A production-minded booking web application for D Festival × 幻樂空間, built with Next.js App Router, PostgreSQL, Prisma, Argon2 password hashing, and JWT sessions stored in httpOnly cookies.
This project demonstrates:
- a public event and booking flow;
- authenticated user sessions and password-change enforcement;
- availability checks with Hong Kong business rules;
- booking history and bonus-reward handling;
- a separate admin surface for booking review and calendar operations.
-
Start the database from the parent directory:
docker compose up -d
-
Copy environment variables and install dependencies:
cp .env.example .env npm install
-
Apply migrations and seed a local development database:
npx prisma migrate deploy npm run db:seed
-
Start the development server:
npm run dev
Open http://localhost:3000.
| Command | Purpose |
|---|---|
npm run db:studio |
Open Prisma Studio |
npm run build |
Create a production build |
npm run db:seed |
Seed local development data |
GET /api/v1/public/settings— public event settingsPOST /api/v1/registration— user registrationPOST /api/v1/auth/login,logout,change-passwordGET /api/v1/me— current user and booking-gate stateGET /api/v1/booking/availability?from=yyyy-MM-dd&to=yyyy-MM-ddPOST /api/v1/booking/requestGET /api/v1/booking/history
The server enforces the event window, advance-booking limits, personal and teaching quotas, rolling three-day limits, capacity, overlap checks, password-change requirements, and the booking-open timestamp.
POST /api/v1/admin/auth/login— admin login/admin/bookings— approve, waitlist, or reject bookings/admin/calendar?from=&to=— calendar preview
All business dates are displayed in Asia/Hong_Kong; timestamps are stored in UTC.
- Keep all local secrets in
.env; never commit real credentials. - The seed command is for local development only. Configure a unique local admin password through
SEED_ADMIN_PASSWORD. - Before deploying, verify that seed accounts, staging credentials, and admin routes are disabled or protected in the target environment.
The repository is a portfolio and development reference. The admin UI is not fully wired for every operation yet; use the documented API and Prisma Studio paths for local inspection.