18 Commits

Author SHA1 Message Date
Ben Senescu
ac7ebfe13a
Add Dub referral conversion tracking (leads + sales) (#531) 2026-08-25 21:49:08 -04:00
Ben Senescu
f048dc3bd1
fix(rank-tracking): drain due configs deterministically (clean-room alternative to #456) (#462) 2026-08-07 13:53:30 -04:00
Ben Senescu
c40a04459c
fix(billing): retry missing Autumn balance (#450) 2026-08-06 21:33:25 -04:00
Ben Senescu
7990c4db7f
fix(billing): confirm credit depletion before refusing chat turns (#407) 2026-07-20 18:36:02 -04:00
Ben Senescu
c11517908d
Handle billing KV failures and preserve Lighthouse start-page matching (#375) 2026-07-09 22:23:03 -04:00
Ben Senescu
7caaebbbac Shrink eager worker bundle: lazy boundaries at module seams + build-enforced guard (#366) 2026-07-07 21:47:42 -04:00
Ben Senescu
a337f0ac08 perf: bound Autumn retry window + cache customer existence off the hot path (#365) 2026-07-07 21:47:42 -04:00
Ben Senescu
3c7e704b4a
Triage active PostHog errors: validator noise, workflow output cap, Autumn retries, deploy-reset noise (#361) 2026-07-05 23:22:44 -04:00
Ben Senescu
4f17fe4942 Triage production log errors: audit crash, Autumn webhook FK, PostHog capture, auth rate-limit IP, log noise (#327) 2026-07-02 18:15:46 -04:00
Ben Senescu
0652f3a8a6
improve onboarding chat ux + migrated to DO
* Add onboarding agent v1 product spec

* Add onboarding agent implementation plan (Project Think)

* Update onboarding plan: chat + seed function (drop Think/Workflows)

* feat(onboarding): data + metering foundation, Project Context store, MCP tool

* feat(onboarding): site read + DataForSEO signal + OpenRouter strategy seed

* feat(onboarding): strategy + streaming chat UI with update_project_context tool

* fix(onboarding): address review — bound free runs, cap chat, share auth+error helpers, harden scrape

* fix(onboarding): use canonical keyword-locations list, not a separate country list

* Improve onboarding strategy chat

* feat(onboarding): refine upgrade rail UI + fact-checked copy

- Rebuild upgrade sidebar: drop the nested card so the rail itself is the
  container (header / plan / features / CTA / progress footer with dividers)
- Remove the 'Free preview' badge + headline pitch; header now reads
  'Previewing OpenSEO' with the site domain beneath
- Tighten copy against the fact sheet: fix monthly-vs-top-up credit wording,
  drop 'live' rank tracking, add money-back + open-source trust signals,
  unify CTAs to 'Upgrade to continue', cut cross-panel feature redundancy
- Replace off-strategy suggested question; add progress bar counter
- FORCE_FREE_PREVIEW flag to always show the preview/limit UI while testing

* feat(onboarding): add 'What do you recommend' strategy chip; revert suggested questions

- Add a highlighted suggestion chip that prompts Sam for the strategy, shown
  only when the user hasn't already used the welcome 'Show my strategy' CTA
- Track strategyRequested so the chip isn't re-offered after use
- Restore the original four suggested questions

* feat(onboarding): add OpenSEO Discord CTA + fact-sheet entry

- Discord link in the upgrade sidebar
- Fact-sheet community entry + system-prompt guidance so Sam can point
  users to the Discord for community/second-opinion help

* chore(merge-ready): round 1 fixes

- scrape.ts SSRF: validate the initial domain via audit/url-policy
  (normalizeAndValidateStartUrl) and re-validate each redirect hop with
  redirect:"manual" (one hop, blocked/private/metadata hosts + DoH rebinding).
  Replace the content-length-only guard with a bounded streaming read so
  chunked/CDN responses can't buffer past MAX_RESPONSE_BYTES. Remove the
  unguarded normalizeDomainToUrl helper. Add scrape.test.ts.
- http-errors.ts: map PAYMENT_REQUIRED AppError to HTTP 402 (was 500), so the
  onboarding chat paywall backstop surfaces correctly.
- OnboardingStrategyChat: replace the hardcoded FORCE_FREE_PREVIEW=true debug
  flag (which forced paid users into the free-preview/paywall UI) with a
  safe-by-default ?preview=1 URL override.
- onboardingStrategy.ts: delete the dead generateOnboardingStrategy export
  (knip) and its now-unused imports; the chat tool path uses runOnboardingSeed.
- chat.ts: rename inner runOnboardingSeed result to fix no-shadow.
- Extract presentational chat sub-components into OnboardingStrategyChatParts
  to satisfy max-lines; reformat Markdown.tsx for prettier.

* chore(merge-ready): round 2 fixes

- chat.ts: validate message role in schema + count total messages (not just user-role) so the free-question gate can't be bypassed with mislabelled roles
- OnboardingStrategyChat.tsx: surface useChat error state with a paywall-aware notice; branch 'Ask about OpenSEO' message text on isPaid
- OnboardingStrategyChatParts.tsx: guard free-preview welcome copy behind !isPaid (paid variant for subscribers)
- onboardingStrategy.ts: reset onboardingRunStatus/onboardingRunAt when the domain changes so a corrected domain can get a fresh free seed

* chore(merge-ready): round 3 fixes

- onboarding chat: count only user-role messages for free-question paywall to match client gate (was counting all messages, firing ~3 turns early)
- ProjectContextStore: drop unused return value/type from saveProjectContextVersion, inline latest-version query into getCurrentProjectContextMarkdown, remove dead toVersion helper and ProjectContextVersion type
- onboarding chat UI: replace 'Why is OpenSEO better than Claude?' suggested chip with 'How does OpenSEO work with Claude?' (Claude is an MCP client, not a competitor)

* feat(onboarding): route post-upgrade to GSC step; drop isPaid from preview chat

- Checkout successUrl now returns to /onboarding?step=3 (GSC connect) instead
  of the strategy chat, with a 'You're in!' success banner introducing the
  remaining GSC + MCP setup steps. Fixes the post-Stripe 'stuck on paywall'
  race since the user leaves the chat entirely.
- The strategy chat is now purely the pre-upgrade free preview: removed the
  managed-access query, the isPaid branching, and the ?preview override. The
  7-question cap always applies (kept as a conversion funnel).

* feat(onboarding): show post-upgrade success as its own step screen

Instead of a banner stacked above the GSC step, render a 'You're in!' screen
using the standard step layout (logo, title, card, Continue) in place of the
GSC step when ?checkout=success is present. Continue drops the param to reveal
the actual GSC step.

* refactor(nav): remove Project settings from account dropdown

Project settings is now reachable only via the project switcher's 'Manage
projects' → /projects → per-project settings. Drops the dead
projectSettingsLinkOptions helper and the now-unused AccountMenu projectId prop.

* refactor(onboarding): remove project-context persistence + MCP tool

Defers the Project Context store to a later PR to simplify this one.

- Delete ProjectContextStore, the get_project_context MCP tool (+ registration),
  the project_context_versions table (schema + migration 0024 + snapshot), and
  the update_project_context chat tool.
- generate_initial_strategy now returns the synthesized strategy to the chat
  without persisting it; claimRun still gates paid spend (one free run).
- Chat system prompt no longer injects saved context; it just grounds Sam with
  the project's domain.
- getOnboardingStrategyState returns only { projectId, domain }.
- Move the agent fact sheet out of docs/ (human docs) to
  src/server/features/onboarding/openseo-fact-sheet.md.

* refactor(routing): move /strategy to /onboarding/chat

Rename the onboarding strategy chat route from /strategy to /onboarding/chat.
_authenticated.onboarding.tsx becomes the index route; the chat is a sibling,
so TanStack auto-creates the shared /onboarding parent (Outlet).

* chore(onboarding): clean up leftovers from the persistence removal

- Drop the chat's onFinish=invalidateStrategyState refetch: now that the
  strategy state is just { projectId, domain } (no persisted markdown), the
  chat can't mutate it, so the post-turn refetch was dead work.
- Fix a stale 'Project Context' doc comment in synthesis.ts.
- Note in specs 0005/0006 that strategy persistence + the MCP read tool were
  deferred, so the docs don't contradict the shipped code.

* feat(onboarding): meter LLM (OpenRouter) spend via Autumn track_tokens

Mirror the DataForSEO metering pattern for LLM cost: a best-effort
trackLlmUsage helper emits a PostHog usage event and records token usage on
Autumn's token-tracking endpoint (REST; not in the autumn-js SDK yet), priced
from the model slug. Wired into the chat stream (onFinish) and the strategy
synthesis call. getOnboardingModel now also returns the resolved model slug.

* feat(onboarding): step-styled site form + account menu on chat page

- Restyle the website/country form to match the onboarding step layout (logo,
  title, helper) and explain why we ask (read the site + pick the search market).
- Extract OnboardingAccountMenu to a shared component and render it on the
  onboarding chat page so signed-in users can reach account actions there too.

* fix(auth): keep verify-email on 'check your inbox' after email sign-up

The post-sign-up redirect always passes ?email=; key the waiting state off it
so a just-signed-up user sees check-your-inbox + resend instead of the sign-in
CTA the verification gate would immediately block, even while the session is
still resolving.

* fix(onboarding): meter total LLM usage across all stream steps

Review caught that streamText onFinish 'usage' is only the last step; with
stopWhen=4 + the strategy tool, multi-step runs under-metered. Use 'totalUsage'
and await the metering so it fires before the stream closes. Also drop the
in-flux cache/reasoning token fields (negligible here).

* feat(onboarding): adopt the 'chat with tools' architecture from agent-onboarding-2

Replace the deterministic seed + synthesis pipeline (and the
onboarding_run_status/run_at columns) with two on-demand tools Sam calls —
read_website and get_seo_metrics — and have Sam write the strategy itself
in-stream, so a mid-stream refresh re-runs cache-backed tools instead of
dead-ending on a 'complete' status. Rename OnboardingStrategy* -> OnboardingChat*.

Preserved from this branch: LLM metering (now via the chat onFinish totalUsage,
covering the in-stream strategy), the account menu on the chat page, the
verify-email fix, and the step-styled site form. Drop columns via migration 0025.

* docs(onboarding): correct spend-bound + stale synthesis comments

Clarify that get_seo_metrics spend is bounded by the question cap + one project
per un-upgraded account (not solely caching, which doesn't cover no-data sites),
and drop 'synthesis' from comments now that Sam writes the strategy in-stream.

* refactor(onboarding): metered LLM via Autumn AI-SDK adapter; drop skipBalanceAssert

Now that every org gets an onboarding_plan with usage credits, onboarding spend
draws down the normal balance — no bypass needed.

- LLM metering: use Autumn's official @useautumn/gateway adapter (withLlmMetering
  wraps the model; correct token-pool pricing for cached/reasoning tokens),
  replacing the hand-rolled onFinish/track_tokens REST plumbing. Point it at the
  existing 'llm_usage' feature (backed by usage_credits + topup_credits) rather
  than a to-be-created 'ai_credits' feature.
- DataForSEO: remove skipBalanceAssert end-to-end (chat metering object, the
  meter() plumbing in dataforseo/client.ts, and the DomainService override type);
  onboarding now asserts balance like every other caller. Kept the email-verified
  + Labs-location gate on get_seo_metrics as the anti-farming bound.

Co-authored with a parallel agent's LLM-metering refactor.

* docs(onboarding): fix stale metering comment + diverged-architecture specs

- DomainService MeteringOverrides comment no longer claims a balance-gate bypass
  (skipBalanceAssert + the onboarding seed are gone).
- specs 0005/0006: correct the update notes — the seed/synthesis pipeline,
  claimRun, and skipBalanceAssert were replaced by the chat-with-tools design;
  flag the bodies as the superseded plan.
- Document the pinned Autumn track_tokens API version.

