Files
authz_client/CLAUDE.md
T
argoyleandClaude Opus 5 3750416d8d
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
feat!: consume privilege events with go-messaging-amqp
eventsourced and sloth moved to Codeberg, where their AMQP modules use codeberg.org/messaging/go-messaging-amqp instead of goamqp; services migrating to them need authz_client on the same client. Setup() now returns go-messaging-amqp setups: the same four per-replica (transient) consumers, with typed handlers that feed Process.

BREAKING CHANGE: Setup returns go-messaging-amqp setups, and Process(msg any) error replaces Process(msg, goamqp.Headers) (any, error). Services stay on v0.5.x until they migrate (see docs/design/codeberg-migration.md).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
2026-09-11 22:47:30 +02:00

47 lines
1.2 KiB
Markdown

# authz_client
Shared Go library for authorization service client integration.
## Shared Documentation
@../docs/claude/architecture.md
@../docs/claude/go-services.md
@../docs/claude/conventions.md
## Library Information
### Purpose
Provides a client for the authz-service, handling privilege management for users across companies. Used by all microservices that need to check user permissions.
### Usage
```go
import client "gitea.unbound.se/shiny/authz_client"
// Create handler with options
handler := client.New(client.WithBaseURL("http://authz-service"))
// Check user privileges
privileges := handler.Get(email, companyID)
if privileges.Invoicing {
// User has invoicing privileges
}
```
### Privileges
The `CompanyPrivileges` struct contains permission flags:
- `Admin` - Administrative access
- `Company` - Company management
- `Consumer` - Consumer/customer access
- `Time` - Time tracking
- `Invoicing` - Invoice management
- `Accounting` - Accounting access
- `Supplier` - Supplier management
- `Salary` - Salary/payroll access
### Event Handling
Registers per-replica (transient) go-messaging-amqp consumers for privilege update events from the authz-service (`Setup()`), keeping the local privilege cache up-to-date.