Skip to content

pull - #174

Merged
indubrolk merged 105 commits into
indufrom
main
Aug 12, 2026
Merged

pull#174
indubrolk merged 105 commits into
indufrom
main

Conversation

@indubrolk

Copy link
Copy Markdown
Collaborator

No description provided.

a-zahi2002 and others added 30 commits May 16, 2026 16:06
Synced from dev branch Implement user registration, booking calendar, and admin dashboard
Implement real-time notification system and enhance landing page UI
Implement booking functionality, UI updates, and database migration
Booking CRUD functinolities added
Enhance admin analytics dashboard, user authentication, and UI components
Implement booking management modals and session timeout features
Implement booking management modals and session timeout features
Enhance admin dashboard, user authentication, and UI components
Enhance admin dashboard and improve user authentication UI
Enhance admin dashboard, user authentication, and booking management
Enhance admin dashboard and improve user authentication UI
Enhance user registration, booking, and admin dashboard features
…ashing and verification to the registration and login flows
Merge pull request #125 from indubrolk/main-dev
Implement dual-layer authentication with bcrypt for registration and login
a-zahi2002 and others added 25 commits July 1, 2026 14:39
… infrastructure with Firebase and Supabase integration
…authentication, role-based dashboards, resource management, and administrative reporting features
Merge main development branches
…tion, and Firebase-Supabase user synchronization services
add landing page layout with integrated theme toggle and notification…
initialize landing page and layout architecture with core UI components
 implement user profile management and notification preference settin…
update Maintenance section interface
Copilot AI lite review requested due to automatic review settings August 12, 2026 10:45
@vercel

vercel Bot commented Aug 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
capstone-urms Ready Ready Preview Aug 12, 2026 10:45am

@indubrolk
indubrolk merged commit 00c5770 into indu Aug 12, 2026
2 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a broad security + QA + operations uplift across the Next.js frontend and Express/Supabase backend, including session lifecycle management, OWASP-style hardening, new automated tests (security + E2E), and database migration infrastructure.

Changes:

  • Added Jest security tests and Playwright E2E tests (with shared auth mocks/helpers) and updated root test scripts.
  • Implemented client-side session lifecycle controls (idle timeout, tab-isolated sessions, token refresh helpers) plus UI/layout refinements around protected areas.
  • Expanded backend capabilities with migrations, new services (SMS), saved searches, stricter RBAC/admin routing, and analytics query batching.

Reviewed changes

Copilot reviewed 99 out of 168 changed files in this pull request and generated 12 comments.

