Skip to content

Peer‐review

ArkadSt edited this page Dec 2, 2024 · 20 revisions

DigiDoc4Business peer-review

This is review of the project DigiDoc4Business as part of the course Software Project at the University of Tartu.

Installation

Everything works fine.

Frontend review

It is not documented that in order for application to work you have to change baseURL to your machine's IP address. Had to figure that out by inspecting the code. In fact (at least when testing both the server and the client on the same machine) 127.0.0.1 could be used.

Upon 'successful' signing the user is not sent back to the MyFiles screen and is stuck on the Verification screen. I solved this for myself by adding <Stack.Screen name="MyFiles" component={MyFiles} /> line to the NavigationContainer. Drawer manu doesn't come back though.

If you want to cancel signing by hitting 'back' arrow on the verification screen you are logged out, which I assume is not an intended behavior.

Backend review

Perhaps it would be better if backend, as a REST application, would always return data in JSON format when HTTP requests are made to it.

Appropriate HTTP status codes should be used (https://www.baeldung.com/rest-api-error-handling-best-practices) including on success. For example code 201 when file is uploaded. Consider using ResponseEntity for HTTP responses.

Some business logic is in the Controller classes. It should be separated.

Unauthorized users shouldn't have access to uploads. At the moment I can download files belonging to any user with a simple GET request (curl http://localhost:8064/files?personalId=00000000000&fileName=test.txt)

Requirements

The biggest problem is that signing doesn't work, unfortunately. I have communicated that issue with the team and the problem might be with the Smart-ID DEMO application itself. The reason is not entirely clear at this point as the team hasn't received an answer for that question from the Smart-ID developers whom they have contacted.

Other

Tests are absent.

Summary

I would suggest to focus on delivering a working demo as right now there are problems UI and signing. A possibility to work with signed files should also be added. Tests should be added. Documentation should be improved. All relevant issues (like with signing) should be documented (may also add descriptive issues to the issue tracker). If some functionality (like signing) cannot be delivered, this should be handled gracefully, for example by displaying an error message to the user. BTW the message "Signature service timed out after 20 seconds." should not be returned as a success (code 200 as it is now), but rather as an error with the relevant HTTP status code (for example code 500 "internal server error" or 503 "service unavailable").

Clone this wiki locally