martbost f2a999edd0 Search Console verification for instantadpay.com
Google Safe Browsing has the site marked "some pages on this site are unsafe"
(social engineering) as of 24 September. The only place that names the pages,
and the only place a review can be requested, is Search Console, and the site
was never verified there. Meta tag on the home page plus the HTML-file
fallback; both are Marty's own account.

The likeliest trigger is already paused: campaign #225 was a verified-visits
ad opening llclickpro.com from our pages, and llclickpro.com carries the same
flag. A guard for that class of problem is the next commit.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-24 19:26:22 -05:00
2026-09-18 13:31:52 -05:00
2026-09-14 05:40:26 -05:00

InstantAdPay — site

Membership advertising with immutable on-chain settlement. Zero-dependency Node server (RM Circle pattern): static pages + JSON API + SSE ledger.

Architecture

  • server.js — http server: pages, /api/*, /join/<id> sponsor links, SSE feed
  • chain.js — contract reader + persistent event indexer (free public RPCs)
  • auth.js — SIWE wallet sign-in (EIP-4361), sessions in the volume
  • accounts.js — site-side records only (free members, last-touch sponsor attribution, handles). The CHAIN is the source of truth for money/credits.
  • public/ — landing, live ledger, member area; no client libraries

Chain flip (rehearsal → mainnet)

Everything chain-specific lives in data/config.json (volume): {contract, chainId, chainName, explorer, rpcs, deployBlock}. Defaults point at the Amoy rehearsal deployment. Launch = deploy the mainnet contract, wipe accounts.json/sessions.json/chain-index.json, PATCH /api/admin/chain with the mainnet values, set rehearsal:false via /api/admin/site. Same code, different config.

Run

PORT=3100 node server.js       # DATA_DIR defaults to ./data

Admin API auth: Authorization: Bearer $ADMIN_PASSWORD.

Spec: ../CONTRACT-SPEC.md (v1.0.3-frozen). Contracts: ../contracts/.

Chatbot knowledge is part of every change

chatbot.js answers members two ways: CANNED regex answers and systemPrompt() for the AI. Any change that a member could ask about (a new pane, a rule, a price, a limit, a fix they noticed) is not done until both are updated in the same commit, and KNOWLEDGE_DATE in chatbot.js is bumped. The QA runner (bash qa/run.sh public) fails when a release note on the live site is newer than that date.

S
Description
InstantAdPay membership advertising site
Readme 39 MiB
Languages
JavaScript 78.8%
HTML 17%
CSS 4.1%
Shell 0.1%