martbost 1d52597c1c Fix missing QR on every member page — blocked by our own CSP
The QR on /p/<id> and /p/<id>/<slug> was drawn by an inline <script>, but the
site sends `script-src 'self'` with no 'unsafe-inline'. The browser silently
refused to run it, so the QR box rendered as an empty white square on every
member page, not just Funnel Factory ones.

Moved the bootstrap to /page-qr.js and pass the link via a data attribute, so
no page data is interpolated into executable script and the CSP stays as
strict as it is. Loosening script-src to fix this would have traded a
site-wide security property for one widget.

This matters more than it looks: these pages go on printed flyers and ad
destinations, where an unscannable QR is discovered by the person holding the
paper.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-28 11:28:48 -05:00

RM Circle Premium — Crypto Team Build Sponsor Router

A small deployable Node/Express app with:

  • / — evergreen advertising/bridge page
  • /start — dynamic onboarding page with the current team sponsor
  • /admin — password-protected sponsor queue manager
  • JSON-file persistence suitable for a Docker volume

Core workflow

  1. Traffic lands on the evergreen bridge page.
  2. Visitors click Get Started.
  3. /start reads the active sponsor from the server and builds the RM Circle referral link dynamically.
  4. In /admin, increment a sponsor's direct count as joins are verified.
  5. When a sponsor reaches 2, click Qualified.
  6. The next waiting sponsor becomes active immediately—no HTML or ad changes required.

Default seeded queue

The seed data reflects the working Crypto Team Build priority list at build time:

  1. ID 30 — Orlando (active)
  2. ID 36 — Mad Dog
  3. ID 35 — Michael Camire
  4. ID 32 — Melissa
  5. ID 34 — Janie

You can change, reorder, add, or delete sponsors in /admin.

Local run

cp .env.example .env
# edit .env and set a strong ADMIN_PASSWORD + SESSION_SECRET
set -a && . ./.env && set +a
npm start

Open:

  • http://localhost:3000/
  • http://localhost:3000/start
  • http://localhost:3000/admin

Docker / Coolify

This project includes a zero-dependency Node server, Dockerfile, and docker-compose.yml. No npm package download is required.

Coolify recommendation

  1. Create a new application from this source/repository.
  2. Use the Dockerfile or Compose deployment.
  3. Add environment variables:
    • ADMIN_PASSWORD — strong unique password
    • SESSION_SECRET — long random string
    • NODE_ENV=production
    • DATA_DIR=/app/data
  4. Persist /app/data using a volume.
  5. Point your domain/subdomain at port 3000 through Coolify's normal proxy/domain configuration.
  6. Open /admin, sign in, and verify the queue before sending traffic.

Sponsor referral URL

The default base is:

https://app.thermcircle.com?ref=

The app appends the current sponsor ID, for example:

https://app.thermcircle.com?ref=30

Change the base URL at any time in Admin → Public Page Settings without editing code.

Important operational behavior

The app intentionally does not auto-qualify sponsors based on clicks or blockchain activity. A team admin verifies the actual placement and clicks Qualified. This prevents an ad click or abandoned transaction from rotating the sponsor queue incorrectly.

Safety and compliance notes

The public pages include risk language, avoid guaranteed-income claims, and remind users never to disclose a MetaMask Secret Recovery Phrase. The onboarding page points to the official MetaMask website and identifies Polygon Mainnet as chain ID 137 with POL as the native gas token.

This app does not custody crypto, request wallet seed phrases, execute transactions, or store private keys.

S
Description
RM Circle Premium - evergreen bridge page + dynamic Crypto Team Build sponsor router
Readme 715 MiB
Languages
JavaScript 65.9%
HTML 33.9%
Shell 0.2%