Full-stack product · Live application

CampusHelper

A campus lost-and-found platform with authenticated reports, image uploads, searchable records, claims, and moderation workflows.

Problem

Campus lost-and-found is usually handled in scattered chat groups, so records disappear and ownership claims are difficult to verify or follow up.

System

A Next.js App Router application with Google sign-in through NextAuth, PostgreSQL via Prisma on Supabase, image storage buckets, Zod-validated APIs, rate limiting, and row-level security, plus an admin moderation dashboard.

Proof

  • Live platform with authenticated item reports, image uploads, search, claims, and comments.
  • Server-side validation with Zod, CSRF protection, rate limiting, and database-level RLS.
  • Admin dashboard backed by moderation and management workflows.

Architecture

  1. ReportA signed-in user posts a lost or found item with photos and details.
  2. DiscoverOther users search and filter records by type, location, date, and keywords.
  3. ClaimOwners and finders coordinate through claims and comments.
  4. ModerateAdmins review reports and manage the listing lifecycle.

Decisions

  • Keep authentication, uploads, and claims behind explicit server-side boundaries.
  • Enforce access at the database with row-level security instead of relying only on application checks.
  • Validate inputs server-side with shared Zod schemas.

Tradeoffs and limitations

  • Managed Supabase storage and auth reduce operational work but tie the stack to one platform.
  • Moderation tooling covers review basics without advanced automation.

Technologies

  • Next.js
  • TypeScript
  • PostgreSQL
  • Prisma
  • Supabase
  • NextAuth