Repository navigation
Conversation
Synced from dev branch Implement user registration, booking calendar, and admin dashboard
Implement real-time notification system and enhance landing page UI
Implement booking functionality, UI updates, and database migration
Booking CRUD functinolities added
Enhance admin analytics dashboard, user authentication, and UI components
…r resource booking management
…ogout and warning modal
Implement booking management modals and session timeout features
…ion token injection
…nd API implementation guidelines
…tected routes to resource management
Implement booking management modals and session timeout features
… with idle timeout utilities
Enhance admin dashboard, user authentication, and UI components
Enhance admin dashboard and improve user authentication UI
Enhance admin dashboard, user authentication, and booking management
…registration and login
Enhance admin dashboard and improve user authentication UI
…ve navigation structure
Enhance user registration, booking, and admin dashboard features
…ashing and verification to the registration and login flows
Merge pull request #125 from indubrolk/main-dev
Implement dual-layer authentication with bcrypt for registration and login
… infrastructure with Firebase and Supabase integration
…authentication, role-based dashboards, resource management, and administrative reporting features
… navigation and dynamic links
…S design system configuration
Merge main development branches
…tion, and Firebase-Supabase user synchronization services
add landing page layout with integrated theme toggle and notification…
initialize landing page and layout architecture with core UI components
implement user profile management and notification preference settin…
update Maintenance section interface
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Pull request overview
This PR introduces a broad security + QA + operations uplift across the Next.js frontend and Express/Supabase backend, including session lifecycle management, OWASP-style hardening, new automated tests (security + E2E), and database migration infrastructure.
Changes:
- Added Jest security tests and Playwright E2E tests (with shared auth mocks/helpers) and updated root test scripts.
- Implemented client-side session lifecycle controls (idle timeout, tab-isolated sessions, token refresh helpers) plus UI/layout refinements around protected areas.
- Expanded backend capabilities with migrations, new services (SMS), saved searches, stricter RBAC/admin routing, and analytics query batching.
Reviewed changes
Copilot reviewed 99 out of 168 changed files in this pull request and generated 12 comments.
Show a summary per file
| File | Description |
|---|---|
| vercel.json | Vercel deployment configuration for Next.js build/output/region. |
| tsconfig.json | Excludes scratch/ from TypeScript compilation. |
| tests/utils/mockAuth.js | JWT helper utilities for security/API tests. |
| tests/setup.js | Jest global setup + firebase-admin mock. |
| tests/security/validation.security.test.js | Security tests for validation/XSS/SQLi scenarios. |
| tests/security/rbac.security.test.js | Security tests for auth/RBAC enforcement paths. |
| tests/security/infrastructure.security.test.js | Security tests for rate limiting + headers. |
| tests/e2e/user-crud.spec.ts | Playwright E2E for admin user CRUD flow. |
| tests/e2e/resource-crud.spec.ts | Playwright E2E for resource CRUD/status toggling. |
| tests/e2e/reporting.spec.ts | Playwright E2E for reporting/export downloads. |
| tests/e2e/rbac.spec.ts | Playwright E2E for role-based route access. |
| tests/e2e/maintenance.spec.ts | Playwright E2E for maintenance lifecycle workflow. |
| tests/e2e/helpers.ts | Shared Playwright login/logout + uniqueness helpers. |
| tests/e2e/booking.spec.ts | Playwright E2E for booking conflict resolution. |
| tests/e2e/auth.spec.ts | Playwright E2E for auth happy/negative paths. |
| scratch/test_relations_query.ts | Local scratch script (now excluded) for Supabase joins. |
| scratch/fetch_openapi.ts | Local scratch script (now excluded) for OpenAPI fetch. |
| scratch/check_orphaned.ts | Local scratch script (now excluded) for orphan checks. |
| README.md | Updated repo structure documentation and module map. |
| proxy.ts | Adds a pass-through “edge middleware” implementation (file naming currently matters for Next.js). |
