Screen every advertiser destination against Google Safe Browsing

Google marked instantadpay.com "deceptive pages" on 24 September. The probable
cause was campaign #225: a verified-visits ad that opened llclickpro.com from
our pages, and llclickpro.com carries exactly that flag. We put other people's
destinations in front of members, so their reputation becomes ours, and
nothing was checking it.

sbcheck.js screens the destination when a campaign is saved (member and house
paths both) and re-screens every live campaign daily, pausing the ones on a
flagged host and alerting the admin channel with the campaigns and owners.
POST /api/admin/sbcheck {dry} runs a pass by hand.

Verdicts are three-valued on purpose: flagged, clean, unknown. A guard that
reads "could not check" as "clean" is the failure mode this whole day has been
about; one that reads it as "flagged" would refuse every advertiser whenever
Google rate-limits us. So flagged refuses and pauses, clean passes, unknown
passes at save time but is logged and retried by the sweep until it resolves.

Uses the official Lookup API v4 when SAFE_BROWSING_KEY is set (full-URL,
batched). Until a key exists it reads the Transparency Report site-status
record, decoded against Google's own test site rather than guessed:
status 1 is clean, status 3 with any true flag is listed, anything else is
no data. That endpoint rate-limits by answering HTML, hence the 4-second pace.

videosweep's inline alert is hoisted into videosweepAlert so both sweeps use
the same admin-only channel: these messages name members and their emails.

QA: member walk 0 bugs, public walk 0 bugs. Verified by hand that
llclickpro.com is refused, rmcircle.team passes, and our own host is skipped.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
martbost
2026-09-24 19:38:35 -05:00
parent f2a999edd0
commit 1b72a9a18c
2 changed files with 3629 additions and 3431 deletions
+3445 -3431
View File
File diff suppressed because it is too large Load Diff