Projects08 of 15
SANDHI Research Lab
A public website, member workspace and administration in one application
What it is
A research lab needs a public face, a place for its members to work, and someone to run both. SANDHI has all three in one Next.js application, built from first commit to production in fourteen days.
The public site
The site draws the lab’s premise literally: a research map threading five themes to the eight areas beneath them. Around it:
- projects that publish their progress;
- publications, people, news, events, opportunities, research notes and resources;
- full-text search that handles Bengali as well as English;
- a way to apply to join, or to propose research.
For members
- A dashboard of what is due this fortnight.
- Project workspaces with a task board and dated progress updates.
- Meetings with written-up notes and calendar export.
- An experiment log that records configuration and results against an append-only history.
- Publications and research notes drafted in Markdown with a live preview, maths and code included, then sent for review.
For administrators
Sixteen administrative managers sit behind both: review queues for papers and notes, an applications inbox that sends its decisions by email, approval of changes to public profiles, members and roles, and an audit log.
Security from the start
Security was a requirement from the start, not a pass at the end.
- Accounts are by invitation only.
- Two-factor sign-in is required of everyone, with passkeys supported.
- Passwords are checked against known breaches.
- Every administrative change is audited in the same database transaction as the change itself.
- Private files are only ever served through short-lived signed links.
Fast, despite rendering on demand
Every page renders on demand, because a nonce-based Content Security Policy rules out page caching. So the caching lives at the data layer instead, tagged and invalidated by every edit. Search runs on PostgreSQL’s own full-text indexes rather than a separate service.
Tested
More than 400 unit tests and more than 140 Playwright end-to-end tests. These include the security boundaries, such as a member being unable to reach an administrator’s page or action, and automated accessibility checks.
Deployed on free tiers, deliberately
- Vercel in Singapore, beside the Neon database, because each page makes several queries and each one pays that distance.
- Cloudflare for DNS, R2 file storage and mail routing.
- Resend for email.
Built with
Next.js 16, React 19, TypeScript, PostgreSQL with Prisma, Better Auth, Cloudflare R2 and Resend: 101 pages and 48 data models. It is live at sandhiresearch.org.