v0.9.12 - Data Integrity & Error Handling
2026-01-04 22:45 - Error Handling Enhancement
Fixed: Supabase error detection on callback page - Users stuck on "Welcome! Wait..." message
- Added error detection BEFORE token extraction in callback handler
- Parse Supabase errors from URL hash (
#error=otp_expired, etc.) - Show user-friendly error messages with specific instructions
- Provide "Return to form" button with link to
registration_url - Handles common errors:
otp_expired- "Link expired, request new one"otp_disabled- "Email login unavailable, use Google/Facebook"access_denied- "Access denied, contact support"- Generic errors - Show Supabase error description
Error message format:
⚠️ [Specific error message]
Чтобы войти снова, перейдите к форме входа:
[Перейти к форме входа] → {registration_url}
2026-01-04 14:30 - Critical Infrastructure Changes
CRITICAL: SMTP Provider Migration - Migrated from Supabase SMTP to Amazon SES
- Root cause: Supabase built-in SMTP hit rate limits during high traffic (European morning registrations)
- Impact: Magic Link emails stopped sending, blocking new user registrations
- Solution: Migrated to Amazon SES (Simple Email Service)
- Implementation:
- Created AWS account and configured SES
- Verified domain ownership (DKIM, SPF records)
- Updated Supabase Dashboard → Authentication → SMTP Settings
- Tested email delivery at scale
- IMPORTANT: Supabase SMTP is ONLY for MVP/testing. Production REQUIRES external SMTP provider.
- Recommended providers: Amazon SES (used here), SendGrid, Mailgun, Postmark
2026-01-04 10:15 - Data Integrity Fixes
Fixed: Magic Link cross-device registration URL loss - ~46% of Magic Link registrations losing pair_id
- Root cause: OAuth redirects lose localStorage when user opens email on different device/browser
- Solution: Pass
registration_urlvia URL query parameter in Magic Link emails - Modified
auth-form.htmlto include registration_url inemailRedirectTocallback URL - Modified callback page (
test-no-elem-2-wordpress-paste.html) to read from URL param with localStorage fallback - Priority-based detection: URL param → localStorage → current page path
- Fixes ~46% data loss in marketing analytics
Fixed: Registration pair sync bug - WordPress pairs not syncing to Supabase
- Added missing
sb_sync_pair_to_supabase()call insb_ajax_save_pair() - Added missing
sb_delete_pair_from_supabase()call insb_ajax_delete_pair() - Registration pairs now properly sync from WordPress to Supabase table
Added
- Data Integrity Monitoring System - Local bash script for verifying registration tracking
monitoring/check-integrity.sh- Compares auth.users vs wp_user_registrations- Checks for lost registrations (not tracked in analytics)
- Checks for missing landing page attribution (pair_id = NULL)
- Configurable time period (default: 1 hour, supports custom periods)
- Exit code 0 = all checks passed, exit code 1 = issues detected
- Safe read-only queries (no data modifications)
- Monitoring Documentation
monitoring/README.md- Complete setup and usage guidemonitoring/.env.example- Credential template with clear instructions- Scheduling examples for automated checks
- Security notes (credentials in .gitignore)
Changed
- Callback URL structure for Magic Link - Now includes registration_url parameter
- Old:
https://site.com/callback - New:
https://site.com/callback?registration_url=/landing-page/ - Backward compatible - falls back to localStorage if param missing
- Old:
- Credential management - Added Supabase section to
.production-credentials- Consolidated credential storage for monitoring scripts
- Already in .gitignore for security
Testing
- Verified 100% pair_id tracking accuracy after fix (SQL queries on production data)
- Tested Magic Link cross-device flow (PC → mobile email → callback)
- Tested registration pair sync (WordPress → Supabase)
- All registration methods working: Google OAuth, Facebook OAuth, Magic Link
Results
- 100% registration tracking accuracy (no more NULL pair_ids)
- Cross-device Magic Link authentication fully working
- Real-time data integrity monitoring capability
- No lost registrations for marketing attribution