NETEROU AD NETWORK · RELEASE CANDIDATE 0.2.0-rc.4 · 26 SEPTEMBER 2026

Installation & operations

Evaluation release, not a certified commercial release. The source and local checks are provided for evaluation. Real provider testing, commercial terms, support commitments and marketplace eligibility must be completed before commercial launch. Nothing in this document represents CodeCanyon approval.

1. What this package contains

A TypeScript/React advertising application with advertiser, publisher and administrator workspaces. It runs on Cloudflare Workers, uses Cloudflare D1 for application records and R2 for creative files. Supabase Auth handles customer and standalone administrator authentication. Stripe Checkout and Connect integrations are included but disabled until configured and tested.

This is not a PHP script or a generic cPanel/MySQL application. A Node server alone does not provide the Cloudflare bindings this application needs. The independent package does not require the seller’s ChatGPT account.

RequirementDetails
Build environmentNode.js 22.13 or newer; pnpm 11.25.0; internet access to the package registry.
RuntimeCloudflare account with Workers, one D1 database and one private R2 bucket. Domain with HTTPS.
AuthenticationYour own Supabase project. Configure email verification and production SMTP, or separately configure Google/Microsoft OAuth.
PaymentsYour own Stripe account eligible for the required Connect model in your operating country. Provider fees and availability are separate.
CostsHosting, storage, database reads/writes, authentication, email, domain and payment processing are paid directly to the providers. No unlimited traffic or cost promise is included.

2. Install a clean instance

Extract the package. The application/ folder contains editable source, migrations and tests. It contains no customer database, account passwords, payment keys or seller news content.

Install dependencies

cd application
corepack prepare pnpm@11.25.0 --activate
corepack pnpm install --frozen-lockfile

If pnpm is not on your PATH, prefix all commands below with corepack, for example corepack pnpm run build. corepack enable is optional and may fail on systems without permission to modify global executable links; administrator privileges are not needed when using corepack pnpm. Install Corepack separately if your Node distribution does not include it.

Use the included lockfile. Do not silently upgrade the framework: this release uses Vinext 1.0.0-beta.5 and Next-compatible APIs. Verify a future upgrade in staging first.

Create your resources

Sign in to Cloudflare using Wrangler. Create a D1 database and an R2 bucket in your own account. Keep the bucket private; the application serves uploaded creatives.

pnpm exec wrangler login
pnpm exec wrangler d1 create advertising-network-db
pnpm exec wrangler r2 bucket create advertising-network-assets

Copy installation.example.json to installation.json. Enter the actual D1 ID, resource names, HTTPS origin, administrator email, Supabase project URL and publishable key. Optional fields: brand_name, company, support_email. Never enter a service-role key in the publishable-key field.

node scripts/configure-installation.mjs installation.json
pnpm run build
pnpm exec wrangler d1 migrations apply DB --local --config wrangler.install.json
pnpm exec wrangler dev --local --config wrangler.install.json

For a local smoke test without provider credentials, run node scripts/configure-installation.mjs installation.example.json --local, then the build, local migration and local server commands above. This disables authentication, registration, payments and ad serving; it does not validate those services. The Wrangler --local option uses local resources. Production configuration requires a valid administrator email and public Supabase key. Origins must not contain credentials, paths, queries or fragments. The installer rejects secret/service-role keys and user tokens; it does not verify public-key validity with the provider. Back up wrangler.install.json before rerunning the installer because it regenerates defaults and resets manually edited flags.

Prepare a real staging deployment

pnpm exec wrangler d1 migrations apply DB --remote --config wrangler.install.json
pnpm exec wrangler secret put TRACKING_SECRET --config wrangler.install.json
pnpm exec wrangler deploy --config wrangler.install.json

Use a unique cryptographically random tracking secret of at least 32 bytes. Enter secrets only through Wrangler or the provider’s secrets interface. Never commit or share .dev.vars, real installation files, backups or credentials.

Attach your domain using Cloudflare. Set Supabase Site URL and the allowed redirect URL to your exact HTTPS origin and /auth/retour. Configure production email delivery before enabling email sign-in. Keep staging and production databases, buckets, Auth projects and Stripe modes separate.

3. Initialize the administrator

Standalone mode uses AUTH_ADMIN_PROVIDER=supabase; it rejects ChatGPT identity headers. The ordinary registration form cannot assign admin privileges.

  1. Create and verify the intended administrator identity in your Supabase Auth project. The email must match ADMIN_EMAIL exactly, ignoring case.
  2. Temporarily change ALLOW_ADMIN_BOOTSTRAP to true in the private runtime configuration and redeploy.
  3. Sign in on your application, visit /admin and click the initialization button. Do this before completing ordinary customer onboarding for that account.
  4. Set ALLOW_ADMIN_BOOTSTRAP=false and redeploy. The database also records completion and prevents a second bootstrap.
  5. Review the company settings and legal documents. Only then enable customer registration with REGISTRATION_ENABLED=true and a nonempty TERMS_VERSION.

Google and Microsoft are separate optional providers, each disabled by default. Configure the OAuth application in the provider and Supabase first. Microsoft requests the email scope. Verify logout, email confirmation, expired links and recovery in your actual environment.

Brand settings change the main logo text, company footer and contact address. Replace the favicon and review editorial/contract text, public page titles and branding inside the embed scripts before advertising a fully white-label installation.

4. Configure and validate payments

Do not enable live payments based solely on the local tests. Test with your own Stripe sandbox and account capabilities first.

Set STRIPE_SECRET_KEY to your test key and STRIPE_WEBHOOK_SECRET to the secret for your application endpoint. Keep PAYMENTS_LIVE_ENABLED=false. Register https://YOUR-DOMAIN/api/webhooks/stripe for these events:

Only signed, recent webhooks in the correct mode and currency can credit a matching pending top-up. The same top-up cannot credit twice. Returning to a success URL does not credit the wallet.

Accounting uses integer millionths of EUR. Checkout top-ups are between €10 and €10,000. Stripe receives integer cents. CPC charges a qualified click; CPM charges a qualified impression using the per-thousand bid. Publishers receive the configured share. The minimum payout defaults to €50, with a 30-day validation period.

Publishers complete Stripe Connect onboarding. The administrator checks a payout before transfer. A pending request may be rejected with a reason; the reserved earnings are released once. Processing transfers require reconciliation and cannot be rejected through that action. A transfer to a Stripe account is not proof of arrival in the beneficiary’s bank account.

Refunds and disputes freeze the affected account for manual reconciliation. Automated proportional reversals, tax accounting and full dispute workflows are not implemented. Do not present the ledger as a complete accounting or tax system.

Required provider acceptance tests

  1. Successful and declined card, cancellation and expired checkout.
  2. Repeated webhook, delayed webhook, wrong amount, wrong currency and wrong mode.
  3. Connect onboarding completed and incomplete; blocked beneficiary.
  4. Payout rejection, duplicate approval, insufficient platform balance and provider timeout.
  5. Refund and dispute, followed by documented manual reconciliation.

Use fresh live credentials only after these checks and the operator’s commercial requirements are complete. The live flag and webhook mode must agree.

5. Use the advertising workspaces

Advertiser

Create a campaign, choose display/native/video and CPC/CPM, add an HTTPS destination, upload a permitted creative, configure total and daily budgets, bid, category, country codes, device and optional dates. Frequency limiting is per hashed connection IP per UTC day, not a unique-person measurement. Zero disables the cap. Editing a campaign sends it back to draft for review.

Publisher

Add a site and copy the generated TXT record to _neterou.YOUR-DOMAIN. Use Verify after DNS propagation. The administrator must separately approve the site. Create placements and copy the supplied embed. Native blocks support grid dimensions; display dimensions must match the creative. Uploaded MP4/WebM videos use user-initiated playback; this is not VAST.

