← All Products/Live PrototypeActive Development

Structured campus attendance and
verified credentialing.

Field Book provides universities, student clubs, and event organizers with a lightweight, multi-role ledger to track event attendance via QR scanning and issue verifiable PDF certificates without heavyweight LMS bloat.

Functional Prototype Deployed

Field Book is currently accessible as a functional prototype with live authentication, role switching, and certificate generation.

Launch Live Prototype ↗ fieldbook.orgs.social
THREE-TIER ROLE ENGINERole-Based Access Control
StudentEvent Discovery & Check-in
• Scan event QR code• Instant duplicate check-in rejection• On-demand PDF certificate generation
OrganizerEvent Creation & Management
• Submit events for administrative approval• Display attendance QR check-in passes• Real-time attendee roster inspection
AdministratorGovernance & Security
• Approve/reject event submissions• Review role change requests• Append-only audit log oversight
System Capabilities

Core Platform Architecture

Designed to solve the administrative bottleneck of managing hundreds of event attendees while maintaining tamper-resistant credential integrity.

01

Event-Code QR Attendance

Organizers project an active attendance QR code containing the structured event identifier. Students scan via the built-in browser scanner.

Duplicate Prevention: Enforced at the database layer via a compound unique constraint on (student_id, event_id). Repeat scans are caught by Postgres (Error 23505) and rejected instantly.
02

Automated PDF Certificate Generation

Once attendance is confirmed in the database, eligible students can trigger automated certificate compilation.

Dedicated Microservice: Powered by a separate Java 17 / Spring Boot service utilizing Apache PDFBox 3 to dynamically composite student names, event metadata, and template background art into signed PDF documents.
03

Two-Tier Event Approval Pipeline

Club organizers can draft and submit event proposals, but events do not enter public discovery until reviewed and approved by institution administrators.

Permission Guards: Role changes are submitted through formal review requests, ensuring student users cannot self-escalate to organizer or administrator privileges.
DATABASE-ENFORCED PERMISSIONS

Technical Verification & Security Audit

Field Book delegates authorization entirely to the database tier rather than relying on frontend client-side validation alone.

67Active RLS PoliciesEnforced across profiles, events, approvals, certificates, and storage buckets
Append-OnlyAudit Trail DesignRLS permits INSERT and SELECT for administrators; zero UPDATE or DELETE policies exist for application roles
3-TierRole IsolationRole guards at route, RPC, and PostgreSQL table levels prevent privilege escalation

Technical Disclosure: Attendance QR codes encode structured event tokens (fieldbook:attendance:<CODE>) rather than asymmetric cryptographic signatures; uniqueness and integrity are enforced by PostgreSQL relational constraints and authenticated session IDs. Audit logs are append-only at the application/RLS layer, preventing accidental or malicious modification through the web application.

Field Book Production Stack

LayerTechnologyRole in Architecture
Frontend SPAReact 18 · Vite · TypeScript · Tailwind CSSClient interface, QR camera capture, role dashboards
Database & AuthSupabase (PostgreSQL 15)Row-Level Security, Auth PKCE, Storage Buckets, Triggers
Certificate ServiceJava 17 · Spring Boot 4 · Apache PDFBox 3Server-side vector rendering of verified PDF certificates
DeploymentVercel (Frontend) · Docker / Render (Backend)High-availability static frontend and microservice host