Three sprints in. 280 tests green. The product is real.
Resilink is a NEET-PG mentoring platform built end-to-end over three sprints — foundation, content + counselling, and the mentor / operations layer. Every surface below is exercisable today on a local dev stack.
Auth, RBAC, audit, security headers.
The bedrock. Cookie-based JWT (no token in the JS bundle), six-role permission tree mirrored as Django Groups, append-only audit log enforced by a Postgres trigger, HSTS + CSP + rate limits — and 134 tests on top.
HttpOnly cookie auth
Access + refresh JWTs travel only in HttpOnly + Secure + SameSite cookies. Reuse detection: a replayed refresh blacklists every device for that user.
Six-role RBAC
student_free → registered → premium, plus mentor, content_editor, super_admin. Single chokepoint (user.assign_role) keeps role field and Group membership in lockstep.
Append-only audit
Postgres BEFORE UPDATE OR DELETE trigger refuses edits. The Python override is fast-fail UX only — the database is the canonical guard.
TOTP admin gate
Django + Wagtail admin both require a verified TOTP device. Recovery codes via single-use StaticDevice tokens.
OpenAPI documented
Every cookie-flow auth view annotated with explicit @extend_schema. Swagger UI groups them under Authentication; cookie-set/read/clear contract spelled out.
Soft-delete + PII anon
User.delete() rewrites email to deleted-XXX@deleted.local, scrubs PII, disables login. Partial unique index keeps the original email re-registerable.
The read surface online.
Wagtail as a headless CMS at /cms/, tier-gated content browse on the SPA, and the counselling-allotment pipeline — PDF → parser → DB → API — ingesting 8,000+ rows across Rajasthan 2023 and AIQ 2022 mop-up fixtures.
Tier-gated content
Single can_access(user, content) is the source of truth used by both list and detail. Free / registered / premium / paid tiers; editors bypass.
Browse contentWagtail headless
Editors get the CMS at /cms/ with the same TOTP gate as Django admin. ContentPage stored as a Wagtail Snippet (UUID PK preserved).
Counselling pipeline
Admin uploads a state PDF → Celery parser runs → bulk-inserts allotments. file_hash UNIQUE blocks duplicates. Versioned parser registry, audited per-run.
dev.sh — one command
./dev.sh boots postgres + redis + backend + celery, waits for healthz, applies migrations, seeds content, then runs npm dev. Ctrl+C tears down.
Idempotent seed data
seed_review_content writes four sample ContentPages — one per tier — via update_or_create on slug. Run repeatedly without drift.
Counselling REST API
GET /api/counselling/uploads/ + per-upload aggregates. Status field surfaces parsing progress to the admin SPA — no WebSockets needed.
The operations layer.
Mentor side complete (Typeform-style onboarding wizard, directory), full admin SPA with users / counselling / surveys / audit / mentor approval, RRIS questionnaire end-to-end, two-factor authentication, and a refreshed design language sweeping every surface.
Mentor onboarding wizard
Schema-driven Typeform-style wizard. One Python file is the source of truth for both backend validation and the React form. No duplicated question list.
See approved mentorsRRIS survey end-to-end
NEET-PG Residency Intelligence Survey: Set A universal + Set B specialty-branched. Versioned schema (currently v3.0; v3.1 expansion in flight).
Admin SPA
Server-Component-first /admin/* with KPI dashboard, user mgmt, counselling deep-dive, RRIS aggregate, audit feed, ⌘K command palette. Server Actions for mutations.
Paid-tier 2FA
Requires2FA permission class is the third gate (alongside Django + Wagtail admins). Paid-role users without TOTP redirect to /account/security before any product page renders.
Auth split + subdomain
Separate /admin/login surface. Production middleware rewrites anything non-admin on admin.<domain> to /admin. Nginx config example for the public-host drop included.
Audit-log viewer
/admin/audit feed every admin action with diff + IP + UA. Read-only by construction — the Postgres append-only trigger means the page has no edit UI to build.
On the road to launch.
Honest about what isn't there yet. Items below are scoped, sequenced, and queued for the next sprint.
RRIS v3.1 expansion
Full 82-question Set A + 20 specialty Set B blocks. Existing v3.0 responses keep schema_version pinned for analytics integrity.
Mentor session booking
In-app LiveKit calls plus Razorpay order flow. Sessions are booked and held in Resilink.
Payout pipeline
Mentor payout schema (gross, commission snapshot, TDS, net) + admin endpoints + Razorpay Route integration. Architecture-in-advance before sessions go live.
AI counselling assistant
Conversation model + LLM call paths. Schema refactor first (ai_messages table split from JSONB) before the feature ships.
DPDP compliance pass
Drop session_attendance.ip_address; cascade User.delete() PII anonymisation to student_profiles + mentor_profiles. DPDP Act 2024.
AWS Terraform (D7)
Deferred since Week 1, pending IAM credentials. Two-step activation: uncomment deploy.yml trigger + add the 8 GitHub Secrets.