Skip to content

CrawlProof Alerts — free ValueSERP email alerts (Phase 1) - #72

Merged
ralyodio merged 1 commit into
masterfrom
feat/crawlproof-alerts
Jul 4, 2026
Merged

ralyodio merged 1 commit into
masterfrom
feat/crawlproof-alerts

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 4, 2026

Copy link
Copy Markdown
Contributor

Builds CrawlProof Alerts (PRD: docs/crawlproof-alerts-prd.md): free, near-realtime email alerts for anything Google can see, powered by ValueSERP, with the existing crawler used to confirm backlinks. Extends the product from a one-time audit into recurring engagement.

Core loop

email + category → magic-link (double opt-in) → scheduled ValueSERP poll (recency-filtered) → dedupe by canonical URL → only never-seen URLs email → backlink candidates crawl-confirmed before alerting.

Reuses the app's pg_cron → /api/cron/<job> → worker pattern, the audit crawler (fetchPage/attachRendered), Resend, and the profiles plan model.

Six fixes folded in over the v1 draft

  1. Economics — per-account monthly SERP-call budget (consume_alert_serp_budget) as the real cost backstop, not just a 50-alert count. A maxed free user is 10–20× the $0.15 ceiling otherwise; F5Bot's free-API story doesn't transfer to paid SERP.
  2. Cold-start — an alert's first poll seeds the dedupe set silently (no email/crawl); value on creation comes from the instant test run (promoted to P0).
  3. Email batching — one digest per user, not one email per alert (50 alerts × daily ⇒ up to 50 emails/day otherwise).
  4. Canonical dedupe — documented as normalized-URL (SERP gives no canonical tag; per-result crawl would be required).
  5. Backlink framing — "newly-indexed pages that mention + link the domain," not a full backlink crawler.
  6. Trust & safety — people-tracking templates (name/reputation/impersonation/legal) gated out of the launch picker pending T&S/GDPR.

What's here

  • Migration supabase/migrations/20260704120000_alerts.sql: alerts, alert_seen_urls, alert_findings, profile budget columns, budget RPC, crawlproof-alert-checks pg_cron job + global kill-switch (cron_config.alerts_enabled).
  • Engine lib/alerts/*: categories/compile, ValueSERP client, canonical dedupe, backlink confirm (+ JS-render fallback), poll+dedupe engine, batched digest, signed pause/unsubscribe tokens, limits/budgets, abuse validation, worker processing.
  • Routes/UI: cron route, pause/unsubscribe handlers, server actions, /alerts dashboard, public /get-alerts signup, worker /alerts/check-user.
  • Tests: 26 cases (dedupe, template compile, backlink anchor detection, abuse validation). App + worker tsc --noEmit clean.

Deploy config

Set VALUESERP_API_KEY, ALERTS_FROM (warmed subdomain); seed cron_config (site_url, cron_secret). alerts_enabled=false halts all SERP spend.

Still open (per PRD §11)

Paid pricing must clear hourly SERP COGS (~$108–$180/mo @ 250 alerts); ValueSERP plan limits; Legal/T&S before un-gating people-tracking. next lint is broken repo-wide in Next 16 (pre-existing), so lint wasn't run; typecheck + tests are the gate.

🤖 Generated with Claude Code

Extends CrawlProof from one-time audits into a recurring-engagement
product: free, near-realtime email alerts for anything Google can see,
with the existing crawler used to confirm backlinks.

Core loop: email + category → magic-link (double opt-in) → scheduled
ValueSERP poll (recency-filtered) → dedupe by canonical URL → only
never-seen URLs email → backlinks crawl-confirmed before alerting.

Reuses the app's pg_cron → /api/cron → worker pattern, the audit
crawler (fetchPage/attachRendered), Resend, and the profiles plan model.

Incorporates six pre-launch fixes over the v1 draft:
- Per-account monthly SERP-call budget as the real cost backstop, not
  just a 50-alert count (a maxed free user is 10-20x the $0.15 ceiling
  otherwise; F5Bot's free-API economics don't transfer to paid SERP).
- Cold-start: an alert's first poll seeds the dedupe set silently;
  value on creation comes from the instant test run (promoted to P0).
- One batched digest per user, not one email per alert.
- Canonical dedupe documented as normalized-URL (no per-result crawl).
- Backlink category framed honestly (newly-indexed linking pages).
- People-tracking templates gated out of the launch picker pending T&S.

Migration: alerts / alert_seen_urls / alert_findings, profile budget
columns, consume_alert_serp_budget RPC, alert-checks pg_cron job.
Tests: 26 cases (dedupe, template compile, backlink anchor detection,
abuse validation). App + worker tsc clean.

Revised PRD: docs/crawlproof-alerts-prd.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 4, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio marked this pull request as ready for review July 4, 2026 19:58
@ralyodio
ralyodio merged commit f45c5cb into master Jul 4, 2026
8 checks passed
@ralyodio
ralyodio deleted the feat/crawlproof-alerts branch July 4, 2026 19:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant