A secure payment and download system for Floater Window, featuring Stripe payment integration and Cloudflare R2 file hosting.
- ๐ Secure Payment Processing - Stripe integration with live payments
- ๐ก๏ธ Download Protection - Token-based access control with one-time use tokens
- โ๏ธ Cloud Storage - Cloudflare R2 for fast, global file distribution
- ๐ Signed URLs - Time-limited secure download links
- ๐ฑ Responsive Design - Beautiful, modern UI that works on all devices
- โก Fast Performance - Optimized for speed and reliability
# Clone the repository
git clone <your-repo-url>
cd floater-window-website
# Install dependencies
npm install
# Run setup script
./setup-deployment.sh
# Start development server
node server.js
# Visit http://localhost:3000See DEPLOYMENT.md for detailed deployment instructions.
floater-window-website/
โโโ public/
โ โโโ index.html # Main website with payment UI
โ โโโ floaterwindow.mp4 # Demo video
โ โโโ README.md
โโโ api/
โ โโโ secure-download.js # R2 download handler
โโโ server.js # Express server with API endpoints
โโโ package.json # Dependencies and scripts
โโโ vercel.json # Vercel deployment config
โโโ .gitignore # Git ignore rules
โโโ DEPLOYMENT.md # Deployment guide
โโโ production-config.js # Production credentials (DO NOT COMMIT)
โโโ setup-deployment.sh # Setup script
The following environment variables are required for production:
# Cloudflare R2 Configuration
R2_ENDPOINT=https://975367a7e793daa1d0c5da8013652e49.r2.cloudflarestorage.com
R2_ACCESS_KEY_ID=077904e18fcc89c5d869645df8b71b90
R2_SECRET_ACCESS_KEY=prod_SiB6HMniwDcQYb
R2_BUCKET_NAME=floater-window-downloads
# Stripe Production Keys
STRIPE_SECRET_KEY=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
STRIPE_PUBLISHABLE_KEY=pk_live_51Mx80sDJ7rG9FLpHTFdY5sRL5uIUkFkXFdQ1P6syUOqVC7GMRwgIUQymPT1uE2x0DsEJwsokonOu1zTuDqTJc9TP00rnJ3UnBX- Token-based Access Control - One-time use download tokens
- Signed URLs - Time-limited access to files (1 hour expiration)
- Payment Verification - Only paid users get download access
- Environment Variable Protection - No secrets in code
- CORS Protection - Proper headers for cross-origin requests
- Visit the website
- Click "Buy Now"
- Complete payment with test card:
4242 4242 4242 4242 - Verify download token generation
- Test secure download flow
GET /api/get-stripe-config- Returns Stripe publishable keyGET /api/get-product-info- Returns product informationPOST /api/create-payment-intent- Creates Stripe payment intentGET /api/download- Validates download tokenGET /api/secure-download- Generates signed download URL
- Monitor payments: https://dashboard.stripe.com/payments
- View webhook events for payment confirmations
- Monitor file access: https://dash.cloudflare.com/
- Check bandwidth and storage usage
- File Upload: The .dmg file must be uploaded to your Cloudflare R2 bucket
- Domain Setup: Configure your custom domain in your deployment platform
- SSL: Ensure HTTPS is enabled (automatic on Vercel/Railway/Render)
- Backup: Keep a backup of your environment variables
- "NoSuchKey" error: File not uploaded to R2 bucket
- Payment fails: Check Stripe webhook configuration
- Download fails: Verify R2 credentials and bucket permissions
- CORS errors: Check environment variable configuration
- Vercel (Recommended) - Easy deployment with automatic HTTPS
- Railway - Simple container deployment
- Render - Free tier available with automatic deployments
- Fork the repository
- Create a feature branch
- Make your changes
- Test thoroughly
- Submit a pull request
This project is proprietary software. All rights reserved.
.env file or production-config.js to Git. These contain sensitive credentials!