CampusHelper
A campus lost-and-found platform with authenticated reports, image uploads, searchable records, claims, and moderation workflows.
Problem
Campus lost-and-found is usually handled in scattered chat groups, so records disappear and ownership claims are difficult to verify or follow up.
System
A Next.js App Router application with Google sign-in through NextAuth, PostgreSQL via Prisma on Supabase, image storage buckets, Zod-validated APIs, rate limiting, and row-level security, plus an admin moderation dashboard.
Proof
- Live platform with authenticated item reports, image uploads, search, claims, and comments.
- Server-side validation with Zod, CSRF protection, rate limiting, and database-level RLS.
- Admin dashboard backed by moderation and management workflows.
Architecture
- ReportA signed-in user posts a lost or found item with photos and details.
- DiscoverOther users search and filter records by type, location, date, and keywords.
- ClaimOwners and finders coordinate through claims and comments.
- ModerateAdmins review reports and manage the listing lifecycle.
Decisions
- Keep authentication, uploads, and claims behind explicit server-side boundaries.
- Enforce access at the database with row-level security instead of relying only on application checks.
- Validate inputs server-side with shared Zod schemas.
Tradeoffs and limitations
- Managed Supabase storage and auth reduce operational work but tie the stack to one platform.
- Moderation tooling covers review basics without advanced automation.
Technologies
- Next.js
- TypeScript
- PostgreSQL
- Prisma
- Supabase
- NextAuth