Google marked instantadpay.com "deceptive pages" on 24 September. The probable cause was campaign #225: a verified-visits ad that opened llclickpro.com from our pages, and llclickpro.com carries exactly that flag. We put other people's destinations in front of members, so their reputation becomes ours, and nothing was checking it. sbcheck.js screens the destination when a campaign is saved (member and house paths both) and re-screens every live campaign daily, pausing the ones on a flagged host and alerting the admin channel with the campaigns and owners. POST /api/admin/sbcheck {dry} runs a pass by hand. Verdicts are three-valued on purpose: flagged, clean, unknown. A guard that reads "could not check" as "clean" is the failure mode this whole day has been about; one that reads it as "flagged" would refuse every advertiser whenever Google rate-limits us. So flagged refuses and pauses, clean passes, unknown passes at save time but is logged and retried by the sweep until it resolves. Uses the official Lookup API v4 when SAFE_BROWSING_KEY is set (full-URL, batched). Until a key exists it reads the Transparency Report site-status record, decoded against Google's own test site rather than guessed: status 1 is clean, status 3 with any true flag is listed, anything else is no data. That endpoint rate-limits by answering HTML, hence the 4-second pace. videosweep's inline alert is hoisted into videosweepAlert so both sweeps use the same admin-only channel: these messages name members and their emails. QA: member walk 0 bugs, public walk 0 bugs. Verified by hand that llclickpro.com is refused, rmcircle.team passes, and our own host is skipped. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
InstantAdPay — site
Membership advertising with immutable on-chain settlement. Zero-dependency Node server (RM Circle pattern): static pages + JSON API + SSE ledger.
Architecture
server.js— http server: pages,/api/*,/join/<id>sponsor links, SSE feedchain.js— contract reader + persistent event indexer (free public RPCs)auth.js— SIWE wallet sign-in (EIP-4361), sessions in the volumeaccounts.js— site-side records only (free members, last-touch sponsor attribution, handles). The CHAIN is the source of truth for money/credits.public/— landing, live ledger, member area; no client libraries
Chain flip (rehearsal → mainnet)
Everything chain-specific lives in data/config.json (volume):
{contract, chainId, chainName, explorer, rpcs, deployBlock}.
Defaults point at the Amoy rehearsal deployment. Launch = deploy the
mainnet contract, wipe accounts.json/sessions.json/chain-index.json,
PATCH /api/admin/chain with the mainnet values, set rehearsal:false via
/api/admin/site. Same code, different config.
Run
PORT=3100 node server.js # DATA_DIR defaults to ./data
Admin API auth: Authorization: Bearer $ADMIN_PASSWORD.
Spec: ../CONTRACT-SPEC.md (v1.0.3-frozen). Contracts: ../contracts/.
Chatbot knowledge is part of every change
chatbot.js answers members two ways: CANNED regex answers and systemPrompt() for the AI. Any
change that a member could ask about (a new pane, a rule, a price, a limit, a fix they noticed) is not
done until both are updated in the same commit, and KNOWLEDGE_DATE in chatbot.js is bumped. The QA
runner (bash qa/run.sh public) fails when a release note on the live site is newer than that date.