| playwright.config.ts | Playwright E2E runner configuration. |
| package.json | Adds test/e2e scripts, migrations scripts, and deps for security/testing. |
| next.config.ts | Adds global security headers via headers() config. |
| lib/supabase.ts | Extends user profile shape + adds authenticated profile upsert helper. |
| lib/session-utils.ts | Token refresh helper + token change listener utilities. |
| lib/firebase.ts | Clarifies one-time initialization and typed Firebase app/auth exports. |
| lib/exportCsv.ts | Adds CSV export helper with UTF-8 BOM. |
| lib/apiClient.ts | Adds fetch wrapper that injects Firebase bearer tokens. |
| jest.config.js | Adds Node Jest config for JS-based security tests. |
| hooks/useTabSession.ts | Adds tab-isolated session storage helper hook. |
| hooks/useIdleTimeout.ts | Adds idle timeout tracking hook with warning/idle states. |
| global.d.ts | Declares module typings for isomorphic-dompurify. |
| Docs/session-management-idle-timeout.md | Documentation for idle timeout/session architecture. |
| Docs/owasp-security-audit.md | Documentation for OWASP audit findings/remediation. |
| Docs/jwt-authentication-flow.md | Documentation for JWT/Firebase auth flow. |
| Docs/database-setup-instructions.md | Documentation for migrations and DB setup. |
| Docs/database-migration-report.md | Documentation/report on schema + RLS + indexing. |
| Docs/CHANGELOG_SESSION_MANAGEMENT.md | Changelog for session/idle-timeout changes. |
| Docs/CHANGELOG_JWT_AUTHENTICATION.md | Changelog for JWT auth flow changes. |
| Docs/CHANGELOG_INPUT_VALIDATION_XSS_SQLI.md | Changelog for input validation + XSS/SQLi mitigations. |
| Docs/CHANGELOG_HTTPS_HSTS_ENFORCEMENT.md | Changelog for HTTPS/HSTS/header hardening. |
| Docs/CHANGELOG_DASHBOARD.md | Changelog for role-based dashboard work. |
| Docs/CHANGELOG_BCRYPT_PASSWORD_ENCRYPTION.md | Changelog for bcrypt password hashing layer. |
| Docs/CHANGELOG_API_RATE_LIMITING.md | Changelog for express-rate-limit setup. |
| components/ThemeToggle.tsx | UI tweaks for theme toggle styling. |
| components/SessionProvider.tsx | Adds warning modal + auto sign-out on inactivity. |
| components/SafeRichTextDisplay.tsx | Adds DOMPurify-based rich-text sanitizer component. |
| components/ResourceCard.tsx | Styling updates for dark mode + badge/button shapes. |
| components/ProtectedRoute.tsx | Adds approval gating, role-based redirect, and wraps in SessionProvider. |
| components/Pagination.tsx | Adds reusable pagination component. |
| components/PageLoader.tsx | Adds full-screen initial loader animation. |
| components/NotificationBell.tsx | Styling/UX changes for notification dropdown. |
| components/MaintenanceTimeline.tsx | Styling improvements + dark-mode adjustments. |
| components/LayoutShell.tsx | Centralizes dashboard layout shell + wraps dashboard routes. |
| components/DeleteBookingModal.tsx | Adds modal UI + DELETE booking API call. |
| components/dashboard/DashboardLayout.tsx | Adds sidebar/topbar shell for dashboard routes. |
| components/charts/BookingPieChart.tsx | Memoizes chart to reduce rerenders; sets displayName. |
| components/charts/BookingLineChart.tsx | Memoizes chart to reduce rerenders; sets displayName. |
| components/charts/BookingBarChart.tsx | Memoizes chart to reduce rerenders; sets displayName. |
| components/BulkImport.tsx | Uses env-based API URL and updates modal styling. |
| backend/tsconfig.json | Adjusts type resolution configuration for backend TS. |
| backend/src/services/socketService.ts | Tightens/changes Socket.IO CORS origin handling. |
| backend/src/services/smsService.ts | Adds Twilio SMS sending + duplicate prevention + delivery logging. |
| backend/src/services/pdfReportService.ts | Enables PDFKit bufferPages for later pagination use. |
| backend/src/services/password.service.ts | Adds bcrypt hashing/verification utility. |
| backend/src/services/analyticsService.ts | Batches Supabase queries via Promise.all; adds booking trend improvements. |
| backend/src/scripts/setCustomClaims.ts | Adds script to set Firebase custom claims. |
| backend/src/scratch/test_sync.ts | Backend scratch script for user sync validation (ignored). |
| backend/src/scratch/list_users.ts | Backend scratch script for listing users (ignored). |
| backend/src/scratch/check_schema.ts | Backend scratch script for schema inspection (ignored). |
