Files
authz_client/CLAUDE.md
T
argoyleandClaude Opus 5 fc0a4a0e31
authz_client / test (push) Skipped
authz_client / vulnerabilities (push) Skipped
pre-commit / pre-commit (push) Skipped
authz_client / vulnerabilities (pull_request) Successful in 46s
authz_client / test (pull_request) Successful in 59s
pre-commit / pre-commit (pull_request) Successful in 2m39s
test: assert which event type each privilege routing key decodes to
Swapping the handler for Privilege.Removed to PrivilegeAdded passed the suite, and would turn every revocation into a grant. The Setup test now asserts each key's message type, the adapter is exercised for all four events (grant then revoke), and process only accepts the four privilege event types. CLAUDE.md warns against combining Setup() with WithReconnect (per-replica queues are re-created on reconnect, losing revocations sent meanwhile).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SV1epy2pKvBx3yDfhxATk2
2026-09-11 22:57:25 +02:00

1.5 KiB

authz_client

Shared Go library for authorization service client integration.

Shared Documentation

@../docs/claude/architecture.md @../docs/claude/go-services.md @../docs/claude/conventions.md

Library Information

Purpose

Provides a client for the authz-service, handling privilege management for users across companies. Used by all microservices that need to check user permissions.

Usage

import client "gitea.unbound.se/shiny/authz_client"

// Create handler with options
handler := client.New(client.WithBaseURL("http://authz-service"))

// Check user privileges
privileges := handler.Get(email, companyID)
if privileges.Invoicing {
    // User has invoicing privileges
}

Privileges

The CompanyPrivileges struct contains permission flags:

  • Admin - Administrative access
  • Company - Company management
  • Consumer - Consumer/customer access
  • Time - Time tracking
  • Invoicing - Invoice management
  • Accounting - Accounting access
  • Supplier - Supplier management
  • Salary - Salary/payroll access

Event Handling

Registers per-replica (transient) go-messaging-amqp consumers for privilege update events from the authz-service (Setup()), keeping the local privilege cache up-to-date. Don't combine Setup() with go-messaging-amqp's WithReconnect: a reconnect declares new per-replica queues, so revocations published during the outage are lost unless Fetch() runs again. Services exit on connection loss (CloseListener) and re-fetch on start.