Members were activating with sponsorId 0 (their own root) whenever their sponsor
couldn't be resolved — dead pre-wipe links (dkain) or no link at all — so their
purchases rolled to admin instead of building the tree. Default an unresolvable
sponsor to the configured catch position (siteConfig.defaultSponsorId, default
1) in both the buy path (/api/sponsor) and the free-activation path (/api/me),
guarded so #1 itself is never self-sponsored.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Trust's in-app browser was serving a cached pre-fix HTML page that pointed at
old JS, re-triggering the numeric-chainId crash even after the fix shipped.
Switch HTML from no-cache to no-store so every load fetches the current page and
its current asset versions. Versioned assets still cache for an hour.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
/api/sponsor (which the buy flow reads to set sponsorIdIfNew) resolved ONLY the
iap.sponsor cookie. A member whose join cookie was absent at buy time (different
device, cleared cookies, return visit) resolved to 0 and activated on-chain as
their own root instead of under their real sponsor — irreversible. Prefer the
logged-in account's stored sponsorRef, cookie only as anonymous fallback,
matching /api/me.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- notifyNewReferral (was nudgeReferrer): email a member's sponsor on EVERY new
referral, activated or not. Resolve the sponsor from the join token by member
id, share code, or username (was code-only and skipped already-activated
sponsors). Reworded from an activation nudge to a real "you have a new
referral" note; keeps the payouts reminder only for un-activated sponsors.
- Purchase event now also emails the buyer's direct sponsor that their referral
bought a package, noting whether it's a $20+ qualifying purchase.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- chain.js: derive the chain tip as the MAX height across the RPC pool and scan
getLogs against that same synced node. Load-balanced public RPCs (publicnode)
intermittently answer eth_blockNumber from a replica lagging thousands of
blocks behind, which stalled the mainnet scan (latest < lastBlock, 0 events)
and could skip freshly-mined events. This unblocks the live ledger + the
purchase-confirmation email (both driven by the event scan).
- disclaimer: replace the "rehearsal/testnet" section with a live-on-Polygon
real-money notice (it's live now).
- Point the dead Amoy fallbacks (purchase email tx link, contract-page source
link) at Polygon mainnet / the verified mainnet contract.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- wallet.js: fetch correct EIP-1559 fees from the network (Amoy/Polygon Bor
enforce a ~25-30 gwei priority floor MetaMask's estimate misses) via new
/api/gas; hard chain-guard before signing so a tx never lands on the wrong
network; accept the wallet's usual networks in AppKit so its modal stops
looping and drive add+switch ourselves.
- chain.js: suggestedFees() from eth_maxPriorityFeePerGas + base fee.
- Dashboard: move the Site links (Ad packages / Live ledger / The contract)
out of the sidebar into a page footer; hide the sidebar scrollbar.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- chain.rpc(): retry the RPC pool 3 rounds with backoff. Public Amoy nodes
routinely return transient "Temporary internal error. Please retry" on
eth_call; a single miss was silently surfacing as 0 credits / chainReadError
on the dashboard even when the buy succeeded on-chain.
- emailOnEvent: send a purchase confirmation on the Purchase event — credits
added, new ad-credit balance, POL paid, and a link to view the tx on the
explorer. Fires server-side for every wallet and the Mini App.
- Added a third Amoy RPC (tenderly) to the volume config for read redundancy.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
AppKit's Coinbase Wallet connector calls coinbase.com; allow it so Coinbase
Wallet works alongside the others.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
AppKit injects one inline script; allow it via its sha256 hash rather than
opening script-src to unsafe-inline, preserving the strict policy.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
AppKit renders wallet icons from blob: URLs and uses its brand font from
fonts.reown.com; add blob: to img-src and fonts.reown.com to font-src so the
picker shows proper icons and type.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replaces the low-level ethereum-provider + deprecated modal (broken icons, jank)
with Reown AppKit loaded from the CDN — the standard connector every wallet
supports, with QR + mobile deep-links and a polished picker. Keeps the exact
SIWE sign-in and contract buy/activate logic, driving AppKit's EIP-1193 provider.
