Case study 05 / 26
Geoland System
Ticketing, supplier and finance system for a Nepal-based travel business — per-currency supplier ledgers, signed private attachments, WhatsApp confirmations and an end-to-end test suite.
- Status
- Deployed
- Domain
- web · cloud · security
- Source of claims
- Private repository README (reviewed). Source and deployment are not public.
An Express 5 + Prisma 7 API and a React 19 single-page app for the people who issue tickets every day. Support agents manage their own tickets; admins see users, expenses, the financial dashboard and broadcasts. Deployed on free tiers across Cloudflare, Render, Neon and Backblaze B2, with nightly encrypted backups.
01/The problem
A travel desk issuing tickets through many suppliers, in more than one currency, needs to know what it owes each supplier at any moment — and needs the one destructive action in the system to be impossible to trigger by accident or by a junior account.
02/The system
An Express 5 + Prisma 7 API and a React 19 single-page app for the people who issue tickets every day. Support agents manage their own tickets; admins see users, expenses, the financial dashboard and broadcasts. Deployed on free tiers across Cloudflare, Render, Neon and Backblaze B2, with nightly encrypted backups.
- React SPA to Express 5 API
- Express 5 API to Private bucket
- Express 5 API to PostgreSQL
- Express 5 API to WhatsApp
- PostgreSQL to Nightly backup
03/Scope
- 01Two roles: support agents create and manage their own tickets; admins add users, expenses, the financial dashboard and broadcasts.
- 02Authorization enforced server-side on every route; the admin namespace is gated at the router and again inside each controller.
- 03Attachments and receipts upload straight from the browser to a private bucket via presigned URLs; responses only ever carry signed read URLs.
- 04Per-supplier ledgers with running balances per currency and a CSV balance-sheet export.
- 05WhatsApp booking confirmations and broadcasts.
- 06Health and readiness endpoints; configuration validated at boot so a bad environment fails immediately.
04/Engineering
Balances are derived, never stored
Closing balance = opening balance − cost of that supplier's tickets, computed on every read from what the company paid (never the selling price). New, edited, moved or deleted tickets show up instantly with nothing to invalidate.
Currencies never mix
Opening balances are one row per supplier per currency, so SAR and NPR stay independent and no cross-currency total exists anywhere. Negative balances are shown, not clamped.
One irreversible operation, fenced
Deleting a supplier re-reads the caller's role from the database instead of trusting the seven-day token, runs in a single transaction with its audit row, and deliberately keeps customers, expenses and the audit trail.
Tests that cannot hurt production
Integration tests run against a real Postgres, and the helpers refuse to run unless the database name contains 'test'. Playwright drives the real UI against a real backend.
05/Interface
Interface screenshots of this commercial product are not public. The visual above is an abstract representation of its modules — not the product itself.
06/Tech stack
- Express 5
- Prisma 7
- PostgreSQL 16
- React 19
- Vite 7
- Tailwind CSS 4
- Playwright
- Cloudflare Workers
- Render
- Neon
- Backblaze B2
- GitHub Actions
07/Result
Verified outcomes
- Deployed on Cloudflare Workers, Render, Neon and Backblaze B2 — all on free tiers.
- Every push and pull request is verified before deploy; the database is backed up and encrypted nightly.
08/Links
Private commercial codebase — no public links.
Next case study
DataAttendance →