Commit Graph

330 Commits

Author SHA1 Message Date
martbost c5a846bd91 Keep the notifications worth interrupting for
Splitting system messages out of the modal was right for payout receipts,
but it would have silenced two that a member genuinely loses money by
ignoring:

  - "@someone is trying to buy. Link your wallet so it pays you" — a sale
    is blocked right now, and the referral is lost permanently once it
    routes to someone else.
  - "You missed 43 POL on InstantAdPay" — a payout passed them by, and the
    message explains exactly how to stop the next one doing the same.

So the dividing line is not system-versus-human, it is "does this need you
to do something". Those two become kind 'alert' and still interrupt; the
receipts stay kind 'notice' and stay in the inbox.

The modal no longer credits an alert to a person either. It was saying "A
message from @martbost" over machine-generated text, because system mail
is sent by member 1 at ADMIN_EMAIL. Alerts now read "Action needed on your
account".

Also reclassified "X is now in your line for good" as a notice — it is
good news about a referral the member gained, with nothing at stake.

qa/messages-notice.mjs now covers both lanes: 14 checks, including that an
alert interrupts and a flood of 25 receipts does not.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 08:25:08 -05:00
martbost a2c77d01d1 Stop payout notices interrupting members who are earning
Marty hit this viewing daily ads: a popup after every single return to
the dashboard, each one a different payout notice.

Two causes, both fixed.

The channel was shared. "You just got paid 40.8923 POL" and "Welcome to
my line, here are your first three moves" were stored identically, as
kind 'broadcast' — the kind the sign-in modal is meant to interrupt for.
Dismissing one just promoted the next unread notice, so a backlog became
a carousel. System messages are now kind 'notice': they land in the
inbox, count toward its badge, and never pop. Only a message a person
actually wrote can interrupt.

The modal also had no memory. loadDashboard() runs on far more than
sign-in — after every ad view, campaign edit and chat close — and it
re-popped each time. It now shows at most once per page load and never
twice for the same message.

The 79 existing machine-generated rows are retagged by a migration in
ensureSchema, 15 of them unread and currently popping. Matched on
subject rather than sender on purpose: these come from member 1 at
ADMIN_EMAIL, which is also Marty's own member address, so his genuine
broadcasts sit under the same sender and must be left alone. Verified
against the live data first — "Credits returned: a counting error on our
side" and the broken-banner note are his, and stay as broadcasts.

qa/messages-notice.mjs covers it: a flood of 25 notices produces no
interruption, the human message still does, and chat stays in its own
lane. Member walk clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 08:09:50 -05:00
martbost a84b851272 Correct the DripOffers capacity figure and tighten the cap
I read campaigns.received_today as a per-day counter and told Marty the
platform delivers about 2,700 clicks a day. It doesn't. That column is
only a daily figure while the nightly cron resets it, and that reset has
stopped running, so the value is an accumulation since it last ran.

The permanent click ledger is unambiguous: roughly 40 to 50 clicks a day
across the whole platform. It also agrees exactly with ordered-minus-
remaining on every campaign, which is a good independent check that the
read-never-derive design is reading the right thing.

So MAX_CLICKS drops from 10,000 to 2,500. At the real volume a 10,000-click
booking would hold the top of the offerwall for most of a year.

The pack-2 placement is working as intended and is already measurable: the
three backfilled campaigns took 14 of the platform's 17 clicks today.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 07:04:20 -05:00
martbost 71ab9555e2 Give a syndicated offer a title a stranger can read
A campaign's name is the member's own internal label, and some of them are
two characters ("MG"). DripOffers rejects anything under five, and more to
the point a click-earner scanning the offerwall learns nothing from "MG".

So the ad's own headline comes first, then the label, and a very short
label is qualified with the destination host — "MG (mailer.gold)" — rather
than dropped or dressed up in marketing copy we invented on the member's
behalf. Nothing usable at all returns null instead of a made-up title.

Found by the backfill: campaign 88 failed on it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 06:52:24 -05:00
martbost d4e2f59f9b Member campaigns now go out as click offers on DripOffers
Third syndication rail. The first two send impressions; this one sends
clicks — a real person picks the offer off the offerwall, goes to the
member's link, and has to stay the dwell time before anyone is paid.

