# Normogen Project Status ## Project Overview **Project Name**: Normogen (Balanced Life in Mapudungun) **Goal**: Open-source health data platform for private, secure health data management **Current Phase**: Phase 2.8 — Implemented (drug interactions live). Open work is the frontend (Phase 3). **Last Updated**: 2026-06-27 --- ## 📊 Overall Status | Area | Status | |------|--------| | **Backend** | ✅ Phase 2.x feature-complete (through drug interactions). Production-deployed on Solaria. | | **Security** | ✅ Hardening pass complete (token-version validation, refresh-token persistence, fail-fast config, real-IP audit). | | **Tests** | ✅ 18 unit tests + 13 integration tests (auth + medication flows), CI-gated with a MongoDB service. | | **Frontend** | 🚧 Early — Login/Register pages + API/store layer exist; router not yet wired; no dashