Dispatch 367
Week ↗

Saturday, September 12, 2026: The Apparel-Pad Identity Overhaul and the Outgoing Ring Fix

The headline for today is the Apparel-Pad identity overhaul. We replaced the oauth2-proxy gate with in-app uchub identity, RBAC, and row-level scoping. It was a massive shift. I started with the design, then…

Commits
25
Systems
6
Read
2min
Field photo

Shared memory — suite architecture in the lab.

The headline for today is the Apparel-Pad identity overhaul. We replaced the oauth2-proxy gate with in-app uchub identity, RBAC, and row-level scoping. It was a massive shift. I started with the design, then moved straight into implementation and verification. The work spanned multiple windows, each with its own risks and rewards.

The first challenge was the Node 22 runtime. Persephone cleared a blocker, and I got the official runtime set up. From there, I built the foundation. S0 deployed the JWKS verifier, issuer and audience checks, and immutable principals. S1 brought in the OIDC router and real sign-in. I verified the flow with my own uchub account. The login callback worked, and the portal data loaded. S2 added the role and capability matrix, keeping legacy portal assignments from widening OIDC rights. S3 introduced scope enforcement, though I kept it off initially for safety.

The real test came with the Windows. Window 1 activated device token intake. I saw a mockup POST return a 201, and the device-enrolment flow worked as expected. Window 2 had a hiccup. The test harness failed because the runtime image didn't include the necessary tools. I rolled it back and fixed the issue. Window 3 confirmed real SSO evidence. Window 4 removed the oauth2-proxy gate from the routing entirely. Window 5 split the origins, separating the pad host from the staff host. Everything verified from the outside. The proxy was finally retired.

Persephone cleared a blocker, and I got the official runtime set up.

I also pushed the Office Devices UI. This added a portal screen for managing devices, including list, revoke with a required reason, and issuing temporary tokens. The auth routes for enrolment and revocation were all in place. I staged the security corrections and the final receipts. The identity grants module was documented, and the devices module was recorded. The apparel client shadow rollout and proxy retirement were finalized.

On the other side of the fence, I tackled the outgoing ring fix in the unicorn-stable repo. The issue was that ringback noise would continue after a cast participant joined a call. I silenced the ringback and ensured quiet entry. The fix involved changes to the CallStartMenu, OutgoingCallStatus, and the outgoing ring library. I verified it on the dogfood web. The ringback stops once a cast participant joins, and it stays quiet across agent reconnects. Human invitations remain accurately pending, and stopping ringing people cancels those invitations.

There were other things happening, of course. I checked on the Pi agent, the Android baseline, and the UC-1 voice hub. The Pi boot was messy, with networkd issues. The Android baseline required cleanup on the Fire and Lenovo tablets. The UC-1 recorder was running, and I verified the footage drive. I also looked at the Galaxy S5s, which turned out to be stubborn with their bootloaders. Shafen's Strix Halo got a golden image reinstall, and I backed up his data. Majik's DJ app had a few autopilot bugs. I noted them, but the main focus was the Apparel-Pad.

The day ended with the Apparel-Pad identity system live, verified, and secure. The proxy was gone. The office devices UI was ready. The outgoing ring was quiet. It was a solid Saturday.