Two things it does that the other rails can't:

- It carries geo-targeted campaigns. DripOffers filters on an explicit
  country list, so a campaign aimed at Tier 1 finally reaches an outside
  audience instead of staying on our own site. Tier-3-only campaigns are
  skipped rather than quietly sent worldwide, because an inclusion list
  can't express "everywhere except the other tiers" and widening it would
  deliver exactly the traffic the owner chose to exclude.
- Delivery is counted, not derived. It reads rows from the platform's
  permanent click ledger. It never computes delivery as ordered minus
  remaining, and pausing never zeroes remaining — that pair is what
  charged members for impressions that never ran on Network Ad Space.

Also fixes two live bugs found while wiring it: the AdRevLinks pause was
nested inside the Network Ad Space check in both the end sweep and
setStatus, so with NAS switched off an ended or paused campaign kept
running on AdRevLinks. Each rail is now checked on its own.

Caps: 1,000 credits minimum, 10,000 clicks maximum per campaign. Not for
cost — Marty owns the platform and these placements are free — but because
the whole site delivers around 2,700 clicks a day, and one campaign
booking 50,000 would sit in the list for weeks.

Inert unless DRIPOFFERS_BRIDGE_URL and _KEY are set. 26 checks green
against the live endpoint; member walk clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 06:27:33 -05:00
martbost dc0f0d056d Syndicate member campaigns to AdRevLinks as Tier 1 popup ads
Second delivery surface for member campaigns, and deliberately the opposite shape to the
Network Ad Space rail: that one is Tier 3 heavy, this one only has prices configured for
US, CA, GB, AU, NZ and UM, so its traffic is Tier 1 by construction.

The AdRevLinks database is not reachable from this server, so rather than opening a
database port to the internet there is a narrow authenticated endpoint on that box which
does the insert locally. Five actions, no general query surface: a leaked key can only
create or remove popup campaigns. The secret lives outside that server's webroot and is
compared in constant time; Apache there strips Authorization, so it travels as
X-Bridge-Key.

adrevlnks.js mirrors nas.js, with two rules carried over from this morning's billing bug:
- DELIVERY IS READ, NEVER DERIVED. status returns the rotator's own per-country counters.
  Nothing is computed from a figure a stop could overwrite, which is exactly what charged
  16 members for undelivered impressions on the NAS side.
- EVERY WRITE IS IDEMPOTENT. Each campaign carries ref "iap:<id>", so a retry after a
  timeout returns the existing campaign instead of booking a second one.

Capped on purpose. That server serves roughly 5,500 popup impressions a DAY in total,
shared by every active campaign, and its rotator favours whichever has delivered least. So
syndicating everything unchecked would starve what is already running, Marty's own ads
included. Hence a credit floor and a per-campaign view cap. Cost is not the reason: he owns
the platform and treats the placements as free. Finite shared inventory is the reason.

Hooked into create, pause/resume and the scheduled end sweep so both networks stay in step.
Inert unless ADREVLNKS_BRIDGE_URL and _KEY are set, and a bridge hiccup can never block a
campaign going live.

qa/adrevlnks-bridge.mjs (15 assertions) drives the REAL endpoint: under-floor campaigns
skipped, full credit value booked, Tier 1 targeting, retry returns the same campaign,
delivery read back, pause/resume mirrored, then deleted and confirmed gone. Creates only
paused campaigns so no live traffic is spent, and leaves nothing behind.

nas-served 8, fraud-allow 12, sponsor-note 5, chatbot-parse 35, qa/run.sh member 0 bugs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 05:53:38 -05:00
martbost 3fb123393a Admin credit grants carry their reason into the member's Credit activity
A correction that reads 'granted by admin' explains nothing to the member looking at
their ledger. The note now travels with the grant, so a credit-consumption correction
names itself where they will actually see it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 19:59:13 -05:00
martbost cb6da01e1c Stop billing members for syndicated impressions that were never delivered
Network Ad Space has no stop flag. Its serving query only picks rows with remaining>0,
so zeroing that counter is the only way to halt an ad. But delivery is derived as
assigned - remaining, so the moment an ad was stopped it read back as 100% DELIVERED.

That was not only a reporting error. reconcileNas() runs every five minutes, had no
status filter, and CHARGES member credits off that figure. So pausing a campaign, or
ending one, made the next reconcile pass bill the member for the entire unspent budget
as though it had all been served.

Measured on production before the fix: 23 member campaigns across 16 members, every
single one charged to exactly 100% of budget, 11,437 credits in total, against on-site
delivery evidence of roughly 4,700 impressions. A naturally exhausted ad also ends at
remaining=0, so the two cases cannot be told apart after the fact, which is why the
true figure has to be captured before the stop.

