A simple template to run webpack,react and express server.
- Webpack
- React
- React router
- Redux toolkit
- Expressjs
- Server side
- session
- RBAC
- MongoDB
- Multiple Tenant organization
- Departments
- Roles
- Permission
├── client
│ ├── dist
│ │ ├── bundle.js
│ │ ├── bundle.js.LICENSE.txt
│ │ └── index.html
│ ├── package.json
│ ├── package-lock.json
│ ├── src
│ │ ├── App.js
│ │ ├── index.html
│ │ └── index.js
│ └── webpack.config.js
├── LICENSE
├── README.md
└── server
├── index.js
├── package.json
└── package-lock.json
4 directories, 14 files
- Clone the repo
- Create
server/.envwithMONGODB_URIset to your MongoDB connection string. - From the project root, run
npm install(installs root, client, and server dependencies). - Run
npm run devto start the API and the webpack client together. - Optionally run
npm run seed:demoto load Acme Corp with departments, roles, and employees (passworddemo123). - The client is at http://localhost:3031/ and the API at http://localhost:3000/api. In development the client also proxies
/apito the server.
Optional: client/.env can set REACT_APP_API_URL (defaults to /api).
npm run build from the project root builds the client for production.
cd servernpm install- Make sure MongoDB is running locally, or set
MONGODB_URIto your MongoDB connection string. node index.jsto start the server- The api will be served at http://localhost:3000/api and the front end bundled app will be served at http://localhost:3000/
The server uses MongoDB with Mongoose models in server/models.
Set MONGODB_URI to override the default local database:
MONGODB_URI=mongodb://127.0.0.1:27017/rbacOrganization — tenant (name, unique slug, plan).
Department — tenantId, name, optional parentId, ancestors (filled on save). Index { tenantId, parentId }.
Employee — login identity and org member. tenantId, name, unique { tenantId, username } and { tenantId, email }, designation, phone, hashed password, departmentId, managerId, ancestorManagers, roleIds, denormalized permissions, isActive. Sessions store this employee (without password) plus resolved roles and permissions. The signed-in employee’s details and org hierarchy are on /profile (GET/PATCH /api/profile). Department can only be changed by that employee’s manager chain (PATCH /api/employees/:id/department).
AuthSession — one record per device login (sessionId, employeeId, userAgent, ip, lastSeenAt, expiresAt). Concurrent logins from different devices stay active; /profile lists them.
Role — per-tenant (tenantId, unique { tenantId, name }), string permissions (e.g. "employee.read"), isSystem.
RoleAssignment — tenantId, employeeId, roleId, optional department scope.
Todo — title, description, status (Pending | Done | In progress), tenantId, employee (Employee ref).
Auth: POST /api/register creates an organization, an Admin role, and the first employee, then saves an Express session in MongoDB. POST /api/login accepts email, password, and optional organizationSlug. Each login creates (or updates) its own session so multiple devices can stay signed in at once. Protected routes use session cookies plus checkAuthentication / checkAuthorization (role names and/or permission strings).