A full-stack, Jira-inspired project management and issue-tracking application built entirely in strict TypeScript. Teams can plan, track, and manage work through customizable Kanban boards, hierarchical issues, role-based access control, audit trails, and rich collaboration features.
| Name | Entry Number | GitHub |
|---|---|---|
| Subarno Saha | 2024CS50431 | @88subarno88 |
| Rohit Meena | 2024CS10030 | @amigo-35 |
GitHub Repository: https://github.com/88subarno88/Task_Board
- Email + password registration and login with
bcrypthashing - JWT-based session management β access tokens in
HTTP-onlycookies, refresh token mechanism for session renewal, logout invalidates refresh token - User profiles with name, email, and avatar
- Role-Based Access Control (RBAC)
- Global Admin β create projects, manage all users, assign project-level roles
- Project Admin β full project settings, manage members, edit workflows
- Project Member β create and edit tasks, participate in project
- Project Viewer β read-only access to project and tasks
- Create, update, and archive projects
- Assign users to projects with project-level permissions
- Project metadata: name, description, created/modified timestamps
- Each project has one or more boards with its own column configuration
- Default columns:
To Do,In Progress,Review,Done(customizable per board) - Native HTML5 Drag & Drop β no external DnD libraries (as required)
- WIP Limits β enforced at column level; invalid moves are blocked at the API, not just warned
- Project Admins can add, rename, reorder, and delete columns
- Three hierarchical task types:
- Story β parent item; status auto-derived from children's statuses
- Task β standard work item, linkable to a Story
- Bug β issue to fix, linkable to a Story
- Parent-child relationships enforced; Story status kept consistent with children
- Task fields: title, description, status, priority (Low/Medium/High/Critical), assignee, reporter, due date
- Create, edit, delete tasks; move between columns; change status/priority/assignee
- Task detail view with full information
- Configurable workflows per board
- Valid status transitions enforced at the API level (invalid transitions blocked, not just warned):
To Do β In Progress In Progress β Review | To Do Review β Done | In Progress Done β To Do - Mandatory Audit Trail β the following events are logged for every task:
- Status changes (old β new status, with timestamp)
- Assignee changes (old β new assignee, with timestamp)
- Comments added/deleted (with timestamp)
- Automatic timestamps: created, updated, resolved, closed
- Comment threads on tasks
- Delete own comments
@emailmention system with clickable mention buttons as they are unique- Activity Timeline per task β comments and audit events merged chronologically
- Rich text support in both issue descriptions and comments β custom-built editor using
contenteditable+execCommandwith no external WYSIWYG library (bold, italic, underline, font family, font size 12β72px, lists, blockquote, code block, links, alignment, strikethrough, indent/outdent, clear formatting)
- Triggered by: task assignment, status change, comment added, user mentioned
- Persistent in-app notification center β stored in the database
- Users can mark notifications as read
- Polling-based fetching
| Layer | Technology |
|---|---|
| Frontend | React 18, Vite, TypeScript (strict: true), React Router DOM, Context API, CSS Modules |
| Backend | Node.js, Express.js, TypeScript (strict: true) |
| ORM | Prisma |
| Database | PostgreSQL |
| Auth | JWT (access + refresh tokens), bcrypt, HTTP-only cookies |
| Drag & Drop | Native HTML5 Drag and Drop API |
| Rich Text | Custom contenteditable editor (no external WYSIWYG) |
| Testing | Jest (backend unit tests) |
| Style | ESLint, Prettier, Google TypeScript Style Guide |
Task_Board/
βββ backend/
β βββ jest.config.js
β βββ package.json
β βββ prisma/
β β βββ schema.prisma # User, Project, Board, Column, Issue, Comment, AuditLog, Notification
β β βββ migrations/
β βββ src/
β β βββ app.ts
β β βββ server.ts
β β βββ config/
β β β βββ database.ts # Prisma client singleton
β β βββ controllers/ # Route handlers
β β βββ middleware/
β β β βββ auth.ts # JWT verification + RBAC guards
β β β βββ errorHandler.ts # Typed AppError class
β β βββ routes/
β β βββ services/
β β β βββ issueservice.ts # Business logic: create/update/move/delete, WIP + workflow validation
β β β βββ notificationservice.ts
β β β βββ ...