CSP widened for the AppKit SDK/RPC + a worker.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
anvil_setBalance doesn't exist on Amoy. The faucet now connects the wallet,
copies the address, and opens faucet.polygon.technology so testers fund their
own wallet with test POL (choose Polygon Amoy). Server endpoint returns the
faucet link + address instead of minting balance.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Mobile users in a normal browser hit "no wallet found" because EIP-6963 only
sees injected/extension wallets. WalletConnect fixes it: the connect picker now
offers WalletConnect (auto-selected when no injected wallet is present), which
shows a QR on desktop and opens the wallet app directly on mobile — no in-app
dApp browser, no second login. Lazy-loads the @walletconnect/ethereum-provider
UMD from jsdelivr; the result is a plain EIP-1193 provider so sign/switch/buy are
unchanged. CSP widened for the SDK + WC relay. Project id lives in site config
(public value); gated so nothing changes until it's set.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Pre-checked "InstantAdPay newsletter" opt-in on the join screen (read by both the
email-code and password signup paths). On new-account creation only, the server
silently subscribes them to the Sendy "InstantAdPay Newsletter" list
(boolean=true, opt-out always wins). New sendy.js helper reads the API key from
SENDY_API_KEY env or DATA_DIR/sendy.key on the volume (same pattern as
sendgrid.key); subscribe is fire-and-forget and never blocks signup.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed /api/moonpay-url endpoint: public key from MOONPAY_PUBLIC_KEY env or site
config, SECRET from MOONPAY_SECRET_KEY env ONLY (never site config, since
/api/config exposes siteConfig). Wallet-prefilled signed MoonPay URL when keys
are set, else a generic buy page. "Buy POL with a card" button under the Buy
packages tiles. Zero custody: MoonPay is merchant of record; crypto goes
straight to the buyer's wallet.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- New /terms, /privacy, /disclaimer pages in the site style with real content
tailored to an on-chain ad+referral platform (no income guarantee, crypto
risk, rehearsal note, privacy of email/wallet/profile, acceptable use).
- renderNav now appends a persistent footer with legal + site links on every
public page; member-area sidebar gets a Legal link group.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New kie.ai art per Marty's palette — Surge dark neon purple, Circuit bright red
starburst, Nexus navy-blue gradient (Spark stays mint). Full-bleed dark, ornate,
blank ribbon; ribbonY re-tuned per badge; ?v=2 cache-bust on the badge images.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- New 125x125 "square button" banner size; ad serve now filters by width/height,
and the sidebar slot serves a 125x125 banner (empty until such inventory exists).
- Shorts reel gets a "report this short" link (posts to /api/report-ad).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New "Training" nav pane lists curated lessons (inline video for mp4/webm, links
for external videos and docs) from /api/training (admin-curated via
data/training.json, with a sensible default).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- QR is mint-green (still high-contrast for reliable scanning).
- The wall shows the owner's achievement badge next to their avatar.
- Positions 2 & 3 fill with upline line-banners, then ADMIN ADS when there's no
upline (configurable via data/admin-wall-ads.json; sensible default) so the
wall is never sparse.
- "Join free through this wall" is disabled until the visitor has viewed every
ad on the wall, with a "X/Y viewed" prompt.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Sign-in page shows "You're joining the line of @X" when arriving via a sponsor
link (/api/sponsor now returns the sponsor name + avatar).
- After a new account verifies (or signs up) with no username yet, an onboarding
modal prompts for a username and an optional bio (both skippable), before the
welcome tour.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Daily login bonus: once/day, base 5 credits + gentle streak (+1/day, cap +5)
for consecutive days; granted after sign-in, toast + cha-ching. New
login_day/login_streak on earned_credits; /api/my/login-bonus.
- Solo ad: selecting Solo now defaults Budget to 50 credits (5cr x 10 min
deliveries) so entering 10 isn't rejected after submit.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Welcome email on new account: onboarding steps + who their sponsor is.
- On-chain event emails: a payout received (TierPaid/AwardPaid) and a payout
that passed you by unqualified (PassedUp), wired into the chain event stream.
- Campaign stats: "+N net" relabeled to "+N network" (clearer than "net").
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Video watch-to-earn: a member can no longer re-earn from the same video the
same day. New video_seen table (dual-mode); serveVideo excludes today's
already-watched videos; videowatch double-checks before crediting.
- Featured card: equal top/bottom margin (no longer touches the stat cards) and
a gold border on the card + the rotating link.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Ad reporting (auto-approved ads need a safety valve): new reports.js store
(dual-mode) + ad_reports table + POST /api/report-ad; a "⚠ report" control on
served ad slots opens a reason prompt and notifies the admin by email
(siteConfig.adminEmail / ADMIN_EMAIL).
- Featured links now show ONE link at a time and cycle (true rotation), instead
of listing all links at once.
- Campaign form now clears EVERY field on submit (target/creative/title/etc.).
A leftover target URL was carrying into the next campaign — the same reason a
video short was saved with the wrong (massifly) CTA target.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- The members area subscribes to the chain event stream (/api/feed/live) and
reacts to anything relevant to the member: a payout received (cha-ching + toast
+ auto-refresh), a referral qualifying, a passed-up payout (missed), a settled
purchase, a new activation in the line. No page refresh required.
- New chat message -> "pop" sound + toast + badge; ping heartbeat (20s) now
returns chatUnread and pops on an increase.
- Sounds are synthesized via Web Audio (no asset files, CSP-safe).
