Sunday means the stack gets polished while the rest of the world sleeps. I spent the day tightening the screws on Prospector and pushing the medical engine in glitter-mane forward. It was a day of closing doors and opening windows.
The biggest story is Prospector. I spent a good chunk of time making it actually safe to run in the wild. I ran an IDOR sweep, adding object-level authorization to every data endpoint. If you aren't the owner, you aren't seeing the data. That’s non-negotiable. I also disabled the Swagger docs and OpenAPI specs in production. There’s no reason for an attacker to have your API map, so I turned it off by default with a flag just in case I need it back.
Security isn’t just about access; it’s about hygiene. I bumped python-jose to 3.4.0 to squash those JWT bomb and algorithm confusion CVEs. I also added a health check to /livez and tightened up the Docker setup. On the reliability side, I configured Celery to ack late, added idempotency checks, and built a stuck-job reaper. If a task hangs, it dies. No more zombie workers eating up resources. I also capped upload sizes to keep the ingestion pipeline from choking on someone’s weird file.
I spent a good chunk of time making it actually safe to run in the wild.
Metering got a serious upgrade too. I implemented atomic pre-spend reservations with a per-tenant monthly cap. If you hit your limit, the system fails closed. It’s annoying for users who hit the wall, but it’s better than overcharging or breaking the bank. I also added per-tenant rate limiting and an admin-grant email verification gate. The frontend got a rebrand to Prospector with dark mode, toasts, and better accessibility. It looks cleaner and feels more responsive.
In glitter-mane, the medical research engine got smarter. I added condition aliases and seed expansion, so the system understands more ways to talk about diseases. I also built optional Center Deep web research for Professor Lumen. It’s a new feature for honest research UX, letting the agent dig deeper when needed. The consult triage got smarter too, with better chart navigation and condition citations. I fixed a bug where the SSE stream would stall mid-panel on large charts, so the UI stays smooth even when the data gets heavy. I also added OCR sanitization at the boundary to keep the RAG text clean.
Valor-ops saw a few overnight polish commits. I added empty-state recovery CTAs, a readiness empties banner, and some deep links. It’s small stuff, but it makes the app feel more complete. I also optimized the list documents endpoint to skip loading OCR text blobs, which should speed things up a bit.
Also today: I deduped interactive uploads in uc-meeting-ops by audio SHA-256. If you upload the same file twice, it doesn’t count twice. Simple, effective.
The day added up to a more secure Prospector and a more intelligent medical engine. The stack is getting better, one commit at a time.
Real product captures — click any to enlarge.