|
| 1 | +<p align="center"> |
| 2 | + <img src="https://img.shields.io/badge/Spring%20Boot-3.5-6DB33F?logo=springboot&logoColor=white" alt="Spring Boot" /> |
| 3 | + <img src="https://img.shields.io/badge/Java-21-ED8B00?logo=openjdk&logoColor=white" alt="Java" /> |
| 4 | + <img src="https://img.shields.io/badge/Expo-SDK%2054-000020?logo=expo&logoColor=white" alt="Expo" /> |
| 5 | + <img src="https://img.shields.io/badge/React%20Native-0.81-61DAFB?logo=react&logoColor=white" alt="React Native" /> |
| 6 | + <img src="https://img.shields.io/badge/Firebase-Hosting-FFCA28?logo=firebase&logoColor=black" alt="Firebase" /> |
| 7 | + <img src="https://img.shields.io/badge/Google%20Cloud-Run-4285F4?logo=googlecloud&logoColor=white" alt="Cloud Run" /> |
| 8 | +</p> |
| 9 | + |
| 10 | +# onTrack |
| 11 | + |
| 12 | +**onTrack** is an academic progress tracker built for McMaster University students. Upload your transcript, track your GPA, manage course assessments, and sync deadlines to Google Calendar — all in one place. |
| 13 | + |
| 14 | +> **Live at [ontrackmac.ca](https://ontrackmac.ca)** |
| 15 | +
|
| 16 | +--- |
| 17 | + |
| 18 | +## Features |
| 19 | + |
| 20 | +### Transcript Upload |
| 21 | +Upload your McMaster transcript as a PDF and onTrack automatically parses it to import your past courses, grades, and current term enrollments. Supports multi-year courses (e.g., `ENGINEER 1P13 A/B`) and handles duplicate detection. |
| 22 | + |
| 23 | +### GPA Tracking |
| 24 | +View your cumulative GPA on both the **4.0** and **12.0** scales. Set a target GPA and visualize your progress. GPA is recalculated automatically whenever courses or grades change. |
| 25 | + |
| 26 | +### AI-Powered Syllabus Extraction |
| 27 | +Upload a course syllabus PDF and onTrack uses **Google Gemini 2.5 Pro** to extract the full assessment breakdown — names, weights, due dates, and grading schemes. Supports courses with multiple grading schemes and selection rules (e.g., "best of" schemes). Extraction runs asynchronously with real-time job status polling. |
| 28 | + |
| 29 | +### Assessment Table |
| 30 | +View and edit assessment details for each course: weights, due dates, times, locations, and grades. Tables are automatically populated from uploaded syllabi or can be built manually. |
| 31 | + |
| 32 | +### Course Grade Calculator |
| 33 | +Enter grades for individual assessments and see your projected final course grade, calculated from syllabus weight breakdowns across all applicable grading schemes. |
| 34 | + |
| 35 | +### Google Calendar Sync |
| 36 | +Connect your Google account and export upcoming assessment deadlines to Google Calendar. Uses a **diff-based sync algorithm** — re-syncing only adds new events and removes outdated ones, never creating duplicates. |
| 37 | + |
| 38 | +### Dashboard |
| 39 | +An at-a-glance overview of your current GPA vs. target, upcoming deadlines, and active courses. Quick actions to add assignments, sync your calendar, or report a bug. |
| 40 | + |
| 41 | +### Course Search |
| 42 | +Browse McMaster's course catalogue to look up course details and descriptions. |
| 43 | + |
| 44 | +### My Courses |
| 45 | +Manage your current term courses, upload syllabi, and access per-course assessment tables. |
| 46 | + |
| 47 | +--- |
| 48 | + |
| 49 | +## Security |
| 50 | + |
| 51 | +Protecting student data is a priority. Here's how onTrack handles security: |
| 52 | + |
| 53 | +| Measure | Details | |
| 54 | +|---------|---------| |
| 55 | +| **Authentication** | Stateless JWT (HMAC-SHA, 1-hour expiry). No server-side sessions. | |
| 56 | +| **Password Storage** | BCrypt with strength factor 12. Passwords are never stored in plaintext. | |
| 57 | +| **Password Requirements** | Minimum 8 characters with at least one uppercase letter, one lowercase letter, and one digit. | |
| 58 | +| **Grade Encryption** | All grade data is encrypted at rest using **AES-256-GCM** with per-record initialization vectors. | |
| 59 | +| **Email Verification** | Token-based verification required before account activation. Tokens are cryptographically random (32 bytes) with a 15-minute expiry and single-use enforcement. | |
| 60 | +| **Rate Limiting** | Sliding-window rate limiter on all endpoints — 10 req/min on authentication routes, 60 req/min on general routes. | |
| 61 | +| **OAuth 2.0** | Google Calendar integration uses JWT-signed state tokens (5-minute expiry) to prevent CSRF during the OAuth flow. | |
| 62 | +| **Input Validation** | Server-side validation on all user inputs with a global exception handler that returns structured error responses. | |
| 63 | +| **Error Handling** | Stack traces, exception types, and internal error messages are never exposed to clients. | |
| 64 | +| **McMaster-Only Registration** | Only `@mcmaster.ca` email addresses can register. | |
| 65 | +| **CORS** | Restricted to configured frontend origin with credentials support. | |
| 66 | +| **Infrastructure** | Hosted on Google Cloud (northamerica-northeast2) with Cloud SQL (PostgreSQL) and MongoDB Atlas. Backend deployed via Cloud Run with containerized builds. | |
| 67 | + |
| 68 | +--- |
| 69 | + |
| 70 | +## Tech Stack |
| 71 | + |
| 72 | +| Layer | Technology | |
| 73 | +|-------|-----------| |
| 74 | +| **Frontend** | React Native, Expo SDK 54, expo-router, react-native-reanimated | |
| 75 | +| **Web Hosting** | Firebase Hosting | |
| 76 | +| **Backend** | Spring Boot 3.5, Java 21 | |
| 77 | +| **Databases** | PostgreSQL (Google Cloud SQL), MongoDB Atlas | |
| 78 | +| **AI** | Google Gemini 2.5 Pro | |
| 79 | +| **Auth** | JWT + BCrypt + email verification | |
| 80 | +| **Email** | Resend | |
| 81 | +| **CI/CD** | GitHub Actions | |
| 82 | +| **Infrastructure** | Google Cloud Run, Firebase Hosting | |
| 83 | + |
| 84 | +--- |
| 85 | + |
| 86 | +## Project Structure |
| 87 | + |
| 88 | +``` |
| 89 | +onTrack/ |
| 90 | +├── backend/ # Spring Boot REST API |
| 91 | +│ └── src/main/java/.../ |
| 92 | +│ ├── accounts/ # Student profiles, transcript upload, course management |
| 93 | +│ ├── assessmenttable/ # Assessment table CRUD and syllabus integration |
| 94 | +│ ├── calendar/ # Google Calendar OAuth and diff-based sync |
| 95 | +│ ├── courses/ # Course catalogue search |
| 96 | +│ ├── mailing/ # Email verification and password reset emails |
| 97 | +│ ├── security/ # JWT auth, rate limiting, encryption, user management |
| 98 | +│ └── syllabus/ # Syllabus upload, Gemini AI extraction, grading schemes |
| 99 | +├── frontend/ # Expo React Native app |
| 100 | +│ ├── app/ # expo-router routes |
| 101 | +│ ├── screens/ # Screen components |
| 102 | +│ ├── src/ # Theme, config, utilities |
| 103 | +│ └── public/ # Landing page, privacy policy |
| 104 | +└── .github/workflows/ # CI/CD pipelines |
| 105 | +``` |
| 106 | + |
| 107 | +--- |
| 108 | + |
| 109 | +## Deployment |
| 110 | + |
| 111 | +| Component | Pipeline | Target | |
| 112 | +|-----------|----------|--------| |
| 113 | +| **Backend** | Push to `main` (backend changes) | Docker build → Google Cloud Run | |
| 114 | +| **Frontend** | Push to `main` (frontend changes) | Expo web export → Firebase Hosting | |
| 115 | + |
| 116 | +Both pipelines run automatically via GitHub Actions. All secrets are stored in GitHub Secrets — no credentials are committed to the repository. |
| 117 | + |
| 118 | +--- |
| 119 | + |
| 120 | +## Acknowledgements |
| 121 | + |
| 122 | +- [macgrades/transcript-api](https://github.com/macgrades/transcript-api) — McMaster transcript parsing API that inspired the transcript upload feature. |
0 commit comments