Three changes:
- nas.deactivate() now reads the real served count BEFORE zeroing and returns it.
- a new ads.stopNas() helper is the only path to a stop, and it persists that figure as
  the campaign's final delivery. No caller touches nas.deactivate() directly any more.
- reconcileNas() only processes campaigns with status='active'. A stopped ad delivers
  nothing further, so there is never anything legitimate left to charge for.

qa/nas-served.mjs (8 assertions) stubs the NAS layer and drives the real code: pausing
records the true 3,000 rather than the 10,000 allocation, a paused campaign is never
charged afterwards and its figure never jumps to the allocation, and an active campaign
still reconciles and is charged normally so the guard did not break delivery.

fraud-allow 12, sponsor-note 5, chatbot-parse 35, qa/run.sh member 0 bugs.

Historical delivery is not recoverable: the stop overwrote the only record of it.
Refunding the 11,437 credits to the 16 affected members is Marty's call, pending.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 19:52:12 -05:00
martbost e95f9df13a Approved exceptions: people you have okayed to hold more than one account
Marty approves specific people for multiple accounts (partners, staff, a spouse on a
shared machine) and needed a way to say so without the guard fighting him.

Admin > Members > Duplicate signals now carries an "Approved exceptions" list: add an
email with a note, see who is on it and when, remove one. It sits directly under the
signals so the two are read together.

An exception can be added against the address they ALREADY have, not just the new one.
That matters because the usual case is approving a person before their second address
exists, and at sign-up time the new address is unknown to us. checkSignup now tracks
every account the sign-up collided with, and clears the block if either side is approved.

Clearing the HARD flags matters as much as clearing the block. Those flags are what
silently drop an account off the leaderboard and bar it from adopting out of the holding
tank, so an approved person would have been "allowed" in name only. They now keep both.
The account is tagged 'allowlisted' instead, so the admin sees why it went through, and
the server logs the exception by name.

Suspension still wins. An exception is permission to hold several accounts, not immunity
from being suspended for something else.

qa/fraud-allow.mjs (12 assertions) boots its own server and walks the real flow: first
account created, second blocked with the Qualified Start redirect, exception added,
second account now created, no hard flag left on it, exception visible in the admin
report, removing it blocks again, malformed address refused, endpoint admin-only.
qa/sponsor-note.mjs 5, qa/run.sh member 0 bugs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 10:42:31 -05:00
martbost 2dfccf0039 Sign-in no longer tells an existing member they are joining somebody's line
Marty signed in and was told "You're joining the line of @bliss". He is member #1.

Cause: the last-touch sponsor cookie lives 30 days, and /api/sponsor set invited
purely from that cookie. So any member who had ever clicked a teammate's invite link
was greeted on the sign-in screen as though logging in would place them under that
person. Untrue, and alarming in exactly the wrong place: their sponsor locked at their
first purchase and nothing on that screen can move it. Anyone seeing that would
reasonably worry their line was about to change.

The greeting now shows when someone actually arrived through a link (?ref= in the URL),
or when the cookie is present AND this browser has never had an account, which is the
genuine "came back later to finish joining" case. A browser that already has an account,
or a signed-in session, never sees it.

Attribution is deliberately untouched: the cookie still resolves, the sponsor id is
still returned, and placement still works exactly as before. Only the greeting changed.

fraud.hasAccountOnDevice(req) is the new signal, reusing the device cookie the
one-account-per-person checks already set.

qa/sponsor-note.mjs (5 assertions) boots its own throwaway server and creates a REAL
account so the case is proven rather than assumed: still greeted with ?ref=, still
greeted from the cookie on a browser with no account, NOT greeted on the browser that
has one, and attribution still resolving. qa/run.sh member: 0 bugs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 08:41:46 -05:00
martbost f27388a322 Chatbot: catch the PIF question when nobody says "PIF", and stop inventing references
Follow-on to the risk rewrite. Two gaps it exposed.

Members ask this without the word PIF: "should I fund their first package", "can I
buy it for them", "can I front someone the $20". Those were falling through to the
AI, which answered reasonably but told the member to "read the full warning on your
training page" - a page section that does not exist and that they would go looking
for. The pattern now also matches a paying verb plus an explicit for-someone-else
phrase, so these get the full canned answer with the risk in it. It deliberately
needs BOTH halves: "which package should I buy" must not be stolen.

