Skip to content
→ All work

Case study 05 / 26

Geoland System

Ticketing, supplier and finance system for a Nepal-based travel business — per-currency supplier ledgers, signed private attachments, WhatsApp confirmations and an end-to-end test suite.

Status
Deployed
Domain
web · cloud · security
Source of claims
Private repository README (reviewed). Source and deployment are not public.

An Express 5 + Prisma 7 API and a React 19 single-page app for the people who issue tickets every day. Support agents manage their own tickets; admins see users, expenses, the financial dashboard and broadcasts. Deployed on free tiers across Cloudflare, Render, Neon and Backblaze B2, with nightly encrypted backups.

01/The problem

A travel desk issuing tickets through many suppliers, in more than one currency, needs to know what it owes each supplier at any moment — and needs the one destructive action in the system to be impossible to trigger by accident or by a junior account.

02/The system

An Express 5 + Prisma 7 API and a React 19 single-page app for the people who issue tickets every day. Support agents manage their own tickets; admins see users, expenses, the financial dashboard and broadcasts. Deployed on free tiers across Cloudflare, Render, Neon and Backblaze B2, with nightly encrypted backups.

Deployment topology6 components
  • React SPA to Express 5 API
  • Express 5 API to Private bucket
  • Express 5 API to PostgreSQL
  • Express 5 API to WhatsApp
  • PostgreSQL to Nightly backup

03/Scope

  1. 01Two roles: support agents create and manage their own tickets; admins add users, expenses, the financial dashboard and broadcasts.
  2. 02Authorization enforced server-side on every route; the admin namespace is gated at the router and again inside each controller.
  3. 03Attachments and receipts upload straight from the browser to a private bucket via presigned URLs; responses only ever carry signed read URLs.
  4. 04Per-supplier ledgers with running balances per currency and a CSV balance-sheet export.
  5. 05WhatsApp booking confirmations and broadcasts.
  6. 06Health and readiness endpoints; configuration validated at boot so a bad environment fails immediately.

04/Engineering

Balances are derived, never stored

Closing balance = opening balance − cost of that supplier's tickets, computed on every read from what the company paid (never the selling price). New, edited, moved or deleted tickets show up instantly with nothing to invalidate.

Currencies never mix

Opening balances are one row per supplier per currency, so SAR and NPR stay independent and no cross-currency total exists anywhere. Negative balances are shown, not clamped.

One irreversible operation, fenced

Deleting a supplier re-reads the caller's role from the database instead of trusting the seven-day token, runs in a single transaction with its audit row, and deliberately keeps customers, expenses and the audit trail.

Tests that cannot hurt production

Integration tests run against a real Postgres, and the helpers refuse to run unless the database name contains 'test'. Playwright drives the real UI against a real backend.

05/Interface

Interface screenshots of this commercial product are not public. The visual above is an abstract representation of its modules — not the product itself.

06/Tech stack

  • Express 5
  • Prisma 7
  • PostgreSQL 16
  • React 19
  • Vite 7
  • Tailwind CSS 4
  • Playwright
  • Cloudflare Workers
  • Render
  • Neon
  • Backblaze B2
  • GitHub Actions

07/Result

Verified outcomes

  • Deployed on Cloudflare Workers, Render, Neon and Backblaze B2 — all on free tiers.
  • Every push and pull request is verified before deploy; the database is backed up and encrypted nightly.

08/Links

Private commercial codebase — no public links.

Next case study

DataAttendance →