Show a summary per file
File Description
vercel.json Vercel deployment configuration for Next.js build/output/region.
tsconfig.json Excludes scratch/ from TypeScript compilation.
tests/utils/mockAuth.js JWT helper utilities for security/API tests.
tests/setup.js Jest global setup + firebase-admin mock.
tests/security/validation.security.test.js Security tests for validation/XSS/SQLi scenarios.
tests/security/rbac.security.test.js Security tests for auth/RBAC enforcement paths.
tests/security/infrastructure.security.test.js Security tests for rate limiting + headers.
tests/e2e/user-crud.spec.ts Playwright E2E for admin user CRUD flow.
tests/e2e/resource-crud.spec.ts Playwright E2E for resource CRUD/status toggling.
tests/e2e/reporting.spec.ts Playwright E2E for reporting/export downloads.
tests/e2e/rbac.spec.ts Playwright E2E for role-based route access.
tests/e2e/maintenance.spec.ts Playwright E2E for maintenance lifecycle workflow.
tests/e2e/helpers.ts Shared Playwright login/logout + uniqueness helpers.
tests/e2e/booking.spec.ts Playwright E2E for booking conflict resolution.
tests/e2e/auth.spec.ts Playwright E2E for auth happy/negative paths.
scratch/test_relations_query.ts Local scratch script (now excluded) for Supabase joins.
scratch/fetch_openapi.ts Local scratch script (now excluded) for OpenAPI fetch.
scratch/check_orphaned.ts Local scratch script (now excluded) for orphan checks.
README.md Updated repo structure documentation and module map.
proxy.ts Adds a pass-through “edge middleware” implementation (file naming currently matters for Next.js).
playwright.config.ts Playwright E2E runner configuration.
package.json Adds test/e2e scripts, migrations scripts, and deps for security/testing.
next.config.ts Adds global security headers via headers() config.
lib/supabase.ts Extends user profile shape + adds authenticated profile upsert helper.
lib/session-utils.ts Token refresh helper + token change listener utilities.
lib/firebase.ts Clarifies one-time initialization and typed Firebase app/auth exports.
lib/exportCsv.ts Adds CSV export helper with UTF-8 BOM.
lib/apiClient.ts Adds fetch wrapper that injects Firebase bearer tokens.
jest.config.js Adds Node Jest config for JS-based security tests.
hooks/useTabSession.ts Adds tab-isolated session storage helper hook.
hooks/useIdleTimeout.ts Adds idle timeout tracking hook with warning/idle states.
global.d.ts Declares module typings for isomorphic-dompurify.
Docs/session-management-idle-timeout.md Documentation for idle timeout/session architecture.
Docs/owasp-security-audit.md Documentation for OWASP audit findings/remediation.
Docs/jwt-authentication-flow.md Documentation for JWT/Firebase auth flow.
Docs/database-setup-instructions.md Documentation for migrations and DB setup.
Docs/database-migration-report.md Documentation/report on schema + RLS + indexing.
Docs/CHANGELOG_SESSION_MANAGEMENT.md Changelog for session/idle-timeout changes.
Docs/CHANGELOG_JWT_AUTHENTICATION.md Changelog for JWT auth flow changes.
Docs/CHANGELOG_INPUT_VALIDATION_XSS_SQLI.md Changelog for input validation + XSS/SQLi mitigations.
Docs/CHANGELOG_HTTPS_HSTS_ENFORCEMENT.md Changelog for HTTPS/HSTS/header hardening.
Docs/CHANGELOG_DASHBOARD.md Changelog for role-based dashboard work.
Docs/CHANGELOG_BCRYPT_PASSWORD_ENCRYPTION.md Changelog for bcrypt password hashing layer.
Docs/CHANGELOG_API_RATE_LIMITING.md Changelog for express-rate-limit setup.
components/ThemeToggle.tsx UI tweaks for theme toggle styling.
components/SessionProvider.tsx Adds warning modal + auto sign-out on inactivity.
components/SafeRichTextDisplay.tsx Adds DOMPurify-based rich-text sanitizer component.
components/ResourceCard.tsx Styling updates for dark mode + badge/button shapes.
components/ProtectedRoute.tsx Adds approval gating, role-based redirect, and wraps in SessionProvider.
components/Pagination.tsx Adds reusable pagination component.
components/PageLoader.tsx Adds full-screen initial loader animation.
components/NotificationBell.tsx Styling/UX changes for notification dropdown.
components/MaintenanceTimeline.tsx Styling improvements + dark-mode adjustments.
components/LayoutShell.tsx Centralizes dashboard layout shell + wraps dashboard routes.
components/DeleteBookingModal.tsx Adds modal UI + DELETE booking API call.
components/dashboard/DashboardLayout.tsx Adds sidebar/topbar shell for dashboard routes.
components/charts/BookingPieChart.tsx Memoizes chart to reduce rerenders; sets displayName.
components/charts/BookingLineChart.tsx Memoizes chart to reduce rerenders; sets displayName.
components/charts/BookingBarChart.tsx Memoizes chart to reduce rerenders; sets displayName.
components/BulkImport.tsx Uses env-based API URL and updates modal styling.
backend/tsconfig.json Adjusts type resolution configuration for backend TS.
