-
Notifications
You must be signed in to change notification settings - Fork 0
My Contributions
This page records the work I did on ShyneBeauty, with credit to the team at the end.
I designed the SQLite schema in schema.sql and the matching SQLAlchemy models in shyne_app/models.py. That covers customers, products, ingredients, batches, product lots, orders, order items, batch ingredients, order status events, and shipments. I chose the foreign-key rules deliberately: cascade deletes for an order's children, restricted deletes for products and customers that carry history, and a null-on-delete for the lot reference on an order line so the line survives if a lot is removed. I added the indexes that back the search and filter on each list page.
I built the account system on a separate auth database so credentials stay isolated from business data. It hashes passwords with Werkzeug PBKDF2 (pbkdf2:sha256:1000000), enforces a password policy (12-character minimum, no email fragments, no demo fallbacks), and runs a forced password-change flow for temporary credentials. I added per-account lockout after repeated failures and a per-IP login throttle, both with expiry windows. I implemented opt-in TOTP multi-factor auth end to end: QR-code enrollment, the challenge step at login, and enable/disable from account settings, with elevated roles nudged to enroll.
I wrote the role and permission layer in shyne_app/access.py. Four roles, Staff Operator, Inventory / Production, Superadmin, and Dev Admin, map to permission bundles, and a require_permission decorator gates every route. Superadmins manage staff through a console I built: invite, activate, resend, cancel, change role, suspend, reactivate, and set a temporary password. Each action writes an audit event with before and after state, and a guard stops anyone from removing the last active Superadmin.
I implemented the operational pages in shyne_app/routes.py:
- The dashboard, with order counts by channel, an intake queue, a ready-to-ship queue, and low-stock alerts.
- Order entry with multiple line items, server-side validation, an auto-generated order number, a computed total, and an initial status event.
- The customer database with create, edit, and search.
- Ingredient inventory with stock and reorder thresholds and a stock-status filter.
- Product and product-batch management, including auto-generated batch codes and lot numbers when a product is first created.
I added the request-lifecycle protections in shyne_app/auth.py: CSRF protection on every form, a content security policy and the other response headers, safe handling of next redirect targets to block open redirects, no-store caching on sensitive pages, an HTTPS redirect under live-prod, and session revocation when an account is suspended mid-session. The small in-process rate limiter in shyne_app/rate_limit.py covers the sensitive POST paths.
I split the original single-file app into the shyne_app/ package and kept the public imports stable. I wrote the Click CLI in shyne_app/cli.py for database setup (init-db, init-live-db), admin creation (create-admin, create-dev-admin), demo seeding, an access backfill command, and a hashed tar.gz backup (export-data). I set up the pytest suite and the GitHub Actions CI: the Python 3.10 and 3.12 matrix, the Playwright accessibility smoke job, and the CodeQL, dependency-review, and gitleaks scanning workflows.
ShyneBeauty was a Kent State University Capstone team project, Spring 2026. My teammates were Melanie Waddle, Bianca Amoako, and Peyton Fazio, who contributed to planning, requirements, and review across the term.