Files
authz_client/CLAUDE.md
T
argoyle 6bdf6e1cd3
Unbound Release / Create Tag (push) Skipped
Unbound Release / Check Preconditions (push) Successful in 29s
authz_client / vulnerabilities (push) Skipped
authz_client / test (push) Skipped
pre-commit / pre-commit (push) Successful in 2m36s
Unbound Release / Create Release (push) Successful in 40s
Unbound Release / Generate Changelog and Handle PR (push) Successful in 37s
Release / release (push) Successful in 2m24s
feat!: consume privilege events with go-messaging-amqp (#327)
2026-09-11 21:00:41 +00:00

1.5 KiB

authz_client

Shared Go library for authorization service client integration.

Shared Documentation

@../docs/claude/architecture.md @../docs/claude/go-services.md @../docs/claude/conventions.md

Library Information

Purpose

Provides a client for the authz-service, handling privilege management for users across companies. Used by all microservices that need to check user permissions.

Usage

import client "gitea.unbound.se/shiny/authz_client"

// Create handler with options
handler := client.New(client.WithBaseURL("http://authz-service"))

// Check user privileges
privileges := handler.Get(email, companyID)
if privileges.Invoicing {
    // User has invoicing privileges
}

Privileges

The CompanyPrivileges struct contains permission flags:

  • Admin - Administrative access
  • Company - Company management
  • Consumer - Consumer/customer access
  • Time - Time tracking
  • Invoicing - Invoice management
  • Accounting - Accounting access
  • Supplier - Supplier management
  • Salary - Salary/payroll access

Event Handling

Registers per-replica (transient) go-messaging-amqp consumers for privilege update events from the authz-service (Setup()), keeping the local privilege cache up-to-date. Don't combine Setup() with go-messaging-amqp's WithReconnect: a reconnect declares new per-replica queues, so revocations published during the outage are lost unless Fetch() runs again. Services exit on connection loss (CloseListener) and re-fetch on start.