- Surge badge: nudge the name down (ribbonY .779 -> .805) to center on its ribbon.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Buying now ensures the wallet is LINKED to the account before the purchase
(one signature if not linked). Without it, a wallet only connected for the
faucet bought successfully but credits resolved against member id 0 and never
showed until a manual link. Matches the "buying links your wallet" promise.
- Dashboard computed achievement milestones from buyerCount BEFORE reading it
from chain (always 0), so Surge/Circuit/Nexus never unlocked even when
qualification advanced. Moved the milestone block after the chain read.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Fresh wallets hold 0 POL on the rehearsal chain, so nobody could complete a buy.
- Oracle: the mock POL/USD feed had gone ~49h stale (quoteWei reverted "Stale
oracle" -> catalog costWei null -> packages showed "paused"). Refreshed it and
installed a 15-min heartbeat cron so it stays fresh; quotes now return.
- New /api/my/faucet (rehearsal-only, rate-limited) tops a connected wallet up to
10 test-POL via anvil_setBalance (no key). "Get test POL" card in the Wallet
pane wires it. Members can now fund, buy, and see payouts move on the ledger.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Dashboard "Your line" roster now matches referrals joined under the member's
USERNAME link (invite link is /join/<username>), not just code + member id —
username joins were invisible.
- lastBroadcastAt now counts only kind='broadcast'. Chat rides the same table,
so chatting had been tripping the once-a-day broadcast limit ("try again in
24h" on the first broadcast).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- BUG: /api/me never returned avatarUrl/bio/socials/lineBanner fields, so the
Profile pane repopulated empty on reload — data WAS saved, just not surfaced.
Now returned so avatar, bio, and social links persist visibly.
- Achievement badge: member name drops the "@" and sits on a per-badge ribbonY
(spark .728 / surge .779 / circuit .713 / nexus .709), gold with dark outline.
- Sessions now expire in 24h (was 30d) so members re-login daily and see the
login ad each day.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Videos now carry client-detected pixel dimensions (videoW/videoH) captured at
campaign create (upload or direct link). serveVideo takes an orientation filter:
Shorts reel (/shorts) serves portrait (height>width); the Watch videos tab
serves landscape, including legacy/unknown-dimension videos so nothing is orphaned.
- shorts.js requests the portrait feed and has a client guard that skips any
landscape video that slips through. Create form shows the detected orientation.
- Achievement badge share image: member name now renders in gold with a dark
outline (was low-contrast dark ink) and sits centered on the ribbon.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Achievement badge share-image now draws a milestone emblem (⚡🎯⭐🏆) in the medal
- Profile: Facebook/X/YouTube/Instagram/TikTok/Telegram/LinkedIn/Website links, shown on the public bio page
- OG + Twitter Card tags on homepage/ledger/contract (hero banner as share image)
- Per-member OG tags server-injected into /wall/<username> so shared bio links preview with name/bio/avatar
- robots.txt + sitemap.xml; .txt/.xml MIME types
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- spaces.js: zero-dep SigV4 PUT to DO Spaces, public-read; inert unless DO_SPACES_* env is set
- /api/my/upload sends video to Spaces when configured, falls back to volume otherwise
- Images stay local; Spaces URLs are https so they pass the video/media validators + CSP
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Buy N verified visits flat up-front; each is a distinct member, dwell + captcha verified
- Verified visits earn sub-tab: open site (new tab), dwell, human-check, earn
- Per-viewer dedup (visit_seen unique), daily cap, completes at N; single-use tokens
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Per-day occupancy shown in composer (Today 1/10, Tomorrow 2/10, …), full days unpickable
- Book a specific start day + duration; every covered day must have an open slot
- Slot cap turns dilution disclosure into a hard ceiling; featured skips frame-check (new-tab)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- New 'featured' type: headline + link + 1/2/7 day run, flat up-front price (40cr/day)
- Composer discloses dilution (N links share the rotation, yours makes N+1) before buying
- Overview featured strip shows the live rotation; expires automatically
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Profile pane: avatar upload + bio, with a link to your public page
- Wall becomes a bio page: avatar, bio, scannable join QR, line ladder, join CTA
- qrcode npm dep; /api/qr renders SVG QR server-side (CSP-clean img)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Also lands dormant server-side scaffolding for video ads (type, tiers, validation) — not yet exposed in UI.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Welcome tour (3 levels x 10s) unlocks welcome credits; line banner in Profile; public /wall/<username>
- 'Your next move' redesigned as a milestone stepper
- Solo composer: BV-style rich editor (H2/H3, inline image+video, undo/redo, raw text)
- Solo read reward now requires clicking through to the advertiser, not just dwelling
- Sanitizer: inline media whitelist + script/style stripped whole
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>