The prompt now forbids sending anyone to a warning, guide or page section that is
not in the PAGES list, and requires plain ASCII (the model was emitting non-breaking
hyphens in "Wi-Fi").

Fixed two first-match-wins routing bugs, one of them mine from the previous commit:
"what do I get for buying a package" was returning the commission split, because I
had widened the earnings pattern to "what do I get" when it should only ever have
been "what do I get paid". And "should I buy the $20 package" previously matched
nothing at all and burned an AI call on a question we have a written answer for.

CANNED is an ordered list, so any pattern edit can silently steal a neighbour. The
suite now pins a 19-case routing table across PIF, price, earnings and the tank, so
the next person to widen a regex finds out immediately. qa/chatbot-parse.mjs is 35
assertions. qa/run.sh member: 0 bugs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 05:41:54 -05:00
martbost 3867b28bd4 Chatbot: the PIF risk is the answer, not a footnote
Marty: the answer has to cover what a member is risking when they send POL to
somebody they have not spoken to and have no commitment from.

The canned answer now leads the advice with "do not send anything until you have
actually talked to that person and they have told you they will use it", then says
plainly: the transfer is wallet to wallet and irreversible, there is no refund and
no chargeback, support cannot pull it back, the gift is theirs whatever they do with
it, and they are free to go quiet or spend it on something else without breaking any
rule. It names the worst case for what it is, which is that a tank member joined
with nobody working with them and may never have engaged, so an unanswered PIF is
the easiest money on this site to lose.

It gives the arithmetic both ways rather than only the upside: a gift that works
costs about half, because the contract pays the sponsor 50 percent when they buy;
a gift to someone who never answers costs all of it. It ends on never gift money
you need and never borrow to do it.

The same guidance goes into the AI prompt as a standing rule, so PIF is never sold
as a tactic on any phrasing that misses the canned pattern, and a "should I PIF
someone from the tank" question starts with talk to them first, not the mechanics.

qa/chatbot-parse.mjs is now 16 assertions: the 9 response-shape cases plus 7 that
pin each risk line, so a future rewrite cannot quietly drop them.
qa/run.sh member: 0 bugs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 05:36:42 -05:00
martbost 6c8cc0ede2 Chatbot: the PIF and holding-tank answers, and no more dead ends on a provider hiccup
Marty hit "I hit a snag answering that one" on "Should I pif someone from the
holding tank". Two separate problems behind it.

The real bug: OpenRouter pads a slow upstream with keepalive lines before the JSON,
and when the provider gives up it can close having sent ONLY that padding. HTTP 200,
no body. JSON.parse threw and EVERY non-canned question died the same way, not just
this one. Now we find the actual JSON object in the stream, treat an empty answer as
a failure rather than sending a blank reply, retry once (the usual cause is one
provider dropping the request), and if both attempts fail we say plainly that it was
our side, not their question, and point at a person.

The content gap: PIF and the holding tank were in the system prompt but had no canned
answers, so they depended on the AI being up. Both are now canned and instant. The PIF
answer leads with the thing the question gets wrong, which is that you cannot PIF
somebody still in the tank: adopt first, they link a wallet, then the button appears.
It is honest that nothing obliges them to buy, that crypto transfers are irreversible,
and that the 50 percent coming back only happens if they actually purchase.

Also fixes a pre-existing routing bug found while testing: "how much do I earn"
returned the PACKAGE PRICE ladder, because the price pattern matches "how much do"
and the commission pattern only caught "how much earn".

qa/chatbot-parse.mjs (9 assertions) drives the real parse branch against a stub
server for every response shape: keepalive-only, keepalive-then-JSON, plain JSON,
SSE comments, empty content, non-JSON. qa/run.sh member: 0 bugs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 05:27:18 -05:00
martbost 8ad2e01a74 Admin: a linked wallet can no longer be misread as an active position
The member card showed the wallet address on its own, directly above "Registered:
no (payouts off)". That reads as "he is set up" when he is not, and it caused a
real misread today on @mcbit1: wallet linked, memberId 0 on chain, every sale in
his line walking up to his sponsor while the row looked healthy.

