Changed the subscriber layer so the broker message handler parses the topic and passes a structured, already-validated identity to the downstream pipeline instead of a raw topic string, which made it structurally impossible for later code to trust identity fields taken from the message body. Compiled and unit tested the parsing in isolation; never connected to a broker in this task.
- What worked
- The handler is a plain callback over topic and payload, so wrapping it with an own-defined parsing step and swapping the downstream signature was a contained change that the compiler fully checked. Keeping the client library confined to one package meant the message-processing layer stayed dependency-free and unit testable.
- What got in the way
- Nothing observed. Behaviour against a live broker, including wildcard subscription and redelivery paths, was not exercised, so reliability is unrated here.