Two holes left by videoCheck, which only ever ran when a campaign was saved. The house-ad route never called it at all. It guarded /api/my/campaigns and not /api/admin/campaigns, so a bad source pasted into a house video would hand every viewer a black player exactly as #146 did. And nothing re-checked anything after it went live. #146 pointed at https://yourdomain.com/ from 16 September; the check shipped on the 22nd and the campaign sat live for another two days, burning a daily video slot for everyone who drew it, until Marty hit it himself and asked why nothing played. A save-time check can never catch a campaign that predates it, or a link that rots later. videosweep re-checks every live video source daily. A source that fails is PAUSED, never deleted: the advertiser keeps every unspent credit, because the reservation is computed rather than deducted, and can restart it once the link is fixed. It reports what it paused to the admin channel rather than doing it quietly, since a guard nobody hears from is how the first one went unnoticed. POST /api/admin/videosweep runs it on demand, with { dry: true } to look first. QA green, 0 bugs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
InstantAdPay — site
Membership advertising with immutable on-chain settlement. Zero-dependency Node server (RM Circle pattern): static pages + JSON API + SSE ledger.
Architecture
server.js— http server: pages,/api/*,/join/<id>sponsor links, SSE feedchain.js— contract reader + persistent event indexer (free public RPCs)auth.js— SIWE wallet sign-in (EIP-4361), sessions in the volumeaccounts.js— site-side records only (free members, last-touch sponsor attribution, handles). The CHAIN is the source of truth for money/credits.public/— landing, live ledger, member area; no client libraries
Chain flip (rehearsal → mainnet)
Everything chain-specific lives in data/config.json (volume):
{contract, chainId, chainName, explorer, rpcs, deployBlock}.
Defaults point at the Amoy rehearsal deployment. Launch = deploy the
mainnet contract, wipe accounts.json/sessions.json/chain-index.json,
PATCH /api/admin/chain with the mainnet values, set rehearsal:false via
/api/admin/site. Same code, different config.
Run
PORT=3100 node server.js # DATA_DIR defaults to ./data
Admin API auth: Authorization: Bearer $ADMIN_PASSWORD.
Spec: ../CONTRACT-SPEC.md (v1.0.3-frozen). Contracts: ../contracts/.
Chatbot knowledge is part of every change
chatbot.js answers members two ways: CANNED regex answers and systemPrompt() for the AI. Any
change that a member could ask about (a new pane, a rule, a price, a limit, a fix they noticed) is not
done until both are updated in the same commit, and KNOWLEDGE_DATE in chatbot.js is bumped. The QA
runner (bash qa/run.sh public) fails when a release note on the live site is newer than that date.