OH Barber is a private client product for a barber shop in Dijon, France. I designed and delivered a mobile-first customer booking journey and an operations dashboard backed by a transactional scheduling model.
This repository is a sanitized portfolio showcase. It contains no client source code, credentials, database export, customer record, or administrator screenshot.
Appointments arriving through calls and social messages create repeated coordination and make live capacity harder to reason about. The product gives customers a guided path from service selection to a confirmed start time, while centralizing the salon's operational controls.
- Customer booking for individual and grouped appointments
- Service, pricing, duration, schedule, capacity, and closure management
- Opaque booking links for cancellation and rescheduling
- Optional customer accounts with phone/password access
- Admin workflow for manual bookings, edits, statuses, and WhatsApp confirmations
- Calendar handoff through Google Calendar and
.ics - Live appointment updates with Supabase Realtime
- PostgreSQL enforcement for start-time capacity under concurrent writes
The TypeScript slot engine gives immediate availability feedback. PostgreSQL rechecks the same rule inside a trigger and takes a transaction-scoped advisory lock for the requested day/start pair. This prevents the interface from being the only protection against concurrent booking requests.
A customer can manage one appointment through an opaque bearer link or sign into an account associated with a normalized phone number. Account passwords are bcrypt-hashed; session tokens are random and only their HMAC hashes are stored.
Administrator access requires both a valid Supabase Auth session and an explicit admin profile. The application does not promote the first person who signs in.
Mobile / desktop browser
│
▼
Next.js App Router on Vercel
├── Public and admin UI
├── Server Actions + Zod validation
├── Supabase SSR administrator auth
└── Hashed customer sessions
│
▼
Supabase PostgreSQL
├── Row Level Security
├── Scheduling and appointment data
├── Realtime appointment publication
├── Transactional capacity trigger
└── Scheduled lifecycle updates
See Architecture and Security & privacy for the verified technical notes.
The public screenshots show only published salon content and an empty booking flow. No appointment was submitted while creating them.
Next.js 16, React 19, TypeScript, Tailwind CSS, Radix UI, Supabase PostgreSQL/Auth/Realtime/RLS, Zod, bcrypt, Vercel, and Node's test runner.
- Production build: passing
- TypeScript typecheck: passing
- ESLint: passing
- Automated tests: 6 passing
- npm audit: 0 known vulnerabilities at portfolio release time
- Gitleaks: 0 findings in the private repository history and sanitized showcase
- Public Vercel endpoint: HTTP 200 at
https://ohbarber-siteweb.vercel.app
- Distributed rate limiting and bot protection are not implemented yet.
- Capacity models appointments sharing the same start time, not every overlapping service interval; the staffing interpretation must be reconfirmed before changing this rule.
- Booking-management links are bearer tokens.
- Full RLS and concurrency integration tests require an isolated Supabase test project.
- Business impact metrics, production usage, analytics, and custom domain: TO CONFIRM WITH MOAD.
Product framing, UX, data model, full-stack architecture, implementation, security hardening, quality checks, and deployment preparation by Moad / DEVCOM.
The production repository remains private. Client data, database identifiers, credentials, operational screenshots, and internal deployment configuration are deliberately excluded here.