* feat(onboarding): gate the chat turn on credit balance (LLM included)

Now that every org gets onboarding_plan trial credits and LLM tokens draw from
the same usage/topup balance, assert that balance before streaming — not just
track it. Extract the DataForSEO balance check into subscription.ts
(getUsageCreditsRemaining / assertUsageCreditsAvailable) and reuse it; the chat
throws a friendly PAYMENT_REQUIRED when credits are gone (client shows the
upgrade copy).

* feat(onboarding): make the strategy chat hosted-only

The chat needs the managed LLM + trial credits, so self-hosted has no business
there. Gate the step-2 navigation on hosted mode and add a beforeLoad redirect
on /onboarding/chat so self-hosted lands back in the wizard.

* feat(onboarding): site-form + welcome copy; drop open-source badge

- Site form: 'Tell us about your website.' title, short input labels, no extra
  helper descriptions.
- Welcome message: lead with the upgrade ask + a Discord/email escape hatch.
- Remove the 'Open source — self-host for free anytime' badge from the rail.

* fix(onboarding): show typing indicator during the submitted wait

showTyping gated on the last message lacking assistant text, but right after
send the last message is the user's own (which has text), so nothing showed
until the assistant message appeared. Show it whenever busy and the last
message isn't assistant-text-yet.

* refactor(onboarding): drop redundant email-verified gate on get_seo_metrics

The route guard already requires a verified email to reach the chat in hosted
mode, and the trial-credit balance bounds spend — so the in-tool emailVerified
check was redundant for real users and blocked local/bypass testing. Keep the
Labs-location check (functional).

* feat(billing): meter onboarding LLM spend into the shared credit pool

Both DataForSEO and onboarding-LLM now draw from the same usage_credits/
topup_credits pool via one helper, instead of LLM needing a separate Autumn
ai_credit_system.

- Extract trackUsageCreditSpend (markup -> credits -> monthly/topup split ->
  autumn.track + usage:credits_consume) into subscription.ts; DataForSEO's
  trackDataforseoCost now delegates to it (behavior unchanged, tests pass).
- Enable OpenRouter usage accounting; the chat onFinish sums the real per-step
  cost OpenRouter reports and deducts it through the same helper.
- Drop the @useautumn/gateway adapter, llm-metering.ts, track_tokens, and the
  AUTUMN_LLM_USAGE_FEATURE_ID constant — no ai_credit_system feature needed.

* feat(onboarding): persist the strategy chat in a Durable Object (AIChatAgent)

Move the onboarding chat from a stateless streamText route to an Agents SDK
AIChatAgent Durable Object, so the conversation persists (DO SQLite) and
survives reloads — one instance per project.

- OnboardingChatAgent.onChatMessage ports the system prompt, read_website +
  get_seo_metrics tools, the credit-balance/free-question gate, and the
  OpenRouter cost metering. Billing gates surface as a normal assistant message
  (staticAssistantResponse) rather than an HTTP 402.
- The Worker authorizes every /agents/* connection (resolve session + verify the
  caller's org owns the projectId) before it reaches the DO; the DO derives org
  /domain from the project it is named after. Auth stays on the proven path.
- Client swaps useChat -> useAgent + useAgentChat (WebSocket), keyed by projectId.
- Adds the DO binding + new_sqlite_classes migration; pins @cloudflare/ai-chat
  0.6.1 to match agents 0.12.3.

* chore(onboarding): bump agents+ai-chat to latest; fix review findings

- Bump agents 0.12.3 -> 0.15.0 and @cloudflare/ai-chat -> 0.8.4 (the supported
  pairing; verified MCP, the DO, and the build still compile).
- Thread the per-turn abortSignal into streamText so a user aborting mid-stream
  cancels the billable LLM call (was leaking sub-cent cost on abort).
- Ensure the org's Autumn customer exists in the Worker authorize step before
  the DO checks the credit balance, avoiding a false 'out of credits' gate on a
  brand-new org's first message.

* chore: remove stray reservation-booker-seo-report.html

* chore: drop stale @useautumn/gateway minimumReleaseAge exclusion

The package was removed when LLM metering moved to the shared credit pool.