Linking a wallet is a free signature that tells the site which address is theirs.
Switching on payouts is a separate transaction that creates the position. Only the
second one makes them payable, so the two states now say so:

  Main wallet  0x30a7…5703  payouts OFF
  Registered   no  wallet linked, but payouts were never switched on, so no
               position exists. Sales in their line walk up to their sponsor and
               lock there.

and the no-wallet case says "no wallet linked yet" instead of the same text.

qa/run.sh member: 0 bugs (the 2 warnings are pre-existing and unrelated).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 05:03:29 -05:00
martbost a2cea3a2be Anti-fraud refusals redirect to Qualified Start (the sanctioned way to hold extra positions); chatbot says the same
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:52:46 -05:00
martbost aab18e28ca Sign-up: hand out the device cookie on every code-request response, including guard refusals
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:40:54 -05:00
martbost 34c62b9d3a Anti-fraud: one account per person enforced at sign-up (device cookie + IP), flags, admin duplicate signals, suspend switch
Marty, 2026-09-16, after @megamol created megamol2/megamol3 under his own link and bought $20 on each
to fake his two qualifying buyers. fraud.js records sign-up IP/UA/browser id (iap.dev cookie set with
the code request) and last-seen on sign-in. New accounts: dup-device (browser already has an account)
and sponsor-device are refused, ip-burst (> fraudMaxSignupsPerIpDay, default 2, per 24h) is refused;
sponsor-ip and shared-ip are flagged only. Flagged/suspended accounts never count on the leaderboard
and cannot adopt from the tank; suspended accounts are signed out everywhere (auth.fromRequest
wrapper) and refused at sign-in. Admin > Members: Duplicate signals card (shared browser / IP,
flagged, suspended), flags badge, Suspend/Unsuspend; GET /api/admin/fraud; PATCH members {suspend,
reason, flags}. Telegram admin alert on every block/flag. Privacy page + chatbot prompt updated.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:39:13 -05:00
martbost 125be174e3 Terms: one account per person (duplicate accounts and self-referral prohibited; Qualified Start linked wallets are the only sanctioned extra positions); chatbot canned + prompt
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:29:54 -05:00
martbost 9b3a79561b Chatbot: repair the price pattern (shell had turned \b into backspace bytes), full package ladder in the answer, ranked above the credits answer
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:19:17 -05:00
martbost 2b4050d410 Chatbot: exact page map (no invented URLs), tighter price/credit patterns, canned answer for the unactivated-sponsor walk-up
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:14:37 -05:00
martbost 27f2742c31 Chatbot: banner-image questions get the creative rule, not the Promo tools kit answer
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:12:49 -05:00
martbost 362526d007 Chatbot brought fully current + knowledge guard
Audit against the live site: removed stale text (featured links and visit packs marked "coming",
Pipeline "coming soon", the superseded sponsor-hold rule, a non-existent home-page calculator,
"earned credits spend on banner and text only", "Coaching pane"); added live featured and visit-pack
rules with prices and limits, the video cap and rewards, the sign-in bonus and claim ladders,
report-an-ad, the public missed-payout posts, the walk-up gain notice, the four-minute overview
video, the promo Videos and Toolkit tabs; new canned answers for featured links, visit packs and
"what is this". KNOWLEDGE_DATE constant + qa/chatbot-sync.mjs (run in public/all QA) fails when a
release note is newer than the chatbot's knowledge.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 14:10:00 -05:00
martbost 5641582709 Banner creatives must be images: server-side image check (extension or image/* HEAD), form hint, chatbot note
Campaign #134 (NAS ad 2806) had the member's join-page link in the image field and served a broken
banner 141 times on the network; #102 did the same with an imgbb page link. imageCheck() accepts
/uploads/ and instantadpay.com/banners files and image extensions outright, otherwise HEADs the URL
(one redirect) and requires image/*. Wired into member and house campaign creation for banners and
login-ad creatives. Form placeholder + hint point at Promo tools > Banners > Copy image URL.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 13:56:30 -05:00
martbost d6bc79c9d6 Home: 'Watch the 4-minute overview' CTA + inline overview video section (Spaces training/platform-overview.mp4)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 13:42:23 -05:00
martbost b811b96e33 Payments feeds: post who missed a share and who got it (on-chain pass-ups and off-chain walk-ups)
Marty, 2026-09-16: make missing a payout visible. On a TierPaid with hops>0 the PassedUp events of the
same tx name the skipped positions, with the reason and how many qualifying buyers they had; the post
says the amount and who received it instead. On a Purchase whose buyer was routed past an unactivated
