TaskFlow β Collaborative Task Manager
A production-grade, FAANG-level collaborative task management application with real-time Kanban boards, built with modern full-stack technologies.
Backend: http://localhost:5000
Frontend: http://localhost:5173 (or next available port)
Login: demo@taskflow.dev / password123
Kanban Boards β Drag-and-drop tasks between columns with @dnd-kit
Real-time Collaboration β Socket.io presence, live updates, typing indicators
Workspaces & Boards β Hierarchical organization with auto-board creation
Task Management β Full CRUD, priorities, due dates, assignees, labels, comments
Optimistic Concurrency Control β Version field on every task, 409 Conflict on stale writes
Gap-based Positioning β Float positions with automatic column rebalance when gaps < 0.001
Server-side RBAC β OWNER > ADMIN > MEMBER > VIEWER enforced on every mutating endpoint
Idempotency Keys β Idempotency-Key header prevents duplicate task creation on retries
Atomic Transactions β Prisma $transaction for task + activity log writes
Observability & Reliability
Health Checks β /api/health (liveness) + /api/ready (readiness with DB/Redis)
Rate Limiting β Auth endpoints (strict) + API endpoints (standard) with Redis fallback
Structured Logging β Request IDs, JSON logs, error taxonomy
Unit Tests β Vitest with positionService coverage (5/5 passing)
Dark Mode β Toggle in top bar, persists to localStorage, darkMode: 'class' in Tailwind
Keyboard Accessible β Full @dnd-kit keyboard support
Responsive Design β Mobile sidebar, horizontal scroll on boards
Notifications β Real-time + REST, mark-as-read, mark-all-read
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β Frontend β β Backend β β Database β
β React 18 ββββββΊβ Node/Express ββββββΊβ PostgreSQL 17 β
β Vite + TS β β Prisma ORM β β (Postgres) β
β TanStack Queryβ β Socket.io β β Redis (opt) β
β Tailwind CSS β β Zod + JWT β β β
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
Key Design Decisions (ADRs)
ADR
Topic
001
PostgreSQL as primary database
002
Socket.io for real-time
003
Optimistic updates with OCC
004
Cursor-based pagination
005
Redis for caching/rate-limit
006
REST + WebSocket separation
Layer
Technology
Frontend
React 18, Vite, TanStack Query v5, React Router v6, @dnd-kit, Tailwind CSS, Lucide React
Backend
Node.js, Express, Prisma ORM, Socket.io, Zod, bcryptjs, jsonwebtoken
Database
PostgreSQL 17, Prisma Migrations
Cache/Queue
Redis (ioredis) with in-memory fallback
Auth
JWT (HS256), bcrypt, HttpOnly-ready
Testing
Vitest, Supertest
CI/CD
GitHub Actions, Docker Compose
Node.js 20+
PostgreSQL 17
Redis (optional β in-memory fallback used if unavailable)
git clone https://github.com/YOUR_USERNAME/taskflow.git
cd taskflow
# Backend
cd server
npm install
# Frontend
cd ../client
npm install
cd server
cp .env.example .env
# Edit .env with your DATABASE_URL, JWT_SECRET, REDIS_URL
cd server
npx prisma migrate dev --name init
npm run seed
# Terminal 1 β Backend
cd server
npm run dev # β http://localhost:5000
# Terminal 2 β Frontend
cd client
npm run dev # β http://localhost:5173
Email: demo@taskflow.dev
Password: password123
docker-compose up -d
# Services: postgres, redis, server (5000), client (5173)
Variable
Description
Default
DATABASE_URL
PostgreSQL connection string
Required
JWT_SECRET
64+ char secret for JWT
Required
REDIS_URL
Redis connection string
Optional
PORT
Backend port
5000
CLIENT_URL
Frontend origin for CORS
http://localhost:5173
NODE_ENV
Environment
development
Method
Endpoint
Description
POST
/api/auth/register
Register new user
POST
/api/auth/login
Login, returns JWT
