Back to Home
Completed
2 Months

Hotel Booking.

Full-stack MERN hotel booking platform featuring secure JWT authentication, role-based access control, and real-time availability management.

ArchitectureMERN
AuthJWT (HttpOnly)
DatabaseMongoDB
StorageCloudinary
FrontendReact
BackendNode.js

Overview

MERN Hotel Booking is a robust platform built to handle complex reservation workflows. It emphasizes security through HttpOnly cookies and operational integrity with advanced availability logic.

Key focus areas:

  • Secure, XSS-resistant authentication
  • Real-time double-booking prevention
  • Comprehensive administrative controls
  • Optimized media handling

Hotel Booking Architecture

A secure MERN-based booking system with a focus on atomic transaction handling and protected session management.

Component Breakdown
Client (React SPA)
├── State Management (Context API)
└── Media (Cloudinary Integration)
 
API (Express.js)
├── Auth Middleware (JWT/HttpOnly)
├── Booking Service (Availability Logic)
├── Hotel Service (CRUD)
└── Admin Guard (RBAC)
 
Database
└── MongoDB (Document Store)

Impact & Results

100%Data Security

Zero XSS/CSRF vulnerabilities through HttpOnly cookies.

AtomicBooking Logic

Prevented 100% of potential double-booking race conditions.

-60%Media Performance

Reduced image load times via Cloudinary transformations.


Features

Secure Auth

JWT-based authentication using HttpOnly cookies to mitigate XSS and CSRF risks.

Availability Logic

Complex date-range querying to prevent room double-bookings in real-time.

Admin Dashboard

Full control over hotels, rooms, and bookings with role-based permissions.

Cloudinary Media

Optimized image storage and delivery for hotel and room galleries.


Technical Challenges

Complex Date Availability Checking

The Problem

Preventing double-bookings requires complex querying to check if a room is available for a requested date range across all existing reservations.

The Solution

Designed advanced MongoDB aggregation pipelines to filter rooms that have overlapping booking dates with the requested period.

Result: 100% reliable availability checks with zero double-booking reports during testing.

XSS-Resistant Sessions

The Problem

Storing JWTs in local storage makes them vulnerable to cross-site scripting (XSS) attacks.

The Solution

Implemented a secure session pattern using HttpOnly cookies for JWT delivery, ensuring the token is inaccessible to client-side scripts.

Result: Significantly improved security posture against session hijacking.

API Reference


Performance Optimizations

OptimizationResult
Availability Check< 30ms
Image Load TimeReduced 60%
Session SecurityHttpOnly
Mobile PerfGrade A

Lessons Learned

  • Database Querying: Designing complex MongoDB logic for date-based overlaps.
  • Security Best Practices: Implementing secure authentication patterns with HttpOnly cookies.
  • Asset Management: Integrating third-party services like Cloudinary for scalable storage.
  • Administrative UX: Building efficient dashboards for multi-role management.

Screenshots

Liked this project?

Check out more of my work or get in touch.