sponsor (movedByTx set by sponsorSyncOnEvent), the post names the sponsor who missed the whole sale
and the upline who now owns that buyer for good. Both go to the main feed and the shared payments
topic unless the events mode is 'none'.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 13:25:31 -05:00
martbost 230c250c64 Earnings pane: Trace a payment card sits at the top
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 12:30:46 -05:00
martbost a727ab1ce5 Payment trace: self-serve "who was paid, who was skipped and why" per purchase (Earnings tab + admin member card)
Marty, 2026-09-16, after the third "why didn't my sponsor get paid" thread of the day (livedreams / gracie25,
Morten / Terry's linked wallets). GET /api/my/trace?who=<#|username> (yourself, anyone up to 3 levels
below you, or your own 3 uplines) and GET /api/admin/trace?who= list every purchase the member was
part of, newest first: buyer, sponsor, package, then levels 1-3 with the recipient, the skipped
positions and the reason ("not qualified: had N of 2 qualifying buyers then"), the platform share, and
a verify link. Linked extra wallets are named after their owner. Earnings tab card "Trace a payment";
admin member card gets a "Payment trace" section; chatbot canned answer + AI prompt route the
question there.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 12:24:53 -05:00
martbost dffcaa113b Never hold a sale for an unactivated sponsor: walk up to the first payable upline, referral follows the money
Marty, 2026-09-16: a purchase must never wait on a sponsor who has not linked a wallet / switched on
payouts. /api/sponsor and /me now walk the site's sponsor line upward to the first upline that is
activated with payouts on (not on the no-payout list) and the buy proceeds under them; nobody
activated -> the catch position (#1). The buyer sees a one-line notice and carries on; admin gets a
heads-up. When the position is created on-chain (MemberActivated), sponsorSyncOnEvent re-points the
buyer's stored sponsor to whoever was paid (#1 included), so the referral leaves the skipped
sponsor's line for good, then sends the pointed notices: the skipped sponsor(s) are told they lost
this referral permanently and how to switch on payouts; the sponsor who was paid is told the
referral is theirs for good and to coach the one who missed it (teach-forward). Admin lookup:
GET /api/admin/sponsor-resolve?ref=. Only a transient chain error still pauses a buy.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 11:18:14 -05:00
martbost a85a198e95 Chain index keeps the full event history (was a 600-event window); one-time rescan from the deploy block
Hugh's Earnings page showed no payouts, referrals or purchases: /api/my/activity read the last 600
events and the window had moved past his Sept 9-10 activity. Ten other readers (dashboard earned
total, leaderboard, holding-tank own-buy check, admin member view, growth snapshot, P&L, burner
match) treated the same list as complete. KEEP_EVENTS 600 -> 250000; chain.rescan() rebuilds from
deployBlock without re-firing onEvent (no repeat Telegram/email), keeps real ts for known events and
estimates ts by block height for backfilled ones; runs once at boot when a filled window is found;
admin routes POST /api/admin/chain/rescan and GET /api/admin/chain/status. State file only rewritten
when events changed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 10:36:28 -05:00
martbost dda8c976b0 No native dialogs: Shorts report prompt -> inline reason buttons; admin drip confirms -> IAP.confirmBox
Same class of bug as the campaign #27 false report: the Shorts report was a prompt() pre-filled with
'inappropriate'. Members now tap a reason button on purpose or cancel. Script tags bumped.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 10:23:00 -05:00
martbost 616f328db5 Report-an-ad dialog: site dialog with no default reason (was a native prompt pre-filled with "broken")
Campaign #27 (house AdRevSplit text ad) was reported "broken" with no note while the target framed
and loaded fine; the report dialog was prompt() with 'broken' as the default value, so one stray OK
filed it. Now IAP.ask with an explicit, validated reason and an optional note; common.js tag bumped
on all pages.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 10:21:53 -05:00
martbost 69d672665c Credit activity ledger: every earn and spend logged with a reason, listed under Campaigns
Hugh earned a 10-credit sign-in bonus, then bought a 280-credit extension; earned credits spend
first, so Earned read 0 and the bonus looked lost. There was no record a member could check.
Now every real credit movement writes a credit_log row (JSON store in file mode): welcome, sign-in
bonus with streak, daily claim, inbox reads, video watches, verified visits, milestone/leaderboard
bonuses, partner codes, admin/team grants, AI Copy Engine charges + refunds, flat buys (featured
run, extension, visit pack, more visits), login-ad days, and metered delivery rolled up per
campaign per day; on-chain purchased-credit spends are marked. GET /api/my/credits/activity;
dashboard shows the last 40 under Campaigns (also when there are no campaigns) with a link from