backend/src/services/socketService.ts Tightens/changes Socket.IO CORS origin handling.
backend/src/services/smsService.ts Adds Twilio SMS sending + duplicate prevention + delivery logging.
backend/src/services/pdfReportService.ts Enables PDFKit bufferPages for later pagination use.
backend/src/services/password.service.ts Adds bcrypt hashing/verification utility.
backend/src/services/analyticsService.ts Batches Supabase queries via Promise.all; adds booking trend improvements.
backend/src/scripts/setCustomClaims.ts Adds script to set Firebase custom claims.
backend/src/scratch/test_sync.ts Backend scratch script for user sync validation (ignored).
backend/src/scratch/list_users.ts Backend scratch script for listing users (ignored).
backend/src/scratch/check_schema.ts Backend scratch script for schema inspection (ignored).
backend/src/scratch/check_both_users.ts Backend scratch script for Firebase vs Supabase user comparison (ignored).
backend/src/schemas/maintenanceSchema.ts Adds Zod schema for maintenance ticket creation.
backend/src/routes/userRoutes.ts Adds public register + admin CRUD + bcrypt endpoints; reworks middleware placement.
backend/src/routes/savedSearchRoutes.ts Adds saved searches CRUD router protected by verifyToken.
backend/src/routes/resourceRoutes.ts Applies verifyToken globally + requireAdmin to mutation routes; adds example RBAC routes.
backend/src/routes/reportScheduleRoutes.ts Fixes schedule router paths relative to mount point.
backend/src/routes/bookingRoutes.ts Adds /my bookings route before /:id.
backend/src/models/savedSearch.model.ts Adds Supabase model layer for saved searches.
backend/src/models/resource.model.ts Adds bulk createMany() support with fallback behavior.
backend/src/models/booking.model.ts Expands user selection to include phone; updates conflict check logic.
backend/src/middleware/validateRequest.ts Adds reusable Zod validation middleware factory.
backend/src/middleware/rbac.middleware.ts Adds role authorization middleware factory.
backend/src/middleware/rateLimiter.ts Adds global + auth-specific rate limiters.
backend/src/middleware/auth.middleware.ts Adds mock-token: bypass for non-production; keeps dev-token bypass.
backend/src/db/supabase-schema.sql Adds password_hash and loosens FK nullability for certain columns.
backend/src/db/migrations/0007_user_approval.up.sql Adds approval_status column + constraint + backfill.
backend/src/db/migrations/0007_user_approval.down.sql Rolls back approval_status changes.
backend/src/db/migrations/0006_sms_and_saved_searches.up.sql Adds phone + sms_logs + saved_searches with RLS policies.
backend/src/db/migrations/0006_sms_and_saved_searches.down.sql Rolls back sms/saved-searches additions.
backend/src/db/migrations/0005_performance_indexes.up.sql Adds created_at indexes for performance.
backend/src/db/migrations/0005_performance_indexes.down.sql Drops created_at performance indexes.
backend/src/db/migrations/0004_seed_data.up.sql Seed data updates (mock users/resources/etc).
backend/src/db/migrations/0004_seed_data.down.sql Seed rollback script (targeted deletes).
backend/src/db/migrations/0003_search_indexing.up.sql Adds generated tsvector columns + GIN indexes.
backend/src/db/migrations/0003_search_indexing.down.sql Rolls back FTS columns/indexes.
backend/src/db/migrations/0002_rls_policies.up.sql Defines RLS helper functions + policies.
backend/src/db/migrations/0002_rls_policies.down.sql Rolls back RLS policies/functions.
backend/src/db/migrations/0001_initial_schema.up.sql Initial schema migration.
backend/src/db/migrations/0001_initial_schema.down.sql Drops schema in reverse dependency order.
backend/src/db/migrate.ts Adds migration runner (apply/rollback) using pg client.
backend/src/controllers/searchCtrl.ts Small change to textSearch options ordering.
backend/src/controllers/savedSearchCtrl.ts Adds controller handlers for saved searches CRUD.
backend/src/controllers/resourceCtrl.ts Standardizes API responses + optimizes import to bulk createMany().
backend/src/controllers/analyticsCtrl.ts Batches resource analytics queries via Promise.all.
backend/src/config/supabaseClient.ts Adds env fallback for service key + improves warnings.
backend/package.json Adds migration scripts and security-related dependencies.
backend/.env.example Expands env example (service key, SMTP, sheets, frontend URL).
app/layout.tsx Adds fonts and icons; changes theme defaults.
app/explore/page.tsx Fetches resources from API using auth token.
app/dashboard/layout.tsx Dashboard route layout placeholder (children only).
.gitignore Tightens env ignores; ignores scratch + Playwright outputs.
.env.example Adds root env example template.
Files not reviewed (1)
  • backend/package-lock.json: Generated file
Suppressed comments (2)