β β βββ tests/ # Jest unit tests
β β βββ types/
β β βββ utils/
β βββ tsconfig.json
β
βββ frontend/
β βββ index.html
β βββ package.json
β βββ src/
β β βββ App.tsx
β β βββ main.tsx
β β βββ components/
β β β βββ IssueForm.tsx # Create issue modal
β β β βββ IssueDetail.tsx # Issue detail/edit modal + activity timeline
β β β βββ RichTextEditor.tsx # Custom rich text editor (no Quill)
β β β βββ cssmodules/
β β βββ context/
β β β βββ AuthContext.tsx
β β βββ pages/
β β βββ services/
β β β βββ Issueservice.ts
β β β βββ projectservices.ts
β β β βββ commentservice.ts
β β βββ types/
β βββ tsconfig.json
β βββ tsconfig.app.json
β βββ tsconfig.node.json
β βββ vite.config.ts
β
βββ README.md
- Node.js v18.0 or higher
- PostgreSQL running locally or hosted
git clone https://github.com/88subarno88/Task_Board.git
cd Task_Board# Terminal 1 β Backend
cd Task_Board
cd backend
npm install
# Terminal 2 β Frontend
cd Task_Board
cd frontend
npm installCreate backend/.env:
DATABASE_URL="postgresql://<YOUR_USERNAME>@localhost:5432/taskboard?schema=public"
DIRECT_URL="postgresql://<YOUR_USERNAME>@localhost:5432/taskboard?schema=public"
JWT_ACCESS_SECRET="taskboard-access-secret-2024"
JWT_REFRESH_SECRET="taskboard-refresh-secret-2024"
JWT_ACCESS_EXPIRY="15m"
JWT_REFRESH_EXPIRY="7d"
PORT=3000
NODE_ENV="development"
CORS_ORIGIN="http://localhost:5173"Create frontend/.env:
VITE_API_URL=http://localhost:3000/apicd backend
npx prisma db push
# or: npx prisma migrate dev --name initNote: You may see a warning about
urlanddirectUrlinschema.prismaβ ignore it, it does not affect functionality.
# Terminal 1 β Backend β http://localhost:3000
cd backend
npm run dev
# Terminal 2 β Frontend β http://localhost:5173
cd frontend
npm run dev| Method | Endpoint | Description |
|---|---|---|
| POST | /api/auth/register |
Register a new user |
| POST | /api/auth/login |
Login, sets HTTP-only cookie |
| POST | /api/auth/refresh |
Issue new access token |
| POST | /api/auth/logout |
Clear cookies, invalidate session |
| Method | Endpoint | Description |
|---|---|---|
| GET | /api/projects |
Get all projects for current user |
| POST | /api/projects |
Create project (Global Admin only) |
| GET | /api/projects/:id |
Get project details and members |
| GET | /api/boards/:id |
Get board with columns |
| PUT | /api/boards/:id/columns |
Update Kanban columns (Project Admin only) |
| Method | Endpoint | Description |
|---|---|---|
| POST | /api/issues |
Create a new issue |
| GET | /api/issues/:id |
Get issue with comments and audit log |
| PUT | /api/issues/:id |
Update issue metadata |
| PATCH | /api/issues/:id/move |
Move issue β triggers workflow + WIP validation |
| DELETE | /api/issues/:id |
Delete an issue |
| GET | /api/issues/:id/audit |
Get audit log for an issue |
| Method | Endpoint | Description |
|---|---|---|
| POST | /api/issues/:issueId/comments |
Add a comment |
| DELETE | /api/comments/:id |
Delete own comment |
| GET | /api/notifications |
Get notifications for current user |
| PATCH | /api/notifications/:id/read |
Mark notification as read |
Backend unit tests cover core business logic, workflow validation, WIP enforcement, and RBAC constraints.
cd backend
npm run test- No external WYSIWYG library β the assignment prohibits libraries not listed in the spec. The rich text editor is built from scratch using the browser's native
contenteditableAPI anddocument.execCommand. - No external DnD library β drag and drop is implemented using the native HTML5 Drag and Drop API as required.
- Workflow transitions are server-enforced β invalid moves are rejected at the API level with a
400error, not just a frontend warning. - Story status is auto-derived β when all children reach
Done, the parent Story auto-transitions. If children areIn ProgressorReview, the Story moves toIn Progress. - Audit log is append-only β events are never edited or deleted, maintaining a reliable history.
- Prisma + PostgreSQL β chosen for type-safe queries and easy schema migrations.