Download-for-email (premium feature #2)
Fan leaves their email -> receives the file; address is added to the mailing list
(source 'download', single opt-in so the download is not behind a confirm barrier).
Reuses SubscriberService (#1).
- DB: audio_tracks.downloadable (default 0).
- admin-audio: per-track no-JS toggle (POST /admin/audio/:id/downloadable) + ⬇
button in the admin list (premium-gated); downloadable also in the /api/:id whitelist.
- routes/download.js (premium-gated): GET /downloads (list), GET /download/:id
(capture page), POST /download/:id (save email + session grant), GET
/download/:id/bestand (serves attachment from storage/audio, 15-min session window,
path-traversal guards).
- views: pages/downloads.ejs + pages/download.ejs (form/ready, auto-start download).
- admin dashboard: ⬇ Downloads link (premium, non-hub).
node --check passed. Nothing else reuses this; #8 notify reuses subscribers.
Co-Authored-By: Claude <noreply@…>