Prototypes Nordhavn Running ClubP15 · Club platform
The club
How Nordhavn Running Club is built
  1. Joining makes a passkey. The server keeps its public key and checks the client data, the challenge, the site, the flags for a present and verified person, and, when signing in, the signature and the counter.
  2. A session is a random token in a cookie the page cannot read. The server keeps only the token’s hash.
  3. Every route names the role it needs. The server looks the route up in this table and refuses a request from a role below it before the route runs.
  4. An event has a number of places. When they are taken, a person joins the waiting list, and a place given back goes to the first person on it.
  5. A paid place is held for 31 minutes while Stripe Checkout is open. It is confirmed only by Stripe’s webhook, checked with HMAC-SHA256 against the endpoint’s secret within 5 minutes of its time, and a repeated event changes nothing.
  6. The club’s mail goes through the same path as the booking prototype: Resend when a key is set, otherwise the outbox on the Mail page.