Latest
2026.34
Experience
- Rebuilt the homepage around destination photography and the message, "Your next adventure starts with a code."
- Added an in-place code reveal so visitors can get and rotate a code without opening a modal or leaving the landing page.
- Changed the menu's Find a code link to open the in-place reveal on the homepage instead of refreshing it.
- Added a visible close control, outside click dismissal, and Escape-key dismissal to the revealed referral code.
- Rewrote How it works, program terms, and owner submission content in direct, plain language.
- Expanded the rewards section with current points and Rivian Adventure Network charging benefit context.
- Linked reward details to Rivian's dedicated U.S. Rewards support page.
- Changed every public contact surface to support@codetoadventure.com.
- Updated the project README with the current feature set, API, moderation, TOTP, analytics, testing, and deployment guidance.
- Redesigned the submission, Privacy, Terms, API documentation, Changelog, administrator login, dashboard, review, and edit pages as one coherent system.
- Removed redundant introductory copy from the Changelog heading.
Brand, design, and performance
- Introduced the Compass Yellow, Warm White, and Trail Black visual system with bold system typography and generous spacing.
- Evolved the original circular-arrow icon with tighter spacing and created an uppercase wordmark with a yellow TO capsule.
- Updated the homepage with the supplied Red Canyon R1T beach hero, responsive local formats, and tuned desktop and mobile framing.
- Added new favicon, touch-icon, and social-card assets.
- Kept the menu pill visible while visitors scroll through every page.
- Removed third-party font requests and established a no-em-dash copy standard.
- Added a dedicated asset revision key so returning visitors receive the matching styles and interactions immediately after deployment.
Accessibility and responsiveness
- Added responsive layouts for the homepage, forms, policy pages, API examples, release archive, and administrator records.
- Improved keyboard navigation, visible focus, form error summaries, live status feedback, touch targets, readable contrast, and menu state.
- Added reduced motion behavior, safer code wrapping, explicit image dimensions, and narrow-phone support.
- Corrected the API documentation heading so it stays within narrow mobile viewports.
- Kept core content and the first referral-code reveal available without JavaScript.
Security, privacy, and moderation
- Blocked public access to Git metadata, logs, diagnostics, internal includes, configuration files, and directory listings.
- Added HTTPS enforcement, HSTS, nonce-based CSP, secure sessions, CSRF protection, login throttling, TOTP, idle expiry, and POST-only mutations.
- Rotated production database access and moved administrator two-factor configuration into a server-only secret.
- Removed the legacy database-backed visitor analytics and retained only aggregate referral-code use counts there.
- Restored privacy-focused Tinylytics traffic measurement on public pages and updated the security policy and Privacy page to match.
- Added moderated submissions, layered abuse checks, privacy-limited API responses, safe pre-migration compatibility, canonical SEO metadata, and crawl controls.