Skip to content
Bennyhinn.
← All work
Full-Stack2026

HACKTOBER 2026 — National Event Management Platform

The official platform for HACKTOBER 2026, a national-level event under Cybersecurity Awareness Month at GNDEC Bidar — built full-stack, with the admin side hardened like a product, not a demo.

Official portal for GNDEC Bidar's national-level cybersecurity event

Stack

  • Next.js 16
  • React 19
  • TypeScript
  • Tailwind CSS v4
  • MongoDB Atlas
  • JWT (HS256)
  • bcrypt
  • HMAC-SHA256
  • Zod
  • Vercel

Problem

A national-level, multi-day event needs more than a landing page: public registration across five competitions, dynamic multi-event pricing, payment verification, attendance tracking, and an administrative back office — all handling real participant data that must stay private and tamper-resistant.

Registration & QR passes

The public portal runs a multi-step registration wizard with a dynamic pricing engine (₹79 for one event up to ₹350 for five) and semester constraints. Each confirmed registration gets a non-sequential ID (`HT26-` + 6 random characters) and a printable accreditation pass.

Rather than encoding participant PII in the QR code, the pass carries an HMAC-SHA256 signed token (`HT26-XXXXXX-<hmac>`). A public verification route confirms authenticity, college, events, and payment status without leaking phone or email.

Hardened admin operations

The admin side is treated as an attack surface. It uses a role-based hierarchy (SUPER_ADMIN > ADMIN > VIEWER), a sliding-window brute-force lockout (5 failed attempts → 15-minute block, HTTP 429), constant-time comparison to mitigate timing attacks on login, HttpOnly session cookies, and strict security headers (`X-Frame-Options: DENY`, `nosniff`, `no-store`).

Organizers get a live analytics dashboard, a payment-verification queue with side-by-side receipt review, a camera-based QR attendance scanner with duplicate check-in detection, filter-aware CSV/Excel exports, and an immutable audit log.

Verification

The platform ships with a unit and business-rules suite (50/50 passing) covering pricing, event limits, semester constraints, rate limiting, HMAC tokens, RBAC, and the payment lifecycle, plus a live HTTP end-to-end suite (8/8 passing) exercising registration, QR verification, payment approval, attendance check-in, and exports.

Limitations

  • Built for a specific event; some rules (pricing tiers, semester options) are domain-specific rather than general-purpose.

Future work

  • Generalize the registration engine for reuse across future department events.