Earn credits. Chatbot canned answer + AI prompt updated; my.js tag bumped.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 08:41:43 -05:00
martbost ffacf741da Extend run / visits top-up: budget = charged + this buy (release parked credits); featured row shows days left
Hugh extended his featured link and his balance fell 1,133 -> 0: the row still carried the 1,400
parked by the old add-credits button, and reactivating it reserved that budget again. Both flat
paths now set budget to spent + accrued + cost. Featured Run column shows "N of M days left"
(Hugh: "says 14 but it's actually 7") and "M days done" after the run.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 08:19:33 -05:00
martbost 28bce75913 Featured links: Extend run (book more days) replaces Buy more views; visit packs top up by visits; campaign rows say paid up front and runs through
Hugh and Michael both added credits to a featured run expecting more days. Featured is a flat
daily buy, so the credits sat unspent until the run ended and their balance read 0 meanwhile.
Now: /api/my/campaigns/:id/extend books extra days after the current run (or from today if it
ended) and charges them at once; top-up refuses featured; a visits top-up buys more visits at the
pack rate, charged now; rows show paid up front + day count + runs through <date> / run ended;
explainer under the campaign table; chatbot canned answer + AI prompt updated; my.js v tag bumped.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 07:38:37 -05:00
martbost b1a1cbff5e Achievement badge image rendered on the server with ffmpeg (a phone canvas sent a blank card); admin re-post route
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 03:30:01 -05:00
martbost 84d9f49d4b Held purchase: nudge the sponsor automatically (email + on-site) to link a wallet and switch on payouts, once an hour at most
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 23:43:11 -05:00
martbost b7cc06b28c Overview: click a chip in Your line at a glance to open that member's Activity panel on My line
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 18:54:00 -05:00
martbost 0da7c796b8 Campaigns: visit packs show 'paid up front' and delivered-of-total instead of a spent bar (Michael's 3,000-credit pack looked used up)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 16:13:26 -05:00
martbost 4d578fadac Lead with the $20 activation language; free-member POL earning no longer volunteered (Marty); chatbot answers truthfully only when asked point-blank
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 15:00:01 -05:00
martbost 310384cdad Credits versus POL spelled out: level 1 needs payouts on (no purchase), free members earn credits; home page block, earning page, join step 3, chatbot (Clinton's question)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 14:29:39 -05:00
martbost 66b3c83d3d Burner: when a campaign's pinned position is dry on-chain, settle the spend from another funded position on the same account (credits are pooled per account)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 12:49:16 -05:00
martbost 92e7304882 Daily growth snapshot to the Telegram payments feed and shared topic (sign-ups, purchases, POL paid, campaigns, viewing, lifetime totals); admin preview/send-now routes and settings
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 12:43:19 -05:00
martbost 8ca019a5b3 Pipeline advice follows the main wallet's buyer count (what the contract pays on); card states the linked-positions rule; chatbot knows it
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 12:26:02 -05:00
martbost 560d758ed9 Pipeline: count linked positions' buyers on member cards, the way My line and badges do; show the main/positions split on the card
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 12:22:25 -05:00
martbost 02f742f90a Pipeline: sponsor follow-up board (stages from the ledger, notes/follow-ups/tags, stage messages into chat), gated by pipelineMode with a coming-soon card until launch; training cards can wait on the same switch
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 11:01:03 -05:00
martbost 56aa7418ad Payment and missed-payment notices also land in the on-site inbox (login pop-up + Messages card), with who bought, share in POL and dollars, and the transaction link
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 10:44:48 -05:00
martbost d6d771d93e Missed-payout email: tell the skipped member who bought, what they missed in POL and dollars, buyers needed, and how to close the gap
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 10:39:12 -05:00
martbost 87fa837165 Campaigns table: click sources stacked so the Clicks column stays narrow, card layout up to 900px; audit alert-day persisted, rounding-scale diffs ignored
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 07:31:16 -05:00
martbost 653c6d486e Launch checklist: launch graphics (wide + square), five day-by-day posts and a DM with link and FOUNDER code, copy buttons
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 07:12:23 -05:00
martbost c5e4dc423b Launch checklist: four promoter swipe emails with the member's link and the FOUNDER code, copy buttons
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 07:05:57 -05:00