaces Process(msg, goamqp.Headers) (any, error). Services stay on v0.5.x until they migrate; their tests that seed privileges via Process need the one-argument call.

Review

Security Expert review: behaviour-preserving — same structs decoded with encoding/json, same ack/drop outcomes, every replica still receives every event (random per-replica queue names), cache race-clean. Its one High was a test gap: wiring Privilege.Removed to the PrivilegeAdded handler passed the suite (every revocation would become a grant). Fixed: the Setup test asserts each key's message type (that mutant now fails), the adapter is exercised for all four events, and process is constrained to the four event types. Documented: don't combine Setup() with WithReconnect (reconnect re-creates per-replica queues, losing revocations sent meanwhile). Deferred to Ambix: the 1 s x-expires on transient queues racing a slow Start (library), no ordering across keys (pre-existing), and payload validation hardening (empty email/company, pre-existing).

🤖 Generated with Claude Code

https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2

## Summary Ports the privilege-cache consumers to `codeberg.org/messaging/go-messaging-amqp`, the AMQP client the Codeberg `eventsourced` modules use (see `docs/design/codeberg-migration.md`). `Setup()` returns the same four per-replica (transient) consumers — `User.Added`, `User.Removed`, `Privilege.Added`, `Privilege.Removed` — with typed handlers feeding `Process`. **Breaking** (releases as v0.6.0): `Setup()` returns go-messaging-amqp setups, and `Process(msg any) error` replaces `Process(msg, goamqp.Headers) (any, error)`. Services stay on v0.5.x until they migrate; their tests that seed privileges via `Process` need the one-argument call. ## Review Security Expert review: behaviour-preserving — same structs decoded with `encoding/json`, same ack/drop outcomes, every replica still receives every event (random per-replica queue names), cache race-clean. Its one High was a test gap: wiring `Privilege.Removed` to the `PrivilegeAdded` handler passed the suite (every revocation would become a grant). Fixed: the Setup test asserts each key's message type (that mutant now fails), the adapter is exercised for all four events, and `process` is constrained to the four event types. Documented: don't combine `Setup()` with `WithReconnect` (reconnect re-creates per-replica queues, losing revocations sent meanwhile). Deferred to Ambix: the 1 s `x-expires` on transient queues racing a slow `Start` (library), no ordering across keys (pre-existing), and payload validation hardening (empty email/company, pre-existing). 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
argoyle added 2 commits 2026-09-11 20:57:47 +00:00
feat!: consume privilege events with go-messaging-amqp
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
3750416d8d
eventsourced and sloth moved to Codeberg, where their AMQP modules use codeberg.org/messaging/go-messaging-amqp instead of goamqp; services migrating to them need authz_client on the same client. Setup() now returns go-messaging-amqp setups: the same four per-replica (transient) consumers, with typed handlers that feed Process.

BREAKING CHANGE: Setup returns go-messaging-amqp setups, and Process(msg any) error replaces Process(msg, goamqp.Headers) (any, error). Services stay on v0.5.x until they migrate (see docs/design/codeberg-migration.md).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
test: assert which event type each privilege routing key decodes to
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
authz_client / test (pull_request) Successful in 59s
authz_client / vulnerabilities (pull_request) Successful in 46s
pre-commit / pre-commit (pull_request) Successful in 2m39s
fc0a4a0e31
Swapping the handler for Privilege.Removed to PrivilegeAdded passed the suite, and would turn every revocation into a grant. The Setup test now asserts each key's message type, the adapter is exercised for all four events (grant then revoke), and process only accepts the four privilege event types. CLAUDE.md warns against combining Setup() with WithReconnect (per-replica queues are re-created on reconnect, losing revocations sent meanwhile).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
argoyle scheduled this pull request to auto merge when all checks succeed 2026-09-11 20:57:48 +00:00

Coverage Report

Total coverage: 98%

## Coverage Report Total coverage: **98%**
argoyle merged commit 6bdf6e1cd3 into main 2026-09-11 21:00:43 +00:00
argoyle deleted branch feat/go-messaging-amqp 2026-09-11 21:00:45 +00:00
Sign in to join this conversation.
No Reviewers
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: shiny/authz_client#327