Skip to content

Leads: enter the sender postal address in the UI - #123

Merged
ralyodio merged 1 commit into
masterfrom
feat/leads-sender-address
Jul 26, 2026
Merged

ralyodio merged 1 commit into
masterfrom
feat/leads-sender-address

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Replaces the OUTREACH_POSTAL_ADDRESS env gate with an address you can type into the Leads page.

Three levels, most-specific-first: project → organization → account → env fallback.

  • Set the account address once; every project can pull it in with Import from account.
  • A project address overrides it — for sending on a client's behalf.
  • Org address sits between the two; only the org owner can change it.
  • Blank falls through to the next level (a " " footer passes a truthiness check and violates CAN-SPAM).

The auto_send guards and the MCP dry-run output now read the same resolved address, so the UI, the autopilot and the tools agree on when live sending is allowed.

Migration already applied to production (three nullable text columns).

633 tests pass (5 new, covering precedence), typecheck clean, build green.

🤖 Generated with Claude Code

CAN-SPAM requires a physical postal address in commercial email, and that
was gated on OUTREACH_POSTAL_ADDRESS. Wrong on two counts: changing it took
a redeploy, and one env var forces one address on every user — an agency
sending for three clients has three addresses to put in the footer.

Three levels now, resolved most-specific-first at send time:

  project       signs this client's outreach with this client's address
  organization  everything the org sends, unless a project overrides it
  account       the personal default, set once

Set the account one and every project is one click from being able to send
("Import from account"). A blank level falls through to the next rather than
being treated as an address — "   " passes a truthiness check and violates
the statute.

The env var survives as a last-resort fallback so existing deploys keep
working, but nothing needs it any more. The auto_send guards and the MCP
dry-run output read the resolved address instead of the env, so all three
now agree on when live sending is allowed.

Migration applied to production.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@ralyodio
ralyodio merged commit abf16ea into master Jul 26, 2026
6 checks passed
@ralyodio
ralyodio deleted the feat/leads-sender-address branch July 26, 2026 16:42
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant