Md. Asif Uddin

    Projects08 of 15

    SANDHI Research Lab

    A public website, member workspace and administration in one application

    A research lab's public website, member workspace and administration in one application, built from first commit to production in fourteen days. Invitation-only accounts, mandatory two-factor sign-in, and fast on free tiers even though every page renders on demand.

    Open the siteSource code

    What it is

    A research lab needs a public face, a place for its members to work, and someone to run both. SANDHI has all three in one Next.js application, built from first commit to production in fourteen days.

    The public site

    The site draws the lab’s premise literally: a research map threading five themes to the eight areas beneath them. Around it:

    • projects that publish their progress;
    • publications, people, news, events, opportunities, research notes and resources;
    • full-text search that handles Bengali as well as English;
    • a way to apply to join, or to propose research.

    For members

    • A dashboard of what is due this fortnight.
    • Project workspaces with a task board and dated progress updates.
    • Meetings with written-up notes and calendar export.
    • An experiment log that records configuration and results against an append-only history.
    • Publications and research notes drafted in Markdown with a live preview, maths and code included, then sent for review.

    For administrators

    Sixteen administrative managers sit behind both: review queues for papers and notes, an applications inbox that sends its decisions by email, approval of changes to public profiles, members and roles, and an audit log.

    Security from the start

    Security was a requirement from the start, not a pass at the end.

    • Accounts are by invitation only.
    • Two-factor sign-in is required of everyone, with passkeys supported.
    • Passwords are checked against known breaches.
    • Every administrative change is audited in the same database transaction as the change itself.
    • Private files are only ever served through short-lived signed links.

    Fast, despite rendering on demand

    Every page renders on demand, because a nonce-based Content Security Policy rules out page caching. So the caching lives at the data layer instead, tagged and invalidated by every edit. Search runs on PostgreSQL’s own full-text indexes rather than a separate service.

    Tested

    More than 400 unit tests and more than 140 Playwright end-to-end tests. These include the security boundaries, such as a member being unable to reach an administrator’s page or action, and automated accessibility checks.

    Deployed on free tiers, deliberately

    • Vercel in Singapore, beside the Neon database, because each page makes several queries and each one pays that distance.
    • Cloudflare for DNS, R2 file storage and mail routing.
    • Resend for email.

    Built with

    Next.js 16, React 19, TypeScript, PostgreSQL with Prisma, Better Auth, Cloudflare R2 and Resend: 101 pages and 48 data models. It is live at sandhiresearch.org.