* perf(onboarding): fetch get_seo_metrics signals in parallel; clarify question-cap

- get_seo_metrics now fetches the domain overview and ranked keywords
  concurrently instead of in series (faster tool turn). Trade-off: it always
  issues the metered ranked-keywords call now, including for no-ranking sites.
- Correct the FREE_ONBOARDING_QUESTION_LIMIT comment: the server re-check counts
  client-supplied history, so the cap is a conversion nudge, not a security
  boundary — the credit balance is the real spend bound.
2026-06-19 18:09:52 -04:00
Ben Senescu
9abed9278f
Remove free trial: subscription paywall + 30-day money-back guarantee (#251) 2026-06-14 21:21:04 -04:00
Ben Senescu
dd429ec4f0
Sync Autumn billing status to Loops and add billing backfill (#269) 2026-06-14 17:19:26 -04:00
Ben Senescu
96f365a473
billing: Autumn webhook + customer status sync (#239) 2026-06-04 23:04:55 -04:00
Ben Senescu
86d3714846
feat: allow free plan users to set up rank tracking (#116) 2026-04-16 02:19:23 -04:00
Ben Senescu
1d9a503335
hosted: add free trial plan and onboarding (#104) 2026-04-08 19:06:35 -04:00
Ben Senescu
ad3b732f60 hosted: add product analytics (#83)
* track core product analytics flows

Track auth, search, export, audit, and credit-consumption events with canonical route IDs so PostHog funnels and usage dashboards stay low-noise and privacy-safe.

* fix: keep auth actions usable after session loss

* refactor: simplify analytics and auth helpers

- Replace isRecord/getActiveOrganizationId type guards with simple cast
- Refactor getAnalyticsRouteContext from if/return chain to route tables
- Replace toVerificationIssueType switch with zod enum
- Merge duplicate credits_consume events into single event per API call
- Merge two PostHogBootstrap useEffects into one

* refactor: add projectId to middleware context to reduce boilerplate

The requireProjectContext middleware now includes projectId directly,
eliminating repeated manual construction of BillingCustomerContext
objects across all server function handlers.

* remove unused BILLING_* env var fallbacks from cost profile script

* remove before_send event enrichment to preserve native PostHog URL tracking

The before_send hook was stripping $pathname, $current_url, $referrer and
other URL properties, which breaks PostHog web analytics dashboards, paths
analysis, session replay, and attribution. The route_id/route_group injection
it provided is unnecessary since PostHog already captures $pathname natively.

* remove route mapping layer, pass raw redirect paths to analytics events

The route ID registry (STATIC_ROUTES, PROJECT_ROUTES, getAnalyticsRouteContext,
getRedirectRouteId) duplicated what PostHog already captures via $pathname.
Replace redirect_route_id with redirect_to containing the raw path, and remove
~80 lines of route mapping infrastructure.

* clean up analytics events: drop redundant submit events and derived properties

- Remove search_submit events for keywords, domain overview, and backlinks
  (the search_complete events capture the meaningful outcome data)
- Remove target_type from backlinks events (derived 1:1 from search_scope)
- Remove result_limit from keyword research (requested limit, not useful
  alongside actual result_count)
- Remove export_format from data:export events (always "csv")

* refactor: inline wrappers, colocate helpers, deduplicate getActiveOrganizationId

- Inline toVerificationIssueType into verify-email.tsx (single-use wrapper)
- Move mapDataforseoPathToCreditFeature into dataforseoClient.ts (only consumer)
- Extract shared getActiveOrganizationId into lib/auth-session.ts (was
  duplicated in __root.tsx and middleware/ensure-user/hosted.ts)
- Rename shared/analytics.ts → shared/internal-user.ts (only email helpers
  remain after removing route mapping, verification, and dataforseo helpers)

* remove internal user tracking and email domain properties

Drop is_internal_user super property, email_domain person property, and all
supporting code (shared/internal-user.ts, getEmailDomain, isInternalUserEmail).
Simplifies initPostHog and identifyAnalyticsUser signatures.

* remove backlinks:search_complete effect-based tracking

The reactive useEffect + useRef dedup pattern added ~30 lines of plumbing
inside a data hook for a single analytics event. Not worth the complexity.