Consent and measurement

<div data-neterou="YOUR_PLACEMENT_ID"></div>
<script async src="https://YOUR-DOMAIN/neterou.js"></script>

// Only after your visitor has given the required consent:
window.neterouConsent = true;
window.dispatchEvent(new Event('neterou:consent'));

// Withdrawal:
window.neterouConsent = false;
window.dispatchEvent(new Event('neterou:consent'));

The operator must connect this signal to a real consent manager. It is not an IAB TCF-certified CMP. Measurement uses a visibility threshold and signed expiring tickets, with duplicate handling and basic automated-traffic filtering. It is not independently certified fraud protection or viewability measurement.

Reports and support

Reports use UTC and EUR and offer 7, 30 or 90 days. CSV downloads are generated server-side with ownership checks. The report API also supports grouping by campaign or placement. Large reports fail explicitly above 10,000 aggregate rows. Campaigns, sites, placements, support tickets, accounts, financial history, pending payouts and audit entries are paginated in batches of 25. Search and status filters run before pagination and retain account ownership checks. The overview keeps a bounded recent snapshot, while its aggregate entity counters are calculated on the full permitted dataset. CSV reports retain their separate 10,000-row aggregate limit. Support provides tickets and one editable administrator reply, not a threaded helpdesk or outbound email notification system.

6. Demonstration mode

Run the demonstration as a separate deployment with DEMO_MODE=true, no production secrets, no Auth connection and no production database. It offers advertiser, publisher and administrator views using fictional records stored in the browser tab. The demonstration defaults to English, with French and Spanish available in the language selector. An explicit language choice is remembered; the default-language action restores English. Reset removes this tab’s demonstration state. It expires after one hour of inactivity or disappears when the tab session ends.

Payments, DNS verification and traffic statistics are simulated. Demo images are limited to 500 KB; video upload and external integrations must be tested in staging. No demo data is automatically imported into a buyer’s application database. Never use real customer or financial information in the demonstration.

Appearance and branding

Open Administration → Settings → Appearance and branding. Choose primary and secondary colors, import your logo and browser-tab icon, and use Preview theme before Save theme. Discard changes restores the saved theme. Restore original theme is a preview until you save it.

The primary color drives action buttons, links and brand accents; the secondary color appears in navigation and dashboard accents. Button text switches between black and white to maintain at least 4.5:1 contrast on its solid background. Links and focus indicators use adjusted shades for their backgrounds. This is not a complete accessibility certification; check your uploaded logo and all final content.

PNG, JPG and WebP inputs up to 5 MB are converted locally to PNG. The logo is fitted within 600 × 180 pixels and the favicon within a transparent 64 × 64 square. Converted images must stay below 500 KB. SVG and remote image URLs are not accepted. Images are stored in your own R2 bucket with D1 asset metadata. Previously uploaded files are retained when the theme changes or resets; include them in storage retention and backup policies.

Only an active administrator can persist the network theme. Changes are recorded in the audit log and appear on public pages and all three workspaces after navigation or refresh. Other already-open browsers refresh to receive the new saved theme. Brand colors do not recolor uploaded creatives, photos, or fixed third-party artwork. Company/name/domain settings and remaining editorial mentions are separate from the visual theme.

In demonstration mode, changes remain private to the current tab. They survive reloads within that tab until the demonstration expires or is reset. No shared database or production storage is written. The supplied download starts with the original theme and no uploaded brand images.

7. Maintenance, backups and updates

Use the administrator’s operational check to flag negative balances, exceeded budgets and transfers awaiting reconciliation. Review Cloudflare Worker errors and Stripe webhook failures. This check does not replace monitoring, database backups or financial reconciliation.

pnpm exec wrangler d1 export DB --remote --config wrangler.install.json --output backup.sql

A local export/import recovery test is included: node tests/backup-restore.mjs. It creates two isolated local D1 databases with fictional records, exports one and imports into the other, then compares balances, ownership, ledger and audit and runs foreign-key and quick consistency checks. It never accesses production. This does not validate remote recovery or R2 object backups.

Protect exported databases as confidential. Configure backup retention and R2 object backups in your own account. Test restoration into a separate D1 database and bucket before relying on backups. Preserve financial records required by your jurisdiction; no blanket deletion job is enabled by this release.

Before updating: back up database, objects, configuration and current release; install dependencies from the new lockfile; run tests and build in staging; apply pending migrations once; verify roles and payment flows; deploy. Keep the previous build for rollback. A database migration may require a forward repair rather than a code rollback.

Local acceptance checks

pnpm test
node tests/premium-routes.mjs
node tests/record-pagination.mjs
node tests/theme-settings.mjs
node tests/buyer-journey.mjs
node tests/backup-restore.mjs
node tests/d1-accounting.mjs
node tests/auth-rate-limit.mjs
python3 tests/test_accounting.py

The buyer-journey test exercises actual API handlers with local D1 and R2: upload, campaign/site/placement moderation, signed tracking, wallet and publisher accounting, reports, payout hold, failed transfer retry and duplicate prevention. Supabase identity, DNS and Stripe responses are simulated. It also copies a synthetic creative to a second local R2 bucket and verifies bytes and MIME metadata. This is not remote recovery or a real provider acceptance test.

The pagination test covers more than 1,000 rows, identical timestamps, concurrent insertion and cross-account access. Python 3 is needed only for the SQL test command.

Troubleshooting

SymptomCheck
Cannot sign inAuth flags, exact Supabase URL/key, redirect allowlist, verified email, SMTP/OAuth setup and browser cookies.
403 on adminAccount role/status, configured admin identity and bootstrap state. Do not bypass ownership checks.
No advertisementsDelivery flag, consent, approved site, exact hostname, active placement/campaign, creative size, targeting, funds, daily/total budgets, frequency and bot filtering.
No wallet creditWebhook signature, mode, currency, matching ledger entry and Stripe event delivery. Never manually replay a credit SQL statement.
Payout pending30-day hold, earnings, minimum, Connect capabilities, available platform funds and existing processing transfers.
Reports emptyUTC range, selected workspace and qualified recorded events. Demo statistics are separate.

8. Release gates and explicit exclusions

Included code has local automated tests. This does not prove production readiness at arbitrary traffic levels. Before commercial sale: complete independent installation with real services; provider testing; security review; backup restore; browser coverage including Safari/Firefox and physical mobile devices; load testing against a declared capacity; full license provenance review; final commercial/privacy policies; and a support/update policy.

Not included as complete capabilities: RTB/OpenRTB, SSP/DSP connections, VAST/VPAID, HTML5 ZIP creatives, conversion attribution, retargeting audiences, multi-currency wallets, automated tax calculation, automatic refund allocation, multi-level staff roles, mandatory administrator MFA, threaded support, transactional business notifications, automatic privacy export/deletion and enterprise fraud certification.

The technical scope is a direct advertising-network foundation. Do not advertise excluded features. The current source is a release candidate, and its use of a beta framework must be disclosed.

9. Licenses and marketplace submission

See THIRD_PARTY_LICENSES.json and licenses/ for the dependency inventory and available license texts. Dependency licenses are not a blanket clearance of all source and assets. Review notices and upstream redistribution rights before distributing this item. Provider brands do not imply affiliation.

The seller’s live data, private credentials, source-control history and news catalog are excluded. The sample banner is a simple demonstration asset. No stock-photo collection is bundled.

CodeCanyon requires English HTML/PDF help and publicly accessible documentation. The submission category, presentation, rights, author eligibility and AI-generated-content policy must be resolved by the seller. As checked on 26 September 2026, new author applications are paused and Code is not an invitation category. Existing Code authors can continue under their account permissions; verify the actual account before preparing an upload. Envato restricts AI-generated content sold as a standalone item or its main component. The provenance and eligibility of this AI-assisted code must be resolved with Envato before claiming it is eligible. No Envato acceptance is claimed.

Official references checked on 26 September 2026

Document status: evaluation documentation, v0.2.0-rc.4. No production secret is required to read it.