new-site/scripts/rescue-mitchell-email.mjs
justin e87715aee7 fix(portal): onboarding/login links last 7 days, not 60 min
The rescue onboarding emails hardcoded a 60-minute expiry -- way too short for a
paid customer who hasn't engaged yet (they may not check email for hours/days),
so Paul's and Mitchell's links expired before they used them. Onboarding links
now last 7 days (ONBOARDING_TTL_MINUTES); the standard security password-RESET
window bumped 30min -> 2h. Re-issued fresh 7-day links to all 3 affected
customers (none had set a password yet) via reissue-onboarding-links.mjs, cc'd.
2026-06-09 22:50:09 -05:00

55 lines
3.7 KiB
JavaScript

/**
* Send Mitchell Allen his portal password-set link + a note that his e-sign
* authorization emails are now on the way (after the SMTP fix). CC justin.
* Run: docker exec performancewest-api-1 node /app/scripts/rescue-mitchell-email.mjs
*/
import pg from "pg";
import crypto from "crypto";
import nodemailer from "nodemailer";
const EMAIL = "mitchell@allenscrapmetal.com";
const CC = "justin@performancewest.net";
const SITE = process.env.DOMAIN ? `https://${process.env.DOMAIN}` : "https://performancewest.net";
const pool = new pg.Pool({ connectionString: process.env.DATABASE_URL });
const mailer = nodemailer.createTransport({
host: process.env.SMTP_HOST || "co.carrierone.com",
port: parseInt(process.env.SMTP_PORT || "587", 10),
secure: false,
auth: { user: process.env.SMTP_USER, pass: process.env.SMTP_PASS },
});
const FROM = process.env.SMTP_FROM || "Performance West <noreply@performancewest.net>";
const cust = await pool.query(`SELECT id, name FROM customers WHERE email=$1`, [EMAIL]);
if (!cust.rows.length) { console.log("no customers row for", EMAIL); process.exit(1); }
const customer = cust.rows[0];
const firstName = (customer.name || "there").split(" ")[0];
const { rows: orders } = await pool.query(
`SELECT order_number, service_name FROM compliance_orders WHERE customer_email=$1 ORDER BY created_at`, [EMAIL]);
const token = crypto.randomBytes(32).toString("hex");
await pool.query(
`INSERT INTO password_reset_tokens (customer_id, token, expires_at) VALUES ($1,$2,$3)`,
[customer.id, token, new Date(Date.now() + 7 * 24 * 60 * 60 * 1000)],
);
const resetLink = `${SITE}/account/reset-password?token=${token}`;
const orderList = orders.map(o => `<li style="margin:4px 0">${o.service_name} <span style="color:#888;font-family:monospace">(${o.order_number})</span></li>`).join("");
await mailer.sendMail({
from: FROM, to: EMAIL, cc: CC,
subject: "Your Performance West login + signature requests are on the way",
html: `<div style="font-family:Arial,sans-serif;max-width:560px;margin:0 auto;padding:24px;color:#222">
<h2 style="color:#1a2744;margin:0 0 8px">You're all set, ${firstName}</h2>
<p>Thanks for your order. We had a delivery issue that kept our earlier emails from reaching you - that's fixed now, so here is everything you need.</p>
<p style="margin:18px 0 6px"><strong>1. Set your password to log in</strong> (valid for 7 days):</p>
<p style="margin:6px 0 18px"><a href="${resetLink}" style="background:#2d4e78;color:#fff;padding:12px 28px;border-radius:8px;text-decoration:none;font-weight:600">Set my password &rarr;</a></p>
<p style="font-size:13px;color:#666;margin:0 0 18px">Or paste this link: ${resetLink}</p>
<p style="margin:18px 0 6px"><strong>2. Sign your authorizations.</strong> We're sending you a separate signature request for each filing below. Each filing begins once you sign it - for the MCS-150 and USDOT reactivation we prepare the form and you review/sign before we submit to FMCSA.</p>
<ul style="padding-left:18px">${orderList}</ul>
<p style="font-size:13px;color:#666">You can also track everything in your portal once you log in. Questions? Reply here or call 1-888-411-0383.</p>
<p style="font-size:12px;color:#9ca3af">Performance West Inc. &middot; performancewest.net &middot; 1-888-411-0383</p>
</div>`,
text: `Hi ${firstName}, set your password to log in: ${resetLink} (valid 7 days). You'll also receive a signature request for each filing: ${orders.map(o => o.service_name + " (" + o.order_number + ")").join("; ")}. Each filing begins once you sign. Questions? 1-888-411-0383.`,
});
console.log(`[rescue] login + signature note sent to ${EMAIL} (cc ${CC}) for ${orders.length} orders`);
await pool.end();