A comprehensive productivity dashboard with task management, habit tracking, and health monitoring.
- Task Management
- Pomodoro Timer
- Habit Tracking
- Calendar
- Quick Notes
- Work Mode
- Position Tracking
- Mood Tracking
- And more!
- Next.js 14 (App Router)
- TypeScript
- Tailwind CSS
- NextAuth.js
- Drizzle ORM
- Neon PostgreSQL (Serverless)
- Upstash Redis (Serverless)
- Row-Level Security (RLS) for data isolation
- Rate limiting for API endpoints
- Input validation and sanitization
- Password strength validation
- Two-factor authentication
- API key management
- Comprehensive logging
- CSRF protection
- Security headers
- Node.js 18+
- Neon PostgreSQL account
- Upstash Redis account
- Clone the repository:
```bash git clone https://github.com/yourusername/productivity-dashboard.git cd productivity-dashboard ```
- Install dependencies:
```bash npm install ```
- Set up environment variables:
Create a .env file in the root directory with the following variables:
``` DATABASE_URL=your_neon_postgres_connection_string NEXTAUTH_SECRET=your_nextauth_secret NEXTAUTH_URL=http://localhost:3000 UPSTASH_REDIS_REST_URL=your_upstash_redis_url UPSTASH_REDIS_REST_TOKEN=your_upstash_redis_token ```
- Push the database schema:
```bash npx drizzle-kit push ```
- Set up Row-Level Security:
```bash npm run setup-rls ```
- Start the development server:
```bash npm run dev ```
Generate migrations:
```bash npx drizzle-kit generate ```
Apply migrations:
```bash npx drizzle-kit migrate ```
The application uses PostgreSQL's Row-Level Security (RLS) to ensure that users can only access their own data. This is enforced at the database level for maximum security.
To set up RLS:
```bash npm run setup-rls ```
The API supports two authentication methods:
- Session-based authentication (for web app)
- API key authentication (for external integrations)
You can manage API keys through the web interface or via the API:
GET /api/user/api-keys- List all API keysPOST /api/user/api-keys- Create a new API keyDELETE /api/user/api-keys/:id- Revoke an API key
API endpoints are rate-limited to prevent abuse. The limits vary by endpoint:
- Authentication endpoints: 10 requests per minute
- Regular API endpoints: 100 requests per minute
- Data Isolation: Each user's data is isolated using Row-Level Security at the database level.
- Password Security: Passwords are hashed using bcrypt and validated for strength.
- Two-Factor Authentication: Users can enable 2FA for additional security.
- API Security: Rate limiting, input validation, and proper error handling.
- Logging: Comprehensive logging for security events and errors.