martbost 7d07fc01f1 Required member profile: username + verified email per position, gated at proof of ownership
Marty, 2026-09-16: leaders can write but 94% of positions cannot receive (47 of 771 have ever signed
in to messaging, 482 messages sit 85% unread). profiles.js stores username + verified email per
POSITION (one wallet holds one position, so a Triple Play holder has three; the person is the email
and one email may hold several positions). Seeds the 40 emails already on file from
member-alerts.json, pre-filled but unverified so confirming costs one tap.

Writes are only ever accepted from a session that PROVED ownership: wallet personal_sign
(messages.verifyChallenge) or the Telegram Mini App bridge. The public /my/<id> page is untouched and
cannot write a profile, verified by test: all four endpoints 401 unauthenticated while /my/21 stays
200. Endpoints GET /api/public/profile, POST .../username, .../email-start, .../email-verify, plus
GET /api/admin/profiles for coverage. Email codes: 6 digits, 15 min, 60s cooldown, 5/day, 6 tries.

profile-gate.js is a two-step modal that cannot be dismissed, fired on dashboard boot (covers the
Mini App landing) and right after a wallet sign-in. Chatbot canned answer + AI prompt updated.
28 unit tests pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 16:56:35 -05:00

RM Circle Premium — Crypto Team Build Sponsor Router

A small deployable Node/Express app with:

  • / — evergreen advertising/bridge page
  • /start — dynamic onboarding page with the current team sponsor
  • /admin — password-protected sponsor queue manager
  • JSON-file persistence suitable for a Docker volume

Core workflow

  1. Traffic lands on the evergreen bridge page.
  2. Visitors click Get Started.
  3. /start reads the active sponsor from the server and builds the RM Circle referral link dynamically.
  4. In /admin, increment a sponsor's direct count as joins are verified.
  5. When a sponsor reaches 2, click Qualified.
  6. The next waiting sponsor becomes active immediately—no HTML or ad changes required.

Default seeded queue

The seed data reflects the working Crypto Team Build priority list at build time:

  1. ID 30 — Orlando (active)
  2. ID 36 — Mad Dog
  3. ID 35 — Michael Camire
  4. ID 32 — Melissa
  5. ID 34 — Janie

You can change, reorder, add, or delete sponsors in /admin.

Local run

cp .env.example .env
# edit .env and set a strong ADMIN_PASSWORD + SESSION_SECRET
set -a && . ./.env && set +a
npm start

Open:

  • http://localhost:3000/
  • http://localhost:3000/start
  • http://localhost:3000/admin

Docker / Coolify

This project includes a zero-dependency Node server, Dockerfile, and docker-compose.yml. No npm package download is required.

Coolify recommendation

  1. Create a new application from this source/repository.
  2. Use the Dockerfile or Compose deployment.
  3. Add environment variables:
    • ADMIN_PASSWORD — strong unique password
    • SESSION_SECRET — long random string
    • NODE_ENV=production
    • DATA_DIR=/app/data
  4. Persist /app/data using a volume.
  5. Point your domain/subdomain at port 3000 through Coolify's normal proxy/domain configuration.
  6. Open /admin, sign in, and verify the queue before sending traffic.

Sponsor referral URL

The default base is:

https://app.thermcircle.com?ref=

The app appends the current sponsor ID, for example:

https://app.thermcircle.com?ref=30

Change the base URL at any time in Admin → Public Page Settings without editing code.

Important operational behavior

The app intentionally does not auto-qualify sponsors based on clicks or blockchain activity. A team admin verifies the actual placement and clicks Qualified. This prevents an ad click or abandoned transaction from rotating the sponsor queue incorrectly.

Safety and compliance notes

The public pages include risk language, avoid guaranteed-income claims, and remind users never to disclose a MetaMask Secret Recovery Phrase. The onboarding page points to the official MetaMask website and identifies Polygon Mainnet as chain ID 137 with POL as the native gas token.

This app does not custody crypto, request wallet seed phrases, execute transactions, or store private keys.

S
Description
RM Circle Premium - evergreen bridge page + dynamic Crypto Team Build sponsor router
Readme 715 MiB
Languages
JavaScript 65.9%
HTML 33.9%
Shell 0.2%