An enterprise-grade, serverless fullstack web application combining bank-grade authentication, multi-factor security, a public developer portfolio hub (/@username), an interactive project showcase engine, a rich Markdown blogging platform, and real-time visitor analytics.
Explore Features β’ System Architecture β’ Quick Start β’ Documentation
Modern developers and software creators often struggle with fragmented digital identitiesβmaintaining separate, paid subscriptions for authentication boilerplates (Auth0/Clerk), link-in-bio pages (Linktree/Bento), technical blogs (Medium/Dev.to), project showcases, and analytics tools.
This repository provides an all-in-one, self-hosted, serverless-native platform that brings these essential capabilities together into a cohesive ecosystem. Deployed on AWS Serverless (Lambda, DynamoDB, S3, API Gateway) and Vercel (Next.js 16), it offers near-zero idle cost, unlimited on-demand scalability, and 100% data ownership.
- Credential-Based Auth: Secure user signup and login with salted
bcryptpassword hashing (cost factor 10). - 6-Digit Email Verification: One-time verification tokens with a strict 15-minute expiration window.
- Social OAuth 2.0 Sign-In: One-click authentication with Google (
passport-google-oauth20) and GitHub (passport-github2). - Account Linking & Disconnection: Seamlessly connect or disconnect social providers from within the dashboard.
- Two-Factor Authentication (TOTP / MFA): Standard-compliant RFC 6238 time-based one-time password security via
speakeasywith QR code generation viaqrcode(compatible with Google Authenticator, Authy, and 1Password). - Multi-Device Session Tracking: Full visibility into active sessions (IP address, user-agent device, creation date) with remote session revocation ("Revoke other sessions").
- Security Audit Trail & Alerts: Tamper-evident activity logs recording IP, timestamp, action, and geolocated city/country, plus automated email alerts on new logins.
- Rate Limiting: Sliding-window protection on authentication endpoints to defend against automated brute-force attacks.
- Personalized Vanity Routing: Clean, branded user profiles at
https://platform.domain/@username. - Link-in-Bio Hub: Configurable list of custom outbound links with real-time click tracking.
- Developer Social Links: Direct integration for GitHub, Twitter/X, and LinkedIn profiles.
- Interactive Profile Tabs: Tabbed navigation across developer Overview, Projects Showcase, and Published Articles.
- Appearance Customizer: User-selectable profile themes (Dark, Light, Custom accent color variables).
- Privacy Toggle: Instant switch between public and private profile visibility.
- Rich Metadata Model: Detail project difficulty, duration, team size, company/client name, license, and progress percentage.
- Multi-Media Showcase: Support for cover images, logos, thumbnails, video demos, and screenshot galleries.
- Code & Docs Links: Direct shortcuts to GitHub repositories, live deployments, API docs, and downloadable assets.
- Built-in Engagement Counters: Track views, likes, stars, forks, comments, and downloads.
- SEO Management: Custom
metaTitle,metaDescription,keywords,canonicalUrl, and OpenGraph images per project.
- Rich Content Authoring: Write articles using Markdown powered by
react-markdown,remark-gfm, andrehype-raw. - Draft & Publishing Lifecycle: Work on drafts in private before publishing to the global
/blogfeed. - Discovery & Search: Auto-generated URL slugs, category filters, multi-tag search, and instant full-text search.
- Privacy-First Metrics: First-party tracking for profile visits (
track-view) and outbound link clicks (track-click). - IP Geolocation Resolution: Automatic conversion of visitor IPs to City and Country using
ipinfo.ioandfreeipapi.com. - Interactive Visualizations: Dual-metric 7-day trend charts (Views vs. Clicks) rendered using
recharts. - Actionable Insights: Live Click-Through Rate (CTR) calculations, top-performing links ranking, and geographic audience breakdowns.
- AWS Serverless Backbone: AWS Lambda API wrapped with
serverless-httpand routed through Amazon API Gateway HTTP API. - Amazon DynamoDB: 7 high-performance, on-demand tables with Global Secondary Indexes (GSIs).
