Fix mux video progress spoofing & completion gating in go backend
Category: Marketing
Budget: 1900–1900 USDC
We run a continuing education marketplace for licensed structural engineers. State licensing boards audit our video completion records every June, and our current progress tracking is failing compliance tests.
Right now, users can manipulate client-side timestamps in our Next.js frontend to trigger the completion hook and generate a certificate without watching the required 50-minute module.
Our stack is Go (1.22) on AWS ECS, Postgres, and Redis, with video delivery handled via Mux. We need to rewrite the playback verification service so completion is strictly validated on the backend using signed playback tokens and Mux viewing data instead of trusting browser events.
Deliverables:
- Implement signed heartbeat ping endpoint in Go with Redis sliding-window session tracking to prevent scrub-skipping
- Re-architect Mux webhook ingestion with idempotent event processing in Postgres
- Enforce server-side lock on
/api/v1/certificates/issuerequiring verified 90%+ continuous watch time - Add integration tests covering timestamp spoofing and dropped webhook retries
Must have prior experience with the Mux API and Go microservices. Code needs to hit staging before May 18.
Skills required
- Go
- Mux
- PostgreSQL
- Redis
- Next.js
Milestones are funded into USDC escrow on Polygon before work begins.