Skip to content

About

A full-stack RESTful API for course and user management with JWT authentication

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

πŸŽ“ Course Management API

A full-stack RESTful API for course and user management with JWT authentication, built with Node.js, Express.js, and MongoDB.

Node.js Express.js MongoDB JWT

✨ Features

πŸ” Authentication System

  • βœ… User Registration with email validation
  • βœ… Secure Login with JWT tokens
  • βœ… Password hashing with bcrypt
  • βœ… Protected routes with middleware
  • βœ… User profile management

πŸ“š Course Management

  • βœ… Full CRUD operations for courses
  • βœ… Course listing with pagination
  • βœ… Course enrollment system
  • βœ… Public and protected endpoints

πŸ›‘οΈ Security & Best Practices

  • βœ… JWT token authentication
  • βœ… Password encryption (bcrypt)
  • βœ… Input validation with express-validator
  • βœ… CORS configuration
  • βœ… Error handling with express-async-handler
  • βœ… JSend response format

πŸš€ Quick Start

Prerequisites

  • Node.js (v14 or higher)
  • MongoDB Atlas account or local MongoDB
  • Git

Installation

  1. Clone the repository

    git clone https://github.com/MONOCODE-V/course-management-api.git
    cd course-management-api
  2. Install dependencies

    npm install
  3. Environment Setup

    # Copy environment template
    cp .env.example .env
    
    # Edit .env file with your configuration
    # MONGODB_URI=your_mongodb_connection_string
    # JWT_SECRET=your_super_secret_key
    # PORT=3000
  4. Start the server

    # Development with auto-restart
    npm run dev
    
    # Production
    npm start

πŸ“š API Documentation

Base URL

http://localhost:3000/api

πŸ”“ Public Endpoints

User Registration

POST /auth/register
Content-Type: application/json

{
  "name": "John Doe",
  "email": "john@example.com",
  "password": "MyPassword123!",
  "age": 25
}

User Login

POST /auth/login
Content-Type: application/json

{
  "email": "john@example.com",
  "password": "MyPassword123!"
}

Get All Courses

GET /courses

πŸ”’ Protected Endpoints

Requires Authorization header: Bearer <jwt_token>

Get User Profile

GET /profile/me
Authorization: Bearer <jwt_token>

Update User Profile

PATCH /profile/me
Authorization: Bearer <jwt_token>
Content-Type: application/json

{
  "name": "Updated Name",
  "email": "new@example.com"
}

Course Management

# Create Course
POST /courses
Authorization: Bearer <jwt_token>

# Update Course
PATCH /courses/:courseId
Authorization: Bearer <jwt_token>

# Delete Course
DELETE /courses/:courseId
Authorization: Bearer <jwt_token>

πŸ—οΈ Project Structure

course-management-api/
β”œβ”€β”€ πŸ“ controllers/           # Route handlers
β”‚   β”œβ”€β”€ auth.controllers.js   # Authentication logic
β”‚   β”œβ”€β”€ course.controllers.js # Course CRUD operations
β”‚   └── user.profile.controllers.js # Profile management
β”œβ”€β”€ πŸ“ data/                  # Database schemas
β”‚   β”œβ”€β”€ coursesSchema.js      # Course model
β”‚   └── userSchema.js         # User model
β”œβ”€β”€ πŸ“ middleware/            # Custom middleware
β”‚   └── auth.js              # JWT authentication
β”œβ”€β”€ πŸ“ routes/                # API routes
β”‚   β”œβ”€β”€ authRoutes.js        # Auth endpoints
β”‚   β”œβ”€β”€ courses.route.js     # Course endpoints
β”‚   └── profileRoutes.js     # Profile endpoints
β”œβ”€β”€ πŸ“„ index.js               # Server entry point
β”œβ”€β”€ πŸ“„ package.json           # Dependencies
β”œβ”€β”€ πŸ“„ .env.example           # Environment template
└── πŸ“„ README.md             # This file

πŸ—„οΈ Database Schema

User Model

{
  name: String,           // Required, 2-50 characters
  email: String,          // Required, unique, validated
  password: String,       // Required, hashed with bcrypt
  age: Number,           // Required, 13-120
  role: String,          // Enum: ['user', 'admin', 'moderator']
  enrolledCourses: [ObjectId], // References to Course
  createdAt: Date        // Auto-generated
}

Course Model

{
  title: String,         // Required
  price: Number,         // Required, positive
  description: String,   // Optional
  instructor: String,    // Required
  duration: Number,      // In hours
  level: String,         // Enum: ['beginner', 'intermediate', 'advanced']
  createdAt: Date       // Auto-generated
}

πŸ§ͺ Testing with Thunder Client / Postman

1. Register a New User

POST http://localhost:3000/api/auth/register
Content-Type: application/json

{
  "name": "Test User",
  "email": "test@example.com", 
  "password": "TestPassword123!",
  "age": 25
}

2. Login and Get Token

POST http://localhost:3000/api/auth/login
Content-Type: application/json

{
  "email": "test@example.com",
  "password": "TestPassword123!"
}

3. Access Protected Route

GET http://localhost:3000/api/profile/me
Authorization: Bearer <your_jwt_token_from_login>

πŸ”§ Available Scripts

# Start development server with auto-reload
npm run dev

# Start production server
npm start

# Install dependencies
npm install

🌍 Environment Variables

Create a .env file in the root directory:

# Database
MONGODB_URI=mongodb+srv://username:password@cluster.mongodb.net/dbname

# JWT Configuration
JWT_SECRET=your-super-secret-jwt-key-make-it-very-long-and-random
JWT_EXPIRES_IN=7d

# Server Configuration
PORT=3000
NODE_ENV=development

# Password Hashing
BCRYPT_ROUNDS=12

πŸ“¦ Dependencies

Production

  • express - Web framework for Node.js
  • mongoose - MongoDB object modeling
  • jsonwebtoken - JWT token generation and verification
  • bcryptjs - Password hashing
  • express-validator - Input validation middleware
  • express-async-handler - Async error handling
  • cors - Cross-Origin Resource Sharing
  • dotenv - Environment variable management

Development

  • nodemon - Development server with auto-reload

πŸ” Security Features

  • Password Hashing: Uses bcrypt with configurable rounds
  • JWT Authentication: Stateless token-based auth
  • Input Validation: Server-side validation for all inputs
  • CORS Protection: Configurable cross-origin requests
  • Error Handling: Centralized error management
  • Environment Variables: Sensitive data protection

🀝 Contributing

  1. Fork the repository
  2. Create your feature branch (git checkout -b feature/AmazingFeature)
  3. Commit your changes (git commit -m 'Add some AmazingFeature')
  4. Push to the branch (git push origin feature/AmazingFeature)
  5. Open a Pull Request

πŸ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ‘¨β€πŸ’» Author

MONOCODE-V

πŸ™ Acknowledgments

  • Express.js team for the amazing framework
  • MongoDB team for the database solution
  • JWT.io for token authentication standards
  • The Node.js community for continuous support

⭐ Star this repository if it helped you!

About

A full-stack RESTful API for course and user management with JWT authentication

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages