Case study / 02
Daily collaboration with security built into every boundary.
A secure task platform with clear responsibilities for administrators, managers, and collaborators.
- Role
- Full-stack Architect & Engineer
- Scope
- Product flows · Application security · File access · Deployment
- Status
- Delivered project
- Year
- 2026

01 / CONTEXT
The problem
Support fast collaboration while protecting sessions, attachments, and business data across distinct roles.
02 / RESPONSE
The response
Angular connects to a Spring Boot API secured with role boundaries, HttpOnly sessions, CSRF protection, MFA, revocation, and private storage.
03 / EXPERIENCE
Product flow
- 01
Invite
Create accounts without exposing task content.
- 02
Assign
Managers define ownership and deadlines.
- 03
Collaborate
Work with comments and secure files.
- 04
Track
Follow progress and overdue work.
05 / SYSTEM
System architecture
The API is the policy boundary between the Angular experience and every data or file service.
06 / TRADE-OFFS
Architecture decisions
Role separation
Account administration does not grant business-data access.
Cookie sessions
HttpOnly JWTs are paired with CSRF controls.
Private attachments
Files are served only after application authorization.
07 / QUALITY
Security & reliability
- TOTP MFA and revocation protect account access.
- Flyway provides repeatable database evolution.
- Security events are recorded for investigation.
08 / EVIDENCE
Outcomes & evidence
- One workspace for assignment, execution, and follow-up.
- Explicit boundaries between administration and business work.
- A deployment split suited to managed platforms.
09 / STACK