martbost 08f7a408e3 Passwordless sign-in: 6-digit email codes, feature-flagged on SendGrid key
/api/auth/email/start issues a 15-min code (60s resend guard, 6 tries);
verify creates the account passwordless (sponsor cookie first-touch) and
mints the session. UI swaps the password cards for the code flow when
config.emailAuth is on; dev mode returns the code inline. Password flow
remains until the key lands in the volume (data/sendgrid.key) or
SENDGRID_KEY env.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-04 13:38:11 -05:00

InstantAdPay — site

Membership advertising with immutable on-chain settlement. Zero-dependency Node server (RM Circle pattern): static pages + JSON API + SSE ledger.

Architecture

  • server.js — http server: pages, /api/*, /join/<id> sponsor links, SSE feed
  • chain.js — contract reader + persistent event indexer (free public RPCs)
  • auth.js — SIWE wallet sign-in (EIP-4361), sessions in the volume
  • accounts.js — site-side records only (free members, first-touch sponsor attribution, handles). The CHAIN is the source of truth for money/credits.
  • public/ — landing, live ledger, member area; no client libraries

Chain flip (rehearsal → mainnet)

Everything chain-specific lives in data/config.json (volume): {contract, chainId, chainName, explorer, rpcs, deployBlock}. Defaults point at the Amoy rehearsal deployment. Launch = deploy the mainnet contract, wipe accounts.json/sessions.json/chain-index.json, PATCH /api/admin/chain with the mainnet values, set rehearsal:false via /api/admin/site. Same code, different config.

Run

PORT=3100 node server.js       # DATA_DIR defaults to ./data

Admin API auth: Authorization: Bearer $ADMIN_PASSWORD.

Spec: ../CONTRACT-SPEC.md (v1.0.3-frozen). Contracts: ../contracts/.

S
Description
InstantAdPay membership advertising site
Readme 39 MiB
Languages
JavaScript 78.6%
HTML 17.1%
CSS 4.2%
Shell 0.1%