← Back to Portfolio

ULAB Lost & Found API

A role-based REST API for managing lost and found items within the ULAB community, with JWT authentication, role-based authorization and a verification-based claim process.

TypeREST API (backend)
StatusCompleted
StackNode.js, Express, MongoDB
AuthJWT, HTTP-only Cookie, RBAC

Overview

ULAB Lost & Found is a backend REST API designed to provide a structured way for the ULAB community to report lost items, record found items and manage ownership claims. Students can register and report lost items, while staff can record found items and review claims. The system uses role-based authorization and verification questions to make the claim process more reliable and reduce false ownership claims.

Key features

  • JWT authentication: secure registration and login using JWT stored in an HTTP-only cookie.
  • Role-based authorization: separate permissions for students, staff and administrators.
  • User management: students can self-register, while administrators can add staff or administrator accounts.
  • Lost & found management: manage records for lost and found items using dedicated MongoDB models.
  • Claim management: students can submit claims for found items and staff can review them.
  • Claim verification: verification questions and answers are used to evaluate whether a claimant can prove ownership.
  • Admin control: administrators have additional authority over user and lost & found information.
  • Validation & error handling: request validation and custom error handling are used to keep API responses consistent.

How a claim works

  • A staff member records a found item with verification questions.
  • A student submits a claim for the found item and provides verification answers.
  • The submitted answers are evaluated against the expected answers and a verification score is generated.
  • Staff review the claim and can accept or reject it based on the verification result.
  • Once a claim is accepted, the item can be treated as successfully returned to its rightful owner.

Example endpoints

The API is organized around authentication, users, lost items, found items and claims. Here are some of the available endpoints. For the complete API, please check the API documentation.

MethodEndpointPurpose
POST/registerRegister a new student account
POST/loginAuthenticate a user and set the JWT cookie
POST/logoutLog out the authenticated user
POST/admin/addUserAllow an administrator to create staff or admin accounts
POST/lostCreate a lost-item report
POST/foundCreate a found-item record
POST/claimSubmit a claim for a found item
PATCH/claim/:idReview and update a claim

What I learned

Building this project helped me understand how to design and structure a real-world Node.js REST API using MVC architecture. I worked with Express middleware, JWT authentication with HTTP-only cookies, role-based authorization, MongoDB and Mongoose relationships, request validation, custom error handling and claim verification logic. I also learned how to organize an API for testing and document its endpoints clearly using Postman.