AssetFlow is a full-stack asset management system for tracking organizational assets throughout their lifecycle—from registration and allocation to booking, maintenance, auditing, transfer, return, and disposal.
The application provides role-specific workspaces for administrators, asset managers, department heads, and employees, backed by a secure REST API and MongoDB.
- Centralized asset inventory with categories, departments, locations, costs, conditions, and lifecycle status
- Image and document uploads for asset and maintenance records
- Employee allocation, return, and transfer workflows
- Shared-asset booking and cancellation
- Maintenance request, approval, assignment, and resolution tracking
- Department-level physical audits with discrepancy reporting
- Role-aware dashboards and navigation
- In-app notifications and activity history
- CSV reporting with human-readable asset, employee, and department data
- JWT authentication, protected routes, guest routes, and role-based access
- Password reset emails using trusted frontend reset links
- Realistic, repeatable demo database seeding
| Role | Primary capabilities |
|---|---|
| Admin | Manage organization data, users, departments, categories, audits, reports, and system activity |
| Asset Manager | Manage assets, allocations, transfers, bookings, and maintenance workflows |
| Department Head | View department-scoped data and review applicable transfer and maintenance operations |
| Employee | View personal allocations, book shared assets, request transfers, and raise maintenance requests |
- React 19
- Vite 8
- React Router
- Axios
- React Hook Form
- Recharts
- Lucide React
- React Hot Toast
- Node.js
- Express 5
- MongoDB and Mongoose
- JSON Web Tokens
- bcrypt
- Multer
- Nodemailer
- Faker
assetflow/
├── client/
│ ├── public/ Static frontend assets
│ └── src/
│ ├── api/ Shared Axios client
│ ├── components/ Reusable UI and route guards
│ ├── constants/ Roles and navigation configuration
│ ├── context/ Authentication state
│ ├── layouts/ Protected application layout
│ ├── pages/ Application pages
│ ├── routes/ Route configuration
│ ├── services/ Feature API services
│ └── styles/ Shared styles
├── docs/
│ └── frontend-architecture.md
└── server/
├── src/
│ ├── config/ Database configuration
│ ├── controllers/ Request handlers and workflows
│ ├── middleware/ Authentication, authorization, errors, uploads
│ ├── models/ Mongoose models
│ ├── routes/ Express route definitions
│ ├── seed/ Demo database seeders
│ └── utils/ Notifications, logs, exports, email, tokens
├── uploads/ Uploaded and seeded demo files
├── API_SPEC.md Detailed API contract
└── openapi.yaml OpenAPI definition
- Node.js 18 or newer
- npm
- MongoDB, either local or hosted
git clone https://github.com/darshangavate/odoo-hackathon-26.git
cd odoo-hackathon-26Create server/.env:
PORT=5000
MONGO_URI=mongodb://127.0.0.1:27017/assetflow
JWT_SECRET=replace-with-a-long-random-secret
FRONTEND_URL=http://localhost:5173
# Required for password-reset email delivery
EMAIL_USER=[email protected]
EMAIL_PASS=your-email-app-passwordFRONTEND_URL must be the trusted frontend origin. Password-reset emails use:
FRONTEND_URL/reset-password/:token
The frontend defaults to http://localhost:5000/api. To use another backend,
create client/.env:
VITE_API_BASE_URL=http://localhost:5000/apicd server
npm install
cd ../client
npm installOpen two terminals from the repository root.
Backend:
cd server
npm run devFrontend:
cd client
npm run devOpen http://localhost:5173.
The production-quality seeder creates departments, categories, 90 assets, allocations, bookings, maintenance requests, audits, notifications, and more than 250 activity-log entries.
Warning: seeding clears the existing AssetFlow collections before inserting the demo dataset. Do not run it against a database containing data you need to keep.
cd server
npm run seedAll seeded accounts use the password Demo@123.
| Role | Accounts |
|---|---|
| Admin | [email protected] |
| Asset Manager | [email protected] through [email protected] |
| Department Head | [email protected] through [email protected] |
| Employee | [email protected] through [email protected] |
Local API base URL:
http://localhost:5000/api
Protected requests use:
Authorization: Bearer <token>Main route groups:
| Route | Purpose |
|---|---|
/api/auth |
Registration, login, profile, and password reset |
/api/departments |
Department management and metadata |
/api/categories |
Asset category management and metadata |
/api/employees |
Employee management and allocation metadata |
/api/assets |
Asset lifecycle management and uploads |
/api/allocations |
Allocation, return, and transfer workflows |
/api/bookings |
Shared-asset bookings |
/api/maintenances |
Maintenance workflows |
/api/audits |
Physical asset audits |
/api/dashboard |
Role-scoped dashboard statistics |
/api/reports |
Reports and CSV exports |
/api/notifications |
User notifications |
/api/activity-logs |
System activity history |
See server/API_SPEC.md for the complete contract and server/openapi.yaml for the OpenAPI definition.
Uploaded files are served from:
http://localhost:5000/uploads/<filename>
npm run dev # Start the Vite development server
npm run build # Create a production build
npm run lint # Run ESLint
npm run preview # Preview the production buildnpm run dev # Start with Nodemon
npm start # Start with Node.js
npm run seed # Clear and populate the demo databaseThe frontend uses a shared Axios client for base URL configuration, authorization headers, timeouts, and normalized errors. Feature services keep API calls separate from rendering and local page state.
Authentication is managed through React context. Public authentication pages
use GuestRoute, while application pages use role-aware ProtectedRoute
guards and a shared layout.
The backend follows an Express route-controller-model structure. Authorization is enforced by middleware and controller-level ownership checks. Notifications and activity logs are secondary operations, so failures in those systems do not roll back successful primary workflows.
For diagrams and a deeper frontend walkthrough, see docs/frontend-architecture.md.
- Use a strong, unique
JWT_SECRET. - Restrict CORS to trusted frontend origins before public deployment.
- Use a dedicated database and email account.
- Ensure
server/uploadsis writable and backed by persistent storage. - Serve the application behind HTTPS.
- Never commit
.envfiles or production credentials. - Run
npm run buildinclientbefore deploying the frontend.
The backend package is currently marked as ISC. Add a repository-level license file before redistributing the complete project.