* simplify: replace manual type guards with zod, deduplicate posthog and sign-out helpers

- Replace hand-rolled typeof checks in getActiveOrganizationId and
  isAuthenticatedServerFunctionContext with zod safeParse
- Extract withPostHogClient helper to deduplicate client posthog wrapper
- Move apiKey guard into getServerPostHogClient factory
- Extract signOutAndRedirect to avoid duplicated sign-out logic
- Drop derivable has_results from analytics events
- Remove unnecessary path normalization in mapDataforseoPathToCreditFeature

* fix: strip email from pageview URLs, restore sign-out guard, harden server posthog, fix path mapper

- Sanitize $current_url on pageviews to remove email query param (PII)
- Restore onSuccess for sign-out redirect to avoid bounce-back on failure
- Swallow shutdown() errors so PostHog outages can't fail billed work
- Rewrite mapDataforseoPathToCreditFeature to match real API path structure
  (path[1] = module, path[3] = endpoint) instead of scanning all segments

* simplify: remove redundant refs in verify-email, infer middleware context type

- Remove unnecessary useRef guards in verify-email effects (deps already prevent re-firing)
- Use z.ZodType<EnsuredUserContext> annotation to infer return type instead of casting
- Add comment explaining one-shot PostHog client on Workers

* fix: reset PostHog identity on sign-out before redirect

* fix: require POSTHOG_HOST env var instead of defaulting to us.i.posthog.com

* fix: annotate url as unknown to satisfy no-unsafe-assignment

* format
2026-04-08 14:09:02 -04:00
Ben Senescu
724a92db0c refactor: move hosted billing to Autumn hooks (#48)
* refactor: move lighthouse audits to dataforseo (#43)

* refactor: move lighthouse audits to dataforseo

* chore: remove obsolete audit settings modal

* refactor: rename psi flows to lighthouse

* save

* refactor: simplify audit lighthouse storage flow

* fix: separate lighthouse metrics from actionable audits

* refactor: remove redundant audit project inputs

* feat: redesign lighthouse issues screen with score gauges and table layout

Replace flat score cards with circular SVG gauges, condense metrics into
a compact grid, and switch issue list from cards to an expandable table
with fixed column widths.


* test: harden lighthouse regression coverage

* fix: restore project-scoped audit inputs

* refactor: simplify lighthouse payload handling

* refactor: inline lighthouse server handlers

* refactor: share audit workflow types

* refactor: simplify lighthouse payload flows

* save

* refactor: drop project pagespeed api key

* fix: restore lighthouse issues loading with resilient project context

* fix: restore audit issues back navigation

* refactor: simplify project context and lighthouse error handling

* fix: tolerate DataForSEO lighthouse payload drift

* refactor: route audit lighthouse through dataforseo client

---------


* refactor: move hosted billing to Autumn hooks

* fix: satisfy ci checks for hosted billing

* refactor: simplify hosted Autumn billing integration

Limit Autumn wiring to the billing route and remove billing-specific indirection so the hosted billing flow is easier to reason about. Stop sending organization IDs as fake customer names to keep customer identity data honest.

* fix: satisfy ci line-limit check for hosted billing

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 22:28:28 -04:00
Ben Senescu
739b3f0b6a
Add autumn metered pricing for hosted mode (#44)
* feat: add hosted billing gate and backlinks metering

* refine hosted billing onboarding flow

* fix: align Autumn credit billing flows

* refactor: simplify Autumn billing flow

* refactor: narrow backlinks billing context

* refactor: require billing identity for backlinks profiles

* refactor: colocate backlinks billing flow

* clean

* refactor: centralize DataForSEO billing client

* refactor: simplify dataforseo billing flow

* chore: fix ci check lint issues

* fix: stabilize backlinks chart sizing

Measure chart container width before rendering the backlinks charts so Recharts does not mount at 0x0 inside responsive layouts.

* docs: document hosted DataForSEO metering

Capture the Autumn credit model and require hosted code to go through the metered client path so provider usage is harder to bypass.

* fix: enforce hosted billing access checks

* fix: preserve hosted billing subscription access

* fix: handle hosted billing UI failures
2026-03-25 13:02:12 -04:00