- Amazon S3 Presigned Uploads: Direct client-to-bucket media uploads via
@aws-sdk/s3-request-presigner, avoiding API payload limits. - Transactional Emails: HTML email notifications delivered via
nodemailerusing responsive Handlebars (.hbs) templates.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β CLIENT / VISITOR BROWSER β
βββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββ
β β
βΌ βΌ
βββββββββββββββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββββ
β FRONTEND (Vercel Network) β β Amazon S3 (Uploads) β
β β’ Next.js 16 App Router (React 19) β β β’ Direct Presigned PUTs β
β β’ Tailwind CSS v4 + Motion + Recharts β β β’ Avatars, Covers, Gallery β
β β’ Public Pages: Landing, /@user, /blogβ ββββββββββββββββ²βββββββββββββββ
β β’ Private Pages: Dashboard, Settings β β
βββββββββββββββββββββ¬ββββββββββββββββββββ β Presigned URLs
β HTTPS API Requests β
βΌ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ΄βββββββββββββββ
β BACKEND (AWS Serverless ap-south-1) β
β β’ Amazon API Gateway (Greedy Proxy Ingress: /{proxy+}) β
β β’ AWS Lambda (Node.js 20.x runtime with Express 5 & serverless-http) β
β β’ Passport.js (Google & GitHub OAuth 2.0) β
β β’ Speakeasy (TOTP 2FA) & JWT Token Generation β
β β’ Nodemailer Email Engine (AWS SES / SMTP) β
βββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β AMAZON DYNAMODB (NoSQL Storage) β
β β’ auth-users β’ auth-user-sessions β’ auth-audit-logs β
β β’ auth-analytics β’ auth-blogs β’ auth-projects β
β β’ express-sessions (connect-dynamodb) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
my-app/
βββ Documentation/ # Comprehensive Architectural Docs
β βββ 01_APPLICATION_PURPOSE_AND_USE_CASES.md # Purpose, problem statement & personas
β βββ 02_FEATURES_AND_INTEGRATIONS_GUIDE.md # Feature matrix & technical integrations
β βββ 03_BACKEND_FRONTEND_ARCHITECTURE_AND_SERVICES.md # Topology, connectivity & cloud services
β
βββ auth-backend/ # Express.js & AWS Serverless Backend
β βββ config/passport.js # Google & GitHub OAuth strategies
β βββ controllers/ # Auth, settings, blog, project & analytics controllers
β βββ middleware/ # JWT auth validation & rate-limiting middleware
β βββ routes/ # Express API route declarations
β βββ templates/ # Handlebars (.hbs) email templates
β βββ utils/ # Email delivery, IP geolocation & logging helpers
β βββ db.js # DynamoDB DocumentClient ORM abstraction
β βββ app.js # Express app configuration & CORS setup
β βββ server.js # Local Node.js HTTP server entry point
β βββ lambda.js # AWS Lambda serverless handler entry point
β βββ template.yaml # AWS SAM / CloudFormation Infrastructure-as-Code
β
βββ auth-frontend/ # Next.js 16 App Router Frontend
βββ src/
β βββ app/
β β βββ (auth)/ # Login, Signup, MFA, Password Reset flows
β β βββ [username]/ # Public vanity portfolio hub (/@username)
β β βββ blog/ # Public blog feed & article reader
β β βββ projects/ # Public project showcase gallery
β β βββ dashboard/ # Creator dashboard, analytics, audit logs, CMS
β β βββ page.tsx # High-conversion landing page
β βββ components/ # UI components (Base UI, Lucide, Charts)
β βββ lib/ # API clients, token store & S3 upload helpers
βββ package.json
- Node.js: v20.x or later installed
- npm: v10.x or later installed
- AWS CLI & SAM CLI: (Optional, only required for AWS cloud deployment)
git clone https://github.com/krishna99-tech/fullstack-auth-platform.git
cd fullstack-auth-platform-
Navigate into the backend directory and install dependencies:
cd auth-backend npm install -
Create your environment file from
.env.example:cp .env.example .env
-
Populate the required environment variables:
PORT=5000 FRONTEND_URL=http://localhost:3000 BACKEND_URL=http://localhost:5000 JWT_SECRET=your_super_secret_jwt_key_here # AWS / DynamoDB Configuration AWS_REGION=ap-south-1 USERS_TABLE=auth-users AUTH_SESSIONS_TABLE=auth-user-sessions AUDIT_LOGS_TABLE=auth-audit-logs ANALYTICS_TABLE=auth-analytics BLOGS_TABLE=auth-blogs PROJECTS_TABLE=auth-projects SESSIONS_TABLE=express-sessions # OAuth 2.0 Credentials (Optional for local dev) GOOGLE_CLIENT_ID=your_google_client_id GOOGLE_CLIENT_SECRET=your_google_client_secret GITHUB_CLIENT_ID=your_github_client_id GITHUB_CLIENT_SECRET=your_github_client_secret # SMTP Configuration (Optional for emails) SMTP_HOST=smtp.gmail.com SMTP_PORT=587 SMTP_USER=your_email@gmail.com SMTP_PASS=your_app_password SMTP_FROM="Platform <no-reply@yourdomain.com>"
-
Launch the local API server:
npm start # Server will run at http://localhost:5000 # Health check available at http://localhost:5000/health
-
In a new terminal window, navigate into the frontend directory:
cd auth-frontend npm install -
Create your local environment configuration:
cp .env.example .env.local
-
Set your backend connection endpoint:
NEXT_PUBLIC_API_URL=http://localhost:5000/api -
Start the Next.js development server:
npm run dev # Frontend will run at http://localhost:3000 -
Open http://localhost:3000 in your browser to explore the landing page, register an account, and customize your profile!
The backend includes an automated deployment script that reads your .env variables and builds the AWS CloudFormation stack:
cd auth-backend
# First time guided deployment:
npm run deploy:guided
# Subsequent automated deployments:
npm run deploy:env- Import the
auth-frontenddirectory into your Vercel Dashboard. - Set the Environment Variable:
NEXT_PUBLIC_API_URL=https://${YOUR_API_ID}.execute-api.ap-south-1.amazonaws.com/Prod/api
- Click Deploy.
For in-depth architectural breakdowns, visit the Documentation/ directory:
- 01_APPLICATION_PURPOSE_AND_USE_CASES.md
Covers the core problem statement, executive vision, user personas, real-world workflows, and business value. - 02_FEATURES_AND_INTEGRATIONS_GUIDE.md
Comprehensive technical guide covering the auth subsystem, project portfolio CMS, markdown blog engine, analytics tracking, and email templates. - 03_BACKEND_FRONTEND_ARCHITECTURE_AND_SERVICES.md
Explains how the frontend and backend communicate, where the backend runs, CORS security, token storage, and AWS services utilized.
- Passwords: Salted with
bcryptbefore storage; raw passwords are never logged or stored. - Tokens: Signed with asymmetric or high-entropy symmetric secrets with strict expiration.
- File Uploads: S3 bucket permissions are protected using presigned PUT URLs with sanitization, avoiding arbitrary executable uploads.
- Rate Limiting: Enforced on high-risk endpoints to deter automated credential-stuffing attacks.
This project is licensed under the ISC License.