| backend/src/scratch/check_both_users.ts | Backend scratch script for Firebase vs Supabase user comparison (ignored). |
| backend/src/schemas/maintenanceSchema.ts | Adds Zod schema for maintenance ticket creation. |
| backend/src/routes/userRoutes.ts | Adds public register + admin CRUD + bcrypt endpoints; reworks middleware placement. |
| backend/src/routes/savedSearchRoutes.ts | Adds saved searches CRUD router protected by verifyToken. |
| backend/src/routes/resourceRoutes.ts | Applies verifyToken globally + requireAdmin to mutation routes; adds example RBAC routes. |
| backend/src/routes/reportScheduleRoutes.ts | Fixes schedule router paths relative to mount point. |
| backend/src/routes/bookingRoutes.ts | Adds /my bookings route before /:id. |
| backend/src/models/savedSearch.model.ts | Adds Supabase model layer for saved searches. |
| backend/src/models/resource.model.ts | Adds bulk createMany() support with fallback behavior. |
| backend/src/models/booking.model.ts | Expands user selection to include phone; updates conflict check logic. |
| backend/src/middleware/validateRequest.ts | Adds reusable Zod validation middleware factory. |
| backend/src/middleware/rbac.middleware.ts | Adds role authorization middleware factory. |
| backend/src/middleware/rateLimiter.ts | Adds global + auth-specific rate limiters. |
| backend/src/middleware/auth.middleware.ts | Adds mock-token: bypass for non-production; keeps dev-token bypass. |
| backend/src/db/supabase-schema.sql | Adds password_hash and loosens FK nullability for certain columns. |
| backend/src/db/migrations/0007_user_approval.up.sql | Adds approval_status column + constraint + backfill. |
| backend/src/db/migrations/0007_user_approval.down.sql | Rolls back approval_status changes. |
| backend/src/db/migrations/0006_sms_and_saved_searches.up.sql | Adds phone + sms_logs + saved_searches with RLS policies. |
| backend/src/db/migrations/0006_sms_and_saved_searches.down.sql | Rolls back sms/saved-searches additions. |
| backend/src/db/migrations/0005_performance_indexes.up.sql | Adds created_at indexes for performance. |
| backend/src/db/migrations/0005_performance_indexes.down.sql | Drops created_at performance indexes. |
| backend/src/db/migrations/0004_seed_data.up.sql | Seed data updates (mock users/resources/etc). |
| backend/src/db/migrations/0004_seed_data.down.sql | Seed rollback script (targeted deletes). |
| backend/src/db/migrations/0003_search_indexing.up.sql | Adds generated tsvector columns + GIN indexes. |
| backend/src/db/migrations/0003_search_indexing.down.sql | Rolls back FTS columns/indexes. |
| backend/src/db/migrations/0002_rls_policies.up.sql | Defines RLS helper functions + policies. |
| backend/src/db/migrations/0002_rls_policies.down.sql | Rolls back RLS policies/functions. |
| backend/src/db/migrations/0001_initial_schema.up.sql | Initial schema migration. |
| backend/src/db/migrations/0001_initial_schema.down.sql | Drops schema in reverse dependency order. |
| backend/src/db/migrate.ts | Adds migration runner (apply/rollback) using pg client. |
| backend/src/controllers/searchCtrl.ts | Small change to textSearch options ordering. |
| backend/src/controllers/savedSearchCtrl.ts | Adds controller handlers for saved searches CRUD. |
| backend/src/controllers/resourceCtrl.ts | Standardizes API responses + optimizes import to bulk createMany(). |
| backend/src/controllers/analyticsCtrl.ts | Batches resource analytics queries via Promise.all. |
| backend/src/config/supabaseClient.ts | Adds env fallback for service key + improves warnings. |
| backend/package.json | Adds migration scripts and security-related dependencies. |
| backend/.env.example | Expands env example (service key, SMTP, sheets, frontend URL). |
| app/layout.tsx | Adds fonts and icons; changes theme defaults. |
| app/explore/page.tsx | Fetches resources from API using auth token. |
| app/dashboard/layout.tsx | Dashboard route layout placeholder (children only). |
| .gitignore | Tightens env ignores; ignores scratch + Playwright outputs. |
| .env.example | Adds root env example template. |
Files not reviewed (1)
- backend/package-lock.json: Generated file
Suppressed comments (2)
backend/src/services/analyticsService.ts:196
- Promise.all results are used without checking
statusRes.error/trendRes.error. A Supabase failure here would produce empty analytics instead of surfacing an error response.
