fix: keep existing privileges when User.Added is processed late #331

Merged
argoyle merged 2 commits from fix/user-added-keeps-privileges into main 2026-09-16 05:19:05 +00:00
2 Commits
Author SHA1 Message Date
argoyleandClaude Opus 5 55e16832c1 chore(deps): bump go-messaging-amqp to v0.0.5 and amqp091-go to v1.15.0
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
authz_client / vulnerabilities (pull_request) Successful in 48s
authz_client / test (pull_request) Successful in 1m0s
pre-commit / pre-commit (pull_request) Successful in 2m15s
govulncheck reports GO-2026-6372 against amqp091-go v1.12.0, pulled in
indirectly: a broker-controlled oversized payload can exhaust memory. Fixed in
v1.13.0; take v1.15.0. The advisory fails CI on main too, and this is the first
build since it was published.

go-messaging-amqp goes to v0.0.5 at the same time, which is what every migrated
service already runs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XMvdB7bcwn1CrQKM4dCshM
2026-09-16 07:16:09 +02:00
argoyleandClaude Opus 5 92f78d369a fix: keep existing privileges when User.Added is processed late
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
authz_client / vulnerabilities (pull_request) Failing after 55s
authz_client / test (pull_request) Successful in 1m4s
pre-commit / pre-commit (pull_request) Successful in 2m16s
Setup() registers one transient consumer per routing key, and each mints its
own queue drained by its own goroutine, so User.Added and Privilege.Added for the
same company can be processed in either order. Process(*UserAdded) replaced the
company entry with empty privileges, so a Privilege.Added handled first lost its
privilege until the next Fetch(), which only runs at service start.

Create the entry only when it is missing instead, matching authz-service's own
aggregate and read view, which both leave an existing user entry alone. This also
makes a User.Added redelivery harmless.

Seen as authz-service #826 acceptance-test failures: a new company's Admin grant
vanished, so company-service's CreateCompany callback waited out its 30s timeout
and the company page stayed empty.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XMvdB7bcwn1CrQKM4dCshM
2026-09-16 07:03:54 +02:00