Kunal Chaudhari
Open to work Let's talk

(Enterprise) Jun 2025 — Present · Webbrains Technologies

TATA Advanced Systems

Company sign-in, and a permanent record of every stock movement.

An inventory system for an enterprise manufacturer. Staff sign in with their company accounts, stock is tracked rack by rack, and every movement is recorded with who did it and when.

Role
Full Stack Developer
Focus
Directory auth, RBAC, audit trail
Status
Live and maintained

(01) In numbers

  • 169REST endpoints

    Stock, transfers, adjustments and reconciliation

  • 26Mongoose models

    Including the audit trail the ledger is read from

  • 3Roles

    Admin, Manager and Operator, with different reach

  • SSODirectory sign-on

    No second set of credentials to issue or revoke

(02) Under the hood

From a terminal on the floor to a row in the ledger

  1. 01 · OPERATOR

    Floor terminal

    A stock movement starts with a person at a terminal, and the system has to be able to name that person afterwards.

  2. 02 · DIRECTORY

    LDAP bind

    Credentials are checked against the directory the organisation already runs. Nothing new is issued here, and nothing new has to be revoked later.

  3. 03 · SESSION

    JWT issued

    The directory says who; the session carries it. Every request after this one is attributable without another round trip.

  4. 04 · ACCESS

    Admin, Manager, Operator

    Roles and permissions are records in the model rather than branches in a controller. Changing what a Manager may do is not a change to code.

  5. 05 · API

    169 endpoints

    Express routers per module — stock, transfers, adjustments, reconciliation — with validation applied before the handler.

  6. 06 · DOMAIN

    Stock movement

    The service that moves stock is the service that records the move. There is no path that does one without the other.

  7. 07 · LEDGER

    Audit row

    User, action and timestamp, written with the transaction. Reconciliation reads the ledger instead of inferring from the current quantity.

(03) The story

01 — The Problem

Every movement had to be attributable

Stock that moves without a name against it is stock you cannot reconcile. And the staff moving it already had directory credentials — a second account per person is one more thing to provision, rotate, and forget to disable.

  • Every transaction traceable to a person and a time.
  • Three roles with genuinely different reach over the same data.
  • No second identity store to maintain alongside the directory.

02 — What I Built

Directory sign-on, and the audit row in the same write

LDAP authenticates against the organisation's own directory and the session carries the role. Stock movement and audit record are written by one code path, so no route can move a quantity quietly.

  • LDAP single sign-on, issuing role-carrying JWT sessions.
  • Dynamic role and permission models for Admin, Manager and Operator.
  • 169 endpoints across 26 Mongoose models, validated in middleware.
  • An audit row with user and timestamp on every stock transaction.

03 — What Changed

Reconciliation has something to read

The ledger answers who moved this and when, directly, instead of that question being reconstructed from quantities. Access follows the directory: when a person leaves it, they leave the system.

  • Discrepancies are traced through the audit trail rather than inferred.
  • Joiners and leavers are handled once, in the directory.
  • A role's reach changes in the permission model, not in a controller.

(04) Architecture

Identity at the bottom, the ledger at the top

  1. 01

    Terminals

    Operator, manager and administrator views onto the same inventory service.

  2. 02

    Directory

    LDAP: the organisation's existing identity, used as it is.

  3. 03

    API

    Express modules for stock, transfers, adjustments and reconciliation.

  4. 04

    Access

    Dynamic role and permission models, resolved per route.

  5. 05

    Domain

    The stock service — a movement and its audit record on one path.

  6. 06

    Data

    26 Mongoose models, with the audit trail indexed for reconciliation.

(05) Decisions

Why it is built this way

  1. (01)

    Identity stays where it already lives

    Authenticating against LDAP means the system holds no opinion about passwords. Provisioning, rotation and revocation stay with the directory, which is where they were being done anyway.

  2. (02)

    The audit row is not optional

    It is written by the same function that moves the stock, not by a caller who might forget. An unaudited movement would have to be a bug in one place rather than an omission in a dozen.

  3. (03)

    Roles are a model, not a branch

    Admin, Manager and Operator are records with permissions attached. Adding a fourth is data; a controller full of role comparisons would have been a deploy.

(06) Built with

What it runs on

Enterprise identity, with the audit trail treated as a first-class model.

For the technically curiousLDAP single sign-on, and an audit row on every stock movement. An enterprise stock system where every movement had to be attributable, and where staff already had directory credentials they should not have to duplicate. LDAP single sign-on now carries role-based permissions for Admin, Manager and Operator, and every stock transaction writes an audit row with user and timestamp for reconciliation.

Node.jsExpressMongoDBMongooseReactLDAPJWTRBACDockerNginxPM2Winston