Project · L02 Auth & Security
CanvasFlow
A privacy-first academic dashboard that connects to any university’s Canvas LMS, keeps student tokens encrypted and pushes changes the moment they happen.
- Role
- Full-stack developer
- Period
- Sep 2026 — present
- Stack
-
- Next.js
- React
- TypeScript
- Prisma
- Supabase
- Auth.js
- AES-256-GCM
- Web Push
Context
Students at ELTE and many other universities live in Canvas LMS, but its notifications are slow and scattered. CanvasFlow is an open-source command centre that works with any Canvas institution.
What I built
- Multi-university support. Users connect their own Canvas URL and personal access token.
- Token security. Tokens are encrypted at rest with AES-256-GCM (random 96-bit IVs, 128-bit authentication tags) and never reach the browser.
- An adaptive sync engine that reads Canvas rate-limit headers and moves between 60- and 180-second intervals, backing off on HTTP 429.
- Serverless-safe execution: a 40-second time-budget guard and auto-expiring locks keep runs inside platform limits.
- Event-driven Web Push (VAPID) for new, unlocked or rescheduled tasks and posted grades, with idempotent scheduling.
- Hardening: sliding-window rate limiting on auth routes, open-redirect protection and timing-safe secret checks on cron endpoints.
Engineering notes
- Tested where it matters. 51 unit and integration tests cover token encryption, auth security, throttling, semester parsing and task priority.
Status
Open source under the MIT licence; in development since September 2026.