How Nordhavn Running Club is built
- Joining makes a passkey. The server keeps its public key and checks the client data, the challenge, the site, the flags for a present and verified person, and, when signing in, the signature and the counter.
- A session is a random token in a cookie the page cannot read. The server keeps only the token’s hash.
- Every route names the role it needs. The server looks the route up in this table and refuses a request from a role below it before the route runs.
- An event has a number of places. When they are taken, a person joins the waiting list, and a place given back goes to the first person on it.
- A paid place is held for 31 minutes while Stripe Checkout is open. It is confirmed only by Stripe’s webhook, checked with HMAC-SHA256 against the endpoint’s secret within 5 minutes of its time, and a repeated event changes nothing.
- The club’s mail goes through the same path as the booking prototype: Resend when a key is set, otherwise the outbox on the Mail page.