What we've shipped

Three sprints in. 280 tests green. The product is real.

Resilink is a NEET-PG mentoring platform built end-to-end over three sprints — foundation, content + counselling, and the mentor / operations layer. Every surface below is exercisable today on a local dev stack.

280tests green
3sprints shipped
26specialties in RRIS
8,000+counselling rows parsed
Sprint 1 · Foundation

Auth, RBAC, audit, security headers.

The bedrock. Cookie-based JWT (no token in the JS bundle), six-role permission tree mirrored as Django Groups, append-only audit log enforced by a Postgres trigger, HSTS + CSP + rate limits — and 134 tests on top.

HttpOnly cookie auth

Access + refresh JWTs travel only in HttpOnly + Secure + SameSite cookies. Reuse detection: a replayed refresh blacklists every device for that user.

Six-role RBAC

student_free → registered → premium, plus mentor, content_editor, super_admin. Single chokepoint (user.assign_role) keeps role field and Group membership in lockstep.

Append-only audit

Postgres BEFORE UPDATE OR DELETE trigger refuses edits. The Python override is fast-fail UX only — the database is the canonical guard.

TOTP admin gate

Django + Wagtail admin both require a verified TOTP device. Recovery codes via single-use StaticDevice tokens.

OpenAPI documented

Every cookie-flow auth view annotated with explicit @extend_schema. Swagger UI groups them under Authentication; cookie-set/read/clear contract spelled out.

Soft-delete + PII anon

User.delete() rewrites email to deleted-XXX@deleted.local, scrubs PII, disables login. Partial unique index keeps the original email re-registerable.

Sprint 2 · Content + counselling

The read surface online.

Wagtail as a headless CMS at /cms/, tier-gated content browse on the SPA, and the counselling-allotment pipeline — PDF → parser → DB → API — ingesting 8,000+ rows across Rajasthan 2023 and AIQ 2022 mop-up fixtures.

Tier-gated content

Single can_access(user, content) is the source of truth used by both list and detail. Free / registered / premium / paid tiers; editors bypass.

Browse content

Wagtail headless

Editors get the CMS at /cms/ with the same TOTP gate as Django admin. ContentPage stored as a Wagtail Snippet (UUID PK preserved).

Counselling pipeline

Admin uploads a state PDF → Celery parser runs → bulk-inserts allotments. file_hash UNIQUE blocks duplicates. Versioned parser registry, audited per-run.

dev.sh — one command

./dev.sh boots postgres + redis + backend + celery, waits for healthz, applies migrations, seeds content, then runs npm dev. Ctrl+C tears down.

Idempotent seed data

seed_review_content writes four sample ContentPages — one per tier — via update_or_create on slug. Run repeatedly without drift.

Counselling REST API

GET /api/counselling/uploads/ + per-upload aggregates. Status field surfaces parsing progress to the admin SPA — no WebSockets needed.

Sprint 3 · Mentor + admin + RRIS + 2FA

The operations layer.

Mentor side complete (Typeform-style onboarding wizard, directory), full admin SPA with users / counselling / surveys / audit / mentor approval, RRIS questionnaire end-to-end, two-factor authentication, and a refreshed design language sweeping every surface.

Mentor onboarding wizard

Schema-driven Typeform-style wizard. One Python file is the source of truth for both backend validation and the React form. No duplicated question list.

See approved mentors

RRIS survey end-to-end

NEET-PG Residency Intelligence Survey: Set A universal + Set B specialty-branched. Versioned schema (currently v3.0; v3.1 expansion in flight).

Admin SPA

Server-Component-first /admin/* with KPI dashboard, user mgmt, counselling deep-dive, RRIS aggregate, audit feed, ⌘K command palette. Server Actions for mutations.

Paid-tier 2FA

Requires2FA permission class is the third gate (alongside Django + Wagtail admins). Paid-role users without TOTP redirect to /account/security before any product page renders.

Auth split + subdomain

Separate /admin/login surface. Production middleware rewrites anything non-admin on admin.<domain> to /admin. Nginx config example for the public-host drop included.

Audit-log viewer

/admin/audit feed every admin action with diff + IP + UA. Read-only by construction — the Postgres append-only trigger means the page has no edit UI to build.

What's next

On the road to launch.

Honest about what isn't there yet. Items below are scoped, sequenced, and queued for the next sprint.

RRIS v3.1 expansion

Full 82-question Set A + 20 specialty Set B blocks. Existing v3.0 responses keep schema_version pinned for analytics integrity.

Mentor session booking

In-app LiveKit calls plus Razorpay order flow. Sessions are booked and held in Resilink.

Payout pipeline

Mentor payout schema (gross, commission snapshot, TDS, net) + admin endpoints + Razorpay Route integration. Architecture-in-advance before sessions go live.

AI counselling assistant

Conversation model + LLM call paths. Schema refactor first (ai_messages table split from JSONB) before the feature ships.

DPDP compliance pass

Drop session_attendance.ip_address; cascade User.delete() PII anonymisation to student_profiles + mentor_profiles. DPDP Act 2024.

AWS Terraform (D7)

Deferred since Week 1, pending IAM credentials. Two-step activation: uncomment deploy.yml trigger + add the 8 GitHub Secrets.

Progress — Resilink