GET
/api/auth/me
Get current user
POST
/api/auth/logout
Logout (stateless)
Method
Endpoint
Description
GET
/api/workspaces
List user's workspaces (with boards)
POST
/api/workspaces
Create workspace + default board
GET
/api/workspaces/:id
Get workspace
PATCH
/api/workspaces/:id
Update workspace
DELETE
/api/workspaces/:id
Delete workspace
Method
Endpoint
Description
GET
/api/boards/workspace/:id
List boards in workspace
POST
/api/boards/workspace/:id
Create board + default columns
GET
/api/boards/:id
Get board
GET
/api/boards/:id/data
Full board (columns + nested tasks)
PATCH
/api/boards/:id
Update board
DELETE
/api/boards/:id
Delete board
Method
Endpoint
Description
POST
/api/columns/board/:id
Create column
PATCH
/api/columns/:id
Update column (name, position)
DELETE
/api/columns/:id
Delete column
Method
Endpoint
Description
GET
/api/tasks/board/:id
Paginated tasks (cursor-based)
POST
/api/tasks/board/:id
Create task (idempotent)
PATCH
/api/tasks/:id
Update task (requires version)
POST
/api/tasks/:id/move
Move task (column + position)
DELETE
/api/tasks/:id
Delete task
Comments
Method
Endpoint
Description
GET
/api/comments/task/:id
Get comments for task
POST
/api/comments/task/:id
Add comment
Method
Endpoint
Description
GET
/api/notifications
List user notifications
PATCH
/api/notifications/:id/read
Mark as read
POST
/api/notifications/read-all
Mark all as read
Method
Endpoint
Description
GET
/api/health
Liveness probe
GET
/api/health/ready
Readiness probe (DB + Redis)
JWT Authentication β HS256, 7-day expiry, stateless
Password Hashing β bcrypt (cost 10)
RBAC β Server-side on every mutating endpoint
Rate Limiting β Auth: 5 req/min, API: 100 req/min
Helmet β Security headers (CSP, HSTS, etc.)
CORS β Configured for frontend origin only
Input Validation β Zod schemas on all endpoints
cd server
npm test # Run all tests (Vitest)
npm run test:watch # Watch mode
positionService β 5/5 tests passing (gap-based ordering, rebalance)
Integration tests for auth, workspaces, tasks (configured)
taskflow/
βββ client/ # React frontend
β βββ src/
β β βββ components/ # Layout, ProtectedRoute
β β βββ context/ # AuthContext, SocketContext
β β βββ pages/ # Login, Register, Dashboard, Board, Workspaces
β β βββ services/ # API client (axios)
β β βββ main.jsx # Entry point
β βββ ...
βββ server/ # Node/Express backend
β βββ src/
β β βββ middleware/ # auth, authorize, validate, rateLimiter, idempotency
β β βββ routes/ # auth, workspaces, boards, tasks, comments, notifications, activity, health
β β βββ services/ # taskService, positionService, notificationService, activityService
β β βββ utils/ # prisma, redis, logger, events, schemas, permissions, response
β β βββ middleware/ # errorHandler, requestId, requestLogger
β β βββ app.js # Express app factory
β β βββ index.js # Entry point (routes + socket)
β β βββ config.js # Centralized config
β βββ prisma/ # Schema + migrations + seed
β βββ tests/ # Vitest unit tests
βββ docs/ # Architecture + ADRs
β βββ ADR/ # 6 Architecture Decision Records
β βββ ARCHITECTURE.md
β βββ DATABASE.md
β βββ CONCURRENCY.md
β βββ REALTIME.md
β βββ SCALABILITY.md
β βββ SECURITY.md
β βββ AUTH.md
β βββ CACHING.md
βββ docker-compose.yml # Postgres + Redis + App
Fork the repository
Create a feature branch (git checkout -b feature/amazing-feature)
Commit changes (git commit -m 'feat: add amazing feature')
Push to branch (git push origin feature/amazing-feature)
Open a Pull Request
MIT License β see LICENSE for details.
Built with β€οΈ using modern full-stack best practices. Inspired by Linear, Notion, and GitHub Projects.