Dispatch 271
Week ↗

RLS hardening, auctions, and the legal stack

Monday started with a deep dive into the contact-ops security posture. I spent the bulk of the morning on the RLS rewrite, specifically Phase 4.0 through 4.3. This wasn't just a tweak; it was a foundation la…

Commits
18
Systems
5
Read
2min
Product capture

Listing-Ops — assistant.

Monday started with a deep dive into the contact-ops security posture. I spent the bulk of the morning on the RLS rewrite, specifically Phase 4.0 through 4.3. This wasn't just a tweak; it was a foundation layer. I built out the schema for isolation modes and user-tenant memberships (Phases 4.1), then immediately followed up with a security hotfix that applied RLS to six previously unprotected tenant-scoped tables (Phase 4.0b). The goal was strict isolation, so I wrote an adversarial test suite to verify that the new isolation-aware RLS actually holds up under pressure. I also added a Keycloak script to automate the switch-client ops (for the MCP set-point feature), which should save us some manual headaches down the road. The membership gate logic is now in place, and the database predicates are live (Phase 4.3).

In listing-ops, the auction feature finally got some love. I implemented the backend support for the AUCTION listing format, which involved updating the core models, the agent toolset, and the eBay listing publisher. The frontend didn't lag behind; I built the in-app auction UI, which includes the format selector and controls for starting, reserving, and setting duration. It feels good to see the auction flow taking shape from the database schema up to the user interface. I also fixed a minor annoyance with multi-photo uploads to ensure monotonic ordering and a single cover image, so the listing details look clean.

The uc-meeting-ops repo saw a significant push for v3.22.5. The big win here is the stuck-state recovery for the AlwaysOn recording feature. I rewrote the session watchdog logic to handle cases where the recording gets stuck, adding over 400 lines of robust error handling (stuck-state recovery). Alongside that, I rolled out annual Pro pricing and a Founding 100 coming soon page. The billing integration is now live with the new Stripe price IDs. I also spent a good chunk of time on the legal side of things, adding Terms, Privacy, and AUP pages to the frontend. It is a lot of boilerplate, but it is necessary boilerplate. I updated the changelog and the docker-compose files to pass the new environment variables, ensuring the billing and watchdog features are active in the containers.

I implemented the backend support for the AUCTION listing format, which involved updating the core models, the agent toolset, and the eBay listing publisher.

On the infrastructure side, I worked on the unicorn-brigade configuration. I added a BRIGADE_FEDERATION_ONLY flag to enforce a customer-facing production posture. This helps us keep the development and production environments distinct and secure. I also updated the federation spec documentation to clarify the dev/prod tier separation and feature-flag posture. It is a small change, but it helps keep the architecture clear as we scale.

Also today: I resolved a classification gate in the accounting-ops docs to clarify that David is a contractor, not an employee. A small administrative win that keeps our records straight.

The day added up to a lot of foundational work. We hardened the security layer, launched the auction feature, and got the legal and billing pieces in place for the next release. It was a solid Monday.

Also in the frame

Real product captures — click any to enlarge.

brigade
listing ops
brigade