Skip to content

My Contributions

BrandonRobare edited this page Jun 2, 2026 · 1 revision

My Contributions

This page records the work I did on ShyneBeauty, with credit to the team at the end.

Data model

I designed the SQLite schema in schema.sql and the matching SQLAlchemy models in shyne_app/models.py. That covers customers, products, ingredients, batches, product lots, orders, order items, batch ingredients, order status events, and shipments. I chose the foreign-key rules deliberately: cascade deletes for an order's children, restricted deletes for products and customers that carry history, and a null-on-delete for the lot reference on an order line so the line survives if a lot is removed. I added the indexes that back the search and filter on each list page.

Authentication

I built the account system on a separate auth database so credentials stay isolated from business data. It hashes passwords with Werkzeug PBKDF2 (pbkdf2:sha256:1000000), enforces a password policy (12-character minimum, no email fragments, no demo fallbacks), and runs a forced password-change flow for temporary credentials. I added per-account lockout after repeated failures and a per-IP login throttle, both with expiry windows. I implemented opt-in TOTP multi-factor auth end to end: QR-code enrollment, the challenge step at login, and enable/disable from account settings, with elevated roles nudged to enroll.

Access control

I wrote the role and permission layer in shyne_app/access.py. Four roles, Staff Operator, Inventory / Production, Superadmin, and Dev Admin, map to permission bundles, and a require_permission decorator gates every route. Superadmins manage staff through a console I built: invite, activate, resend, cancel, change role, suspend, reactivate, and set a temporary password. Each action writes an audit event with before and after state, and a guard stops anyone from removing the last active Superadmin.

Business workflows

I implemented the operational pages in shyne_app/routes.py:

  • The dashboard, with order counts by channel, an intake queue, a ready-to-ship queue, and low-stock alerts.
  • Order entry with multiple line items, server-side validation, an auto-generated order number, a computed total, and an initial status event.
  • The customer database with create, edit, and search.
  • Ingredient inventory with stock and reorder thresholds and a stock-status filter.
  • Product and product-batch management, including auto-generated batch codes and lot numbers when a product is first created.

Security middleware

I added the request-lifecycle protections in shyne_app/auth.py: CSRF protection on every form, a content security policy and the other response headers, safe handling of next redirect targets to block open redirects, no-store caching on sensitive pages, an HTTPS redirect under live-prod, and session revocation when an account is suspended mid-session. The small in-process rate limiter in shyne_app/rate_limit.py covers the sensitive POST paths.

Structure, CLI, and tooling

I split the original single-file app into the shyne_app/ package and kept the public imports stable. I wrote the Click CLI in shyne_app/cli.py for database setup (init-db, init-live-db), admin creation (create-admin, create-dev-admin), demo seeding, an access backfill command, and a hashed tar.gz backup (export-data). I set up the pytest suite and the GitHub Actions CI: the Python 3.10 and 3.12 matrix, the Playwright accessibility smoke job, and the CodeQL, dependency-review, and gitleaks scanning workflows.

Team

ShyneBeauty was a Kent State University Capstone team project, Spring 2026. My teammates were Melanie Waddle, Bianca Amoako, and Peyton Fazio, who contributed to planning, requirements, and review across the term.

Clone this wiki locally