A tenant command API links verified identity, authorization, versioned storage, replay and an outbox in one request path.
Spring Boot tenant command API project: assemble the local write path
The assembled fixture
The downloadable source kit now has one local web context that receives a signed tenant token, checks issuer, audience, expiry and tenant_id, requires receipt.write, applies a managed service owner rule, performs a versioned H2 update and commits the outbox and replay rows together. It verifies an accepted write, a replay, two key conflicts, stale version, cross-tenant denial, wrong scope, missing claim and rollback after event insertion. This closes the local composition gap between earlier isolated fixtures.
This test configuration is not the runnable ReceiptApplication. That application still uses local Basic credentials and in-memory receipts. The migration plan explains the identity swap; the delivery plan covers worker work not assembled here.
Release gates remain concrete
Move the schema into versioned migrations and run the same tests against the target database. Force concurrent first requests with the same key, prove the unique-key conflict path, then add a relay and idempotent consumer. Check crash/restart cases, issuer rotation, unknown tenant membership, load and deployed gateway behavior. Do not publish the local signing key or fixture credentials. The point of the current source kit is to let a reader inspect exact boundaries, not to supply a production service.
Checked source
// Local checked flow: bearer -> scope -> owner -> versioned JDBC -> outbox + replay.
// Production work: real issuer, migrations, target DB, relay, consumer, recovery.
int responseVersion = managedService.change(
trustedTenant, receiptId, requestKey, command, false);Verification boundary
TenantReceiptCommandFlowTest runs eight local contract tests for the combined command path in the downloadable Spring source kit. The excerpt is shortened; the kit contains the complete test.
Costs and limits
No real identity provider, membership registry, deployment gateway, external broker, target database, concurrent request race or process crash is in this fixture. Transaction and JWT costs must be measured under the intended workload before capacity decisions.
Common Mistakes
- Do not deploy test-generated RSA keys.
- Do not call the runnable Basic-auth app tenant-aware because this separate test exists.
- Do not claim a committed outbox row was delivered.
Read next
Spring tenant command transaction: keep state, event and replay record together, Spring Boot receipt API: move from local Basic auth to tenant-scoped tokens, Spring receipt outbox command: record intent without claiming delivery, Spring Boot receipt delivery project: add a recoverable worker contract.
Continue with checked relay behavior
Continue with Spring project: turn the local outbox model into a measured relay.
Continue with checked settings and schema rollout
Continue with Spring database contract phase: reject old writers only after backfill.