backend/src/services/socketService.ts:68 - Stray comment
// Trigger nodemon restartlooks like a debugging artifact and doesn’t belong in committed production code.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+108
to
+125
| const [ | ||
| resRes, | ||
| maintRes, | ||
| activeRes, | ||
| completedRes, | ||
| totalMaintRes, | ||
| pendingMaintRes, | ||
| mbRes | ||
| ] = await Promise.all([ | ||
| resQuery, | ||
| maintQuery, | ||
| activeBookingsQuery, | ||
| completedBookingsQuery, | ||
| totalMaintQuery, | ||
| pendingMaintQuery, | ||
| mbQuery | ||
| ]); | ||
|
|
Comment on lines
+56
to
+58
| const [resRes, bkRes] = await Promise.all([resQuery, bkQuery]); | ||
| const resourceData = resRes.data; | ||
| const bookingData = bkRes.data; |
Comment on lines
34
to
+37
| department?: string; | ||
| password_hash?: string; | ||
| phone?: string; | ||
| approval_status?: "Pending" | "Approved" | "Rejected"; |
Comment on lines
+7
to
+17
| const allowedOrigins = process.env.ALLOWED_ORIGINS | ||
| ? process.env.ALLOWED_ORIGINS.split(',') | ||
| : [process.env.FRONTEND_URL || 'http://localhost:3000', 'http://127.0.0.1:3000']; | ||
|
|
||
| io = new Server(httpServer, { | ||
| cors: { | ||
| origin: process.env.ALLOWED_ORIGINS | ||
| ? process.env.ALLOWED_ORIGINS.split(',') | ||
| : ['http://localhost:3000', 'http://127.0.0.1:3000'], | ||
| origin: (origin, callback) => { | ||
| if (!origin) return callback(null, true); | ||
| if (/\.vercel\.app$/.test(origin)) return callback(null, true); | ||
| if (allowedOrigins.includes(origin)) return callback(null, true); | ||
| return callback(new Error(`CORS: Origin '${origin}' not allowed`)); |
Comment on lines
+42
to
+49
| // Allow mock-token bypass in development ONLY (for Quick Operator Access demo users) | ||
| if (token.startsWith('mock-token:') && process.env.NODE_ENV !== 'production') { | ||
| const parts = token.split(':'); | ||
| const uid = parts[1] || 'dev-user'; | ||
| const role = parts[2] || 'student'; | ||
| req.user = { uid, role, admin: role === 'admin' }; | ||
| return finalize(); | ||
| } |
Comment on lines
+124
to
+127
| const safeHtml = cleanHtml.replace( | ||
| /<a\s/g, | ||
| '<a rel="noopener noreferrer" ' | ||
| ); |
| import { X, AlertTriangle, Trash2, MapPin } from "lucide-react"; | ||
| import { useAuth } from "@/lib/auth-context"; | ||
|
|
||
| const API = process.env.NEXT_PUBLIC_API_URL || "http://localhost:5000"; |
Comment on lines
+43
to
+47
| {isDashboardPage ? ( | ||
| <ProtectedRoute> | ||
| <DashboardLayout>{children}</DashboardLayout> | ||
| </ProtectedRoute> | ||
| ) : ( |
Comment on lines
+19
to
+22
| export function proxy(request: NextRequest) { | ||
| // Pass all requests through — client-side ProtectedRoute handles auth. | ||
| return NextResponse.next(); | ||
| } |
Comment on lines
+24
to
+54
| // --- RBAC Example Routes --- | ||
|
|
||
| // 1. Admin only route (e.g., deleting a user, though normally in userRoutes) | ||
| router.delete( | ||
| "/:id/delete-user-example", | ||
| verifyToken, | ||
| authorizeRoles("admin"), | ||
| (req, res) => { | ||
| res.json({ message: "Success: Admin action performed." }); | ||
| } | ||
| ); | ||
|
|
||
| // 2. Lecturer and Admin route (e.g., approving a student resource request) | ||
| router.post( | ||
| "/:id/approve", | ||
| verifyToken, | ||
| authorizeRoles("admin", "lecturer"), | ||
| (req, res) => { | ||
| res.json({ message: "Success: Resource request approved." }); | ||
| } | ||
| ); | ||
|
|
||
| // 3. Maintenance only route (e.g., updating a broken equipment ticket) | ||
| router.patch( | ||
| "/:id/maintenance-ticket", | ||
| verifyToken, | ||
| authorizeRoles("maintenance", "admin"), // often admins can do anything | ||
| (req, res) => { | ||
| res.json({ message: "Success: Maintenance ticket updated." }); | ||
| } | ||
| ); |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.