# BloodLink: free deployment and installation

Public website: https://bloodlink-village.salmannayab.chatgpt.site
Village: Chak 13/1AL
Join code: CHAK13-1AL (membership still requires approval)

## Use it now
The website is published publicly. Open /install on Android or iPhone and add it to the Home Screen. This PWA is the no-store-fee option and shares the same Supabase records across devices.

## Independent free hosting: Cloudflare Pages
The project produces a static website; its backend remains Supabase. Keep both services on their Free plans and do not enable paid add-ons.
1. Build the site with the existing package manager: `pnpm install --frozen-lockfile`, then `pnpm build`.
2. Upload the CONTENTS of `dist/client` to a new Cloudflare Pages Direct Upload project. Alternatively connect a Git repository with build command `pnpm build` and output directory `dist/client`.
3. Use the free `pages.dev` address. A purchased custom domain is not required.
4. The web app uses its current HTTPS origin for authentication redirects; no code edit is needed for the pages.dev address. Native builds still need verified deep-link handling.
5. In Supabase > Authentication > URL Configuration set Site URL to that same HTTPS address and add that exact root URL to Redirect URLs.
6. Test registration, email confirmation, reset-password, membership approval and two-device updates before inviting the village.

Free quotas are finite. Supabase Free currently includes a 500 MB database and 50,000 monthly active users; quotas and idle-project behaviour may change. Your connected organization was verified as Free on 27 September 2026. Cloudflare Pages has a Free plan with 500 builds/month. No paid plan or custom domain was purchased for this work.

## Fix localhost confirmation links
Supabase Authentication > URL Configuration:
- Site URL: https://bloodlink-village.salmannayab.chatgpt.site
- Redirect URL: https://bloodlink-village.salmannayab.chatgpt.site
- Also allow the same root with a trailing slash if your email flow uses it.
Save changes, then request a NEW confirmation/reset email. Already-sent links can still contain localhost.
The existing public Site URL and exact redirect URL were saved successfully on 27 September 2026. Change these again if you move to a pages.dev address.

## Authentication email delivery
Supabase's default email sender is limited and restricted to authorized addresses; public rollout may need a custom SMTP service. SMTP configuration and email delivery have not been verified in this task. Choose a provider's free tier only after checking its verified-sender/domain requirements and daily limits. Never turn off verification merely to bypass delivery limits. Provider credentials must be supplied through a secure dashboard, never chat or frontend source.

## Native Android and iOS projects
`mobile/` contains a Capacitor wrapper around the same static web build. It is source, not an APK or IPA. Build and device testing are still required.
- Android: official Android Studio / Android SDK and required Java version are needed; build/sign an APK for direct distribution. Keep the signing key private and retain it for future updates.
- iOS: a Mac and Xcode are required. Apple free Personal Team deployment is temporary and is not general village distribution. App Store distribution normally requires paid Apple Developer membership (eligible organizations may qualify for a waiver).
- With zero budget, the Safari/Chrome home-screen PWA is the practical cross-platform release. No Apple/Google developer subscription was purchased.

## Sources checked
https://developers.cloudflare.com/pages/platform/limits/
https://supabase.com/pricing
https://supabase.com/docs/guides/auth/auth-smtp
https://developer.apple.com/help/account/basics/about-your-developer-account
https://capacitorjs.com/docs

## Keep the village online without a paid plan
No provider guarantees free hosting forever. Supabase Free projects with low activity over seven days may pause; check your dashboard and restore when needed. Keep regular private database exports and source backups. Never upload donor database exports to the public website. Cloudflare Pages free hosting and Supabase Free retain this app’s implemented database, roles and realtime features within their quotas. Custom SMTP may still be needed for public signup emails.

## Administrator and coordinators
Sign into the app as israrcsc5@gmail.com and open Admin panel. Under Member approvals approve a neighbour, then under Coordinators choose Appoint coordinator. At most three are permitted; remove a coordinator role before replacing them. Database rules prevent coordinators from appointing others, changing another coordinator or changing the permanent admin. Infrastructure account owners can still administer the underlying database; permanence here means the application’s permissions.

## Birthdays
Full dates of birth are stored separately from the directory, visible to the donor and management team. Age is calculated using the date in Pakistan and returned only to the admin and coordinators. A personal birthday greeting appears when the donor opens the app on their birthday; there are no automatic WhatsApp, email or push birthday messages. Existing age-only records request DOB without inventing a date.

References:
https://developers.cloudflare.com/pages/get-started/direct-upload/
https://supabase.com/docs/guides/platform/free-project-pausing

## Final update: birthdays, units and colours
- Ordinary members see birthdays as day/month only. Age sorting and ages are management-only. Raw age reads through the API are blocked.
- Record the actual units in each donation. The homepage sums all village donation units. Existing records with no unit count are explicitly excluded and counted as incomplete; managers or donors should correct them. Editing or deleting a record updates the total. Requests are not counted as donations.
- Eight stable blood-group colours and four distinct summary-card colours are used. Active requests appear above the summary cards, with urgent requests first.
- The connected Supabase project already has the database updates. To host this same app independently, upload the ready-built ZIP to Cloudflare Pages and keep this same backend. Do not rerun the initial schema on the existing database.
- For a NEW backend, apply database/schema.sql, atomic-profile.sql, readable-join-codes.sql, admin-and-birthdates.sql, lock-village.sql, privacy-units.sql, and request-donations.sql in that order. Set up the intended admin Auth account and village ownership before inviting members; never substitute an unverified account. Update lib/supabase.ts with the new public URL/key and rebuild.


## Latest release: confirmed donations, language and sign-in
1. Open Blood requests and select Fulfilled (or All).
2. For an old completed request, choose Add missing donation. Select the actual donor, actual units and actual donation date. Only enter a blood-bank review date if known.
3. Save. This creates one linked donation and updates the village total, donor card, village ledger and that donor's My donations. Repeat for other actual donors. Offers to help are not automatically treated as donations. Do not duplicate an existing personal donation; edit/remove the old duplicate carefully if necessary.
4. For open requests, use Confirm donation. The request is fulfilled when the confirmed units meet the requested quantity. One donation per donor per request prevents repeated-click duplicates.
5. Only the permanent admin has Delete request, for open, fulfilled or cancelled requests. It removes the request and offers, while keeping donation units and a requester snapshot. Donor profile deletion and explicit donation deletion are separate actions and do remove their respective history.
6. The top English / اردو selector defaults to English and saves the choice on this browser/device. Urdu includes the directory, forms, management, remembrance and install screens. Personal names and user-entered notes are not machine translated. Browser-native date pickers and external authentication messages can follow the browser/provider's own language.
7. Sign-in persists and refreshes automatically. Logging out signs out this browser. Clearing site data, private browsing, session revocation, or moving to a different domain may require signing in again. Language is stored separately and survives logout. Do not share a logged-in admin device.
8. The supplied memorial emblem is now used for PWA and native source icons. If an installed shortcut still shows the old icon, remove that shortcut and install again from /install. Removing an icon does not delete Supabase records. Actual appearance depends on the phone's icon mask.

## Ready-to-upload ZIP (no build needed)
Use BloodLink-Updated-Cloudflare-Pages.zip in Cloudflare Dashboard > Workers & Pages > Create application > Pages > Direct Upload / Upload assets. Upload the ZIP itself if the dashboard accepts it, or extract it and upload its contents. Give the project a name such as chak13-bloodlink; Cloudflare assigns an available https://NAME.pages.dev address. It is public and has no chatgpt.site in the address.
Keep the current Supabase project: all existing village accounts, permissions, donations and realtime updates remain in that backend. The backend migration has already been applied; do NOT re-run SQL on this existing project. Change Supabase Site URL and exact allowed Redirect URL to the new HTTPS address, then test a newly requested confirmation/reset email. Users must sign in once on the new domain and install again from the new domain. Existing old shortcuts continue opening the old address.
The Cloudflare project has not been created on your account by this release. The source ZIP contains all frontend/database migration/native source files; no private donor export, passwords or service-role key is included.

## Verification for this release
TypeScript and static production build; database rollback tests for confirmed donation totals, duplicate prevention, admin request deletion preserving history, and coordinator deletion denial in all three statuses. No test donations were left in the village. Phone installation and signed APK/IPA builds still require real-device testing. Public SMTP delivery remains unverified.
