Royal Fitness Club Platform (API Server & Web Portal)

  • Backend
  • Full-Stack
  • TypeScript
  • REST APIs

Production · Node.js, Express, Angular, TypeScript …

Executive Overview

A full-stack commercial membership and operations platform comprising a Node.js/Express REST API backend and an Angular client portal, managing member subscriptions, check-in tracking, and administrative scheduling.
The Challenge & Bottleneck

Core Problem

Commercial fitness facilities suffer operational bottlenecks: manual paper registers cause check-in congestion, subscription renewals are frequently missed due to lack of automated alerts, and combining frontend presentation with backend business logic in monolithic codebases makes mobile integration difficult.

Engineering Approach

Architectural Solution

Engineered a decoupled commercial platform pairing a secured Express REST API with an Angular single-page application. Features JWT session authentication, automated subscription expiration cron workers, role-based authorization for front-desk staff vs club owners, and responsive attendance logging.

Quantified Outcomes

Measurable Impact

Automated daily check-ins for hundreds of active members, cut administrative renewal tracking time by 80%, and delivered a reliable production platform deployed for continuous commercial operation.

System Architecture

Component topology, protocol boundaries, and data flow.

Royal Fitness Club Platform (API Server & Web Portal) System Topology
Architecture Flow
CLIENT CONSUMERWeb & API CallsHTTPS / REST PayloadsJSON Schema InputBOUNDARY GATEWAYNginx / Reverse ProxyTLS TerminationRate Limiting & AuthNSERVICE CORE LOGIC• Domain Services & Controllers• DTO Runtime Validation• AWS Secrets Manager Config• Health Readiness ProbesPERSISTENCEPostgreSQL / RedisACID TransactionsDocker / EKS Hosted

Reliability & Production Security

Implemented strict middleware-level request validation, password hashing with bcrypt, JWT token expiration and rotation, and optimized database indexing on member IDs and phone numbers for sub-15ms check-in lookups.

Deployment & Infrastructure

Deployed on Linux VPS behind an Nginx reverse proxy providing TLS termination and static asset caching, managed with PM2 process manager for zero-downtime restarts.
Engineering Post-Mortem & Insights

What I Learned

Technical trade-offs, battle-tested discoveries, and operational takeaways from this project.

1

Enforce Security at Middleware Boundaries, Not Client UI Routes

Hiding a button in an Angular template does not secure an endpoint. Authorization rules must be strictly enforced at every backend Express route middleware layer to prevent unauthorized API calls.

2

Decoupled REST Architecture Enables Omnichannel Expansion

Separating the backend API entirely from the Angular web application allowed the server to simultaneously power mobile check-in apps without rewriting business rules.

3

Database Indexing on High-Frequency Lookups Prevents Check-in Queues

During peak gym hours, hundreds of members check in within minutes. Adding unique compound indexes on phone number and membership ID eliminated table scans and dropped lookup times from 400ms to under 10ms.

4

Automated Expiration Calculations Prevent Revenue Leakage

Calculating subscription validity dynamically on every request can cause discrepancies across time zones. Storing normalized UTC expiration timestamps with daily cron audit jobs ensures unambiguous member billing.

Future Roadmap & Architectural Evolution

  • →Integrate automated WhatsApp and SMS renewal reminder webhooks.
  • →Add multi-branch membership pass synchronization.
Royal Fitness Club Platform (API Server & Web Portal) | Siddhant Ghosh