HACKTOBER 2026 — National Event Management Platform
The official platform for HACKTOBER 2026, a national-level event under Cybersecurity Awareness Month at GNDEC Bidar — built full-stack, with the admin side hardened like a product, not a demo.
Official portal for GNDEC Bidar's national-level cybersecurity event
Stack
- Next.js 16
- React 19
- TypeScript
- Tailwind CSS v4
- MongoDB Atlas
- JWT (HS256)
- bcrypt
- HMAC-SHA256
- Zod
- Vercel
HACKTOBER 2026 Platform — screenshot pending
Problem
A national-level, multi-day event needs more than a landing page: public registration across five competitions, dynamic multi-event pricing, payment verification, attendance tracking, and an administrative back office — all handling real participant data that must stay private and tamper-resistant.
Registration & QR passes
The public portal runs a multi-step registration wizard with a dynamic pricing engine (₹79 for one event up to ₹350 for five) and semester constraints. Each confirmed registration gets a non-sequential ID (`HT26-` + 6 random characters) and a printable accreditation pass.
Rather than encoding participant PII in the QR code, the pass carries an HMAC-SHA256 signed token (`HT26-XXXXXX-<hmac>`). A public verification route confirms authenticity, college, events, and payment status without leaking phone or email.
Hardened admin operations
The admin side is treated as an attack surface. It uses a role-based hierarchy (SUPER_ADMIN > ADMIN > VIEWER), a sliding-window brute-force lockout (5 failed attempts → 15-minute block, HTTP 429), constant-time comparison to mitigate timing attacks on login, HttpOnly session cookies, and strict security headers (`X-Frame-Options: DENY`, `nosniff`, `no-store`).
Organizers get a live analytics dashboard, a payment-verification queue with side-by-side receipt review, a camera-based QR attendance scanner with duplicate check-in detection, filter-aware CSV/Excel exports, and an immutable audit log.
Verification
The platform ships with a unit and business-rules suite (50/50 passing) covering pricing, event limits, semester constraints, rate limiting, HMAC tokens, RBAC, and the payment lifecycle, plus a live HTTP end-to-end suite (8/8 passing) exercising registration, QR verification, payment approval, attendance check-in, and exports.
Limitations
- Built for a specific event; some rules (pricing tiers, semester options) are domain-specific rather than general-purpose.
Future work
- Generalize the registration engine for reuse across future department events.