← work

side project · live

Job Tracker

The tracker I use for my own job search. Visitors get a read-only demo; my real data stays private, isolated by the database.

→ jobs.ljupchop.dev

  • NestJS
  • Prisma
  • PostgreSQL
  • React
  • AWS CDK
  • Cognito

My idea and my choice of stack, built to go deeper on the backend. I use it daily during my own job search, and anyone can click through the same app running on fictional data.

  • Two workspaces, one app. My data and the demo live in separate Postgres schemas. Visitors connect as a read-only database role that can’t even see my tables, so isolation doesn’t depend on a WHERE clause I might forget.
  • Sign-in without tokens in the browser. Amazon Cognito with MFA. The NestJS API runs the OAuth code flow with PKCE and keeps the tokens in httpOnly cookies, so page scripts never see them.
  • A history, not a status field. An application changes stage only by adding an immutable record. The timeline, “days in stage” and every number on the dashboard (funnel, response rate, time to answer) come from that history, and those calculations have unit tests.
  • Day-to-day features. Drag-and-drop board, sortable table with search and filters, follow-up reminders and upcoming interviews.
  • On AWS with CDK. CloudFront with a strict CSP in front of S3 and a private load balancer, then Fargate and RDS. No NAT gateway. CDK tests guard the security decisions.

The “How it’s built” page in the app explains the architecture.