A full-stack web application for managing teams and tasks with role-based access control.
- Authentication — Secure register/login with bcrypt password hashing and session-based auth (HTTP-only cookies)
- Teams — Create teams, invite members by email, manage roles
- Tasks — Create and assign tasks to one or multiple team members, track status and priority
- Role-based access — Only team creators can create/edit/delete tasks; assignees can update their task status
- Due date reminders — Dashboard alerts for overdue tasks, tasks due today, and tasks due within 2 days
- Responsive UI — Works on desktop and mobile
- Frontend: React 18, Vite, Tailwind CSS
- Backend: Node.js, Express.js
- Database: PostgreSQL
- Auth: Passport.js (local strategy), express-session
- Validation: express-validator
- Deployment: Railway (backend + database), Vercel (frontend)
- Node.js 18+
- PostgreSQL 14+
git clone https://github.com/codewithsyedabdullah/Secure-Task-Management-System.git
cd Secure-Task-Management-Systempsql -U postgres -c "CREATE DATABASE teamtaskdb;"
psql -U postgres -d teamtaskdb -f backend/db/schema.sqlcd backend
cp .env.example .envEdit .env:
PORT=5000
DATABASE_URL=postgresql://postgres:yourpassword@localhost:5432/teamtaskdb
SESSION_SECRET=your_long_random_secret
NODE_ENV=development
FRONTEND_URL=http://localhost:5173
cd backend
npm install
npm run devcd frontend
npm install
npm run devVisit http://localhost:5173
| Method | Endpoint | Description |
|---|---|---|
| POST | /auth/register | Register a new user |
| POST | /auth/login | Login |
| POST | /auth/logout | Logout |
| GET | /auth/me | Get current user |
| Method | Endpoint | Description |
|---|---|---|
| GET | /teams | List my teams |
| POST | /teams | Create a team |
| GET | /teams/:id | Get team with members |
| PUT | /teams/:id | Update team (creator only) |
| DELETE | /teams/:id | Delete team (creator only) |
| POST | /teams/:id/members | Add member by email |
| DELETE | /teams/:id/members/:userId | Remove member |
| Method | Endpoint | Description |
|---|---|---|
| GET | /tasks | List tasks (supports ?team_id, ?assigned_to, ?status, ?search) |
| POST | /tasks | Create task (creator only) |
| GET | /tasks/:id | Get task |
| PUT | /tasks/:id | Update task (creator only) |
| PUT | /tasks/:id/status | Update status (assignee or creator) |
| DELETE | /tasks/:id | Delete task (creator only) |
- Connect your GitHub repo on railway.app
- Add a PostgreSQL service
- Set environment variables (DATABASE_URL, SESSION_SECRET, NODE_ENV=production, FRONTEND_URL)
- Set root directory to
backend, start command tonpm start - Run the schema SQL in Railway's PostgreSQL query tab
- Import the repo on vercel.com
- Set root directory to
frontend - Add environment variable:
VITE_API_URL(leave empty — proxy handles it) - Deploy
- Passwords hashed with bcrypt (cost factor 12)
- Sessions stored server-side with HTTP-only, Secure cookies
- All routes protected by authentication middleware
- Input validation and sanitization on all endpoints
- Parameterized SQL queries (no SQL injection)
- Role-based access control on all team and task operations