A robust, secure clinic management and patient record tracking system designed specifically for Ophthalmologists. Built with a modern Node.js and Express backend, it simplifies clinical workflows, manages patient demographics, tracks visit histories (logs), handles canvas drawings for eye diagnostics, generates PDF reports, and automates patient communication via WhatsApp and email.
- Comprehensive Patient Records: Register and search patients easily. Manage demographic details, clinical parameters, insulin usage, and HBA1c levels.
- Visit Logs & History: Track patient visits systematically. Every consultation log details treatments, advice, intraocular pressure (IOP), and diabetic retinopathy (DR) progression.
- Interactive Canvas Drawing: Perform visual/structural ocular diagrams directly inside the browser and attach them to patient records.
- Communication Automation: Send automated notifications, receipts, and clinical summaries via email (Nodemailer) and WhatsApp (using
@whiskeysockets/baileysandwhatsapp-web.js). - Data Export: Export patient lists and detailed medical logs to Microsoft Excel spreadsheets using
exceljs. - PDF Generation: Compile patient history, treatments, and ophthalmic diagnostics into clean PDF reports using
pdf-lib. - Security-First Architecture: Implements Passport-based local & Google OAuth authentication, session persistence using PostgreSQL, HTTP header hardening via
helmet, and request rate-limiting on sensitive routes to prevent brute-force attacks.
- Backend: Node.js, Express.js
- Frontend Template Engine: EJS, Tailwind CSS
- Database: PostgreSQL (with
connect-pg-simplesession store) - Security: Passport.js (Local & Google OAuth2), Helmet, Express Rate Limit, Bcrypt
- APIs & Messaging: WhatsApp Web API (
whatsapp-web.js,baileys), Nodemailer - Utilities: ExcelJS, PDF-Lib, Puppeteer-Core, Multer (file uploads)
graph TD
Client[Client / Web Browser] -->|HTTPS| Express[Express App]
Express --> Auth[Passport.js Auth]
Express --> Security[Helmet & Rate Limiter]
Express --> DB[(PostgreSQL Database)]
Express --> Excel[ExcelJS Export]
Express --> PDF[PDF-Lib Generator]
Express --> WhatsApp[WhatsApp Bot Service]
Express --> Mail[Nodemailer Service]
Auth --> Local[Local Strategy]
Auth --> Google[Google OAuth 2.0]
Optho-App/
├── .agents/ # Agent configuration directory
├── components/ # Backend helper components
│ ├── clean.js # Automated file cleanup task
│ ├── databaseMechanism.js # Patient log utilities
│ ├── db.js # PostgreSQL pool setup
│ ├── mailer.js # Email handling module
│ └── whatsapp.js # WhatsApp client initialization
├── public/ # Static public assets (CSS, JS, Images)
├── views/ # EJS templates for app rendering
│ ├── addPat.ejs # Patient registration page
│ ├── index.ejs # Home dashboard
│ ├── patDet.ejs # Visit log view
│ └── patientDet.ejs # Main patient details dashboard
├── index.js # Express application entry point
├── queries.sql # Database schema setup queries
├── package.json # Application dependencies and scripts
└── Dockerfile # Container configuration
- Node.js (v18.x recommended)
- PostgreSQL (Running local or remote instance)
git clone https://github.com/ramanan-2735/Optho-App.git
cd Optho-Appnpm installRun the schema setup script in your PostgreSQL instance:
psql -U your_user -d your_database -f queries.sqlCreate a .env file in the root directory matching the variables in .env.example:
PORT=3000
DB_URL=postgresql://username:password@localhost:5432/optho_db
SESSION_SECRET=your_jwt_or_session_secret
GOOGLE_CLIENT_ID=your_google_oauth_client_id
GOOGLE_CLIENT_SECRET=your_google_oauth_client_secretDevelopment Mode:
npm run devProduction Mode:
npm startThis repository incorporates essential security measures to ensure patient data confidentiality and system resilience:
- Helmet: Sets secure HTTP response headers to protect against typical web vulnerabilities.
- Express Rate Limiter: Protects auth endpoints (
/login,/register) from credential stuffing and DDoS attacks. - Bcrypt Hashing: Secures user passwords using cryptographic salt hashing.
- Parameterization: All database queries are fully parameterized to protect against SQL Injection attacks.
This project is licensed under the MIT License. See the LICENSE file for details.