Skip to main content
One idea at a time

What this app proves

Taskboard is a working learning application with production concepts. Its local checks provide evidence for specific behavior. They do not certify an arbitrary deployment.

The implemented guaranteesโ€‹

Tenant checks scope queries and mutations. Composite foreign keys reject cross-tenant references. Membership roles are checked at the time of an operation.

A keyed task creation stores its result in the same transaction as the task, activity event, and job. Authorization runs before replay. Concurrent edits compare the stored version.

Jobs use renewable leases and fenced completion. The worker can recover an expired claim. Email delivery remains at least once because ordinary SMTP cannot make its external acceptance atomic with Postgres.

Billing stores checkout reservations before external calls. Valid signed webhooks enter a durable inbox. Duplicate event IDs do not create another reconciliation job. Reconciliation fetches current Stripe state, serializes per workspace, and checks the billing revision before committing.

What the checks runโ€‹

The integration suite runs real PostgreSQL, HTTP, SMTP, and Socket.IO. It checks foreign tenants, roles, CSRF, retries, concurrent mutations, invitation quotas, password reset, pagination, webhook signatures, and job recovery.

The Docker verification runs the compiled API and worker in separate containers. It restarts the API and confirms that a session, task, and idempotent response survive. It observes a worker notification through Postgres and actual email delivery to Mailpit.

Browser checks use the built static course and the running reference client. They cover reading progress, focus mode, search, source navigation, mobile layout, login, task creation, edits, comments, and reload persistence.

What still needs external evidenceโ€‹

The Stripe adapter uses the real SDK. Local tests simulate provider network responses. Real test-mode Checkout, portal configuration, account-specific subscription states, and webhook forwarding require your Stripe account credentials.

This app has no measured capacity claim. Benchmarking representative traffic, tuning password-hash cost, configuring TLS and proxy trust, and validating provider limits are deployment work.

Backups require a real restore drill. Metrics require a collector and alerts. Postgres row-level security, distributed tracing, retention cleanup, and broader account administration are extensions discussed where relevant.

Take away

Trust the guarantees that a check demonstrates. Ask for deployment evidence before calling a system production-ready.