backend/src/services/analyticsService.ts:196

  • Promise.all results are used without checking statusRes.error / trendRes.error. A Supabase failure here would produce empty analytics instead of surfacing an error response.
    backend/src/services/socketService.ts:68
  • Stray comment // Trigger nodemon restart looks like a debugging artifact and doesn’t belong in committed production code.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +108 to +125
const [
resRes,
maintRes,
activeRes,
completedRes,
totalMaintRes,
pendingMaintRes,
mbRes
] = await Promise.all([
resQuery,
maintQuery,
activeBookingsQuery,
completedBookingsQuery,
totalMaintQuery,
pendingMaintQuery,
mbQuery
]);

Comment on lines +56 to +58
const [resRes, bkRes] = await Promise.all([resQuery, bkQuery]);
const resourceData = resRes.data;
const bookingData = bkRes.data;
Comment thread lib/supabase.ts
Comment on lines 34 to +37
department?: string;
password_hash?: string;
phone?: string;
approval_status?: "Pending" | "Approved" | "Rejected";
Comment on lines +7 to +17
const allowedOrigins = process.env.ALLOWED_ORIGINS
? process.env.ALLOWED_ORIGINS.split(',')
: [process.env.FRONTEND_URL || 'http://localhost:3000', 'http://127.0.0.1:3000'];

io = new Server(httpServer, {
cors: {
origin: process.env.ALLOWED_ORIGINS
? process.env.ALLOWED_ORIGINS.split(',')
: ['http://localhost:3000', 'http://127.0.0.1:3000'],
origin: (origin, callback) => {
if (!origin) return callback(null, true);
if (/\.vercel\.app$/.test(origin)) return callback(null, true);
if (allowedOrigins.includes(origin)) return callback(null, true);
return callback(new Error(`CORS: Origin '${origin}' not allowed`));
Comment on lines +42 to +49
// Allow mock-token bypass in development ONLY (for Quick Operator Access demo users)
if (token.startsWith('mock-token:') && process.env.NODE_ENV !== 'production') {
const parts = token.split(':');
const uid = parts[1] || 'dev-user';
const role = parts[2] || 'student';
req.user = { uid, role, admin: role === 'admin' };
return finalize();
}
Comment on lines +124 to +127
const safeHtml = cleanHtml.replace(
/<a\s/g,
'<a rel="noopener noreferrer" '
);
import { X, AlertTriangle, Trash2, MapPin } from "lucide-react";
import { useAuth } from "@/lib/auth-context";

const API = process.env.NEXT_PUBLIC_API_URL || "http://localhost:5000";
Comment on lines +43 to +47
{isDashboardPage ? (
<ProtectedRoute>
<DashboardLayout>{children}</DashboardLayout>
</ProtectedRoute>
) : (
Comment thread proxy.ts
Comment on lines +19 to +22
export function proxy(request: NextRequest) {
// Pass all requests through — client-side ProtectedRoute handles auth.
return NextResponse.next();
}
Comment on lines +24 to +54
// --- RBAC Example Routes ---

// 1. Admin only route (e.g., deleting a user, though normally in userRoutes)
router.delete(
"/:id/delete-user-example",
verifyToken,
authorizeRoles("admin"),
(req, res) => {
res.json({ message: "Success: Admin action performed." });
}
);

// 2. Lecturer and Admin route (e.g., approving a student resource request)
router.post(
"/:id/approve",
verifyToken,
authorizeRoles("admin", "lecturer"),
(req, res) => {
res.json({ message: "Success: Resource request approved." });
}
);

// 3. Maintenance only route (e.g., updating a broken equipment ticket)
router.patch(
"/:id/maintenance-ticket",
verifyToken,
authorizeRoles("maintenance", "admin"), // often admins can do anything
(req, res) => {
res.json({ message: "Success: Maintenance ticket updated." });
}
);

This branch was successfully deployed

1 active deployment
Production — 960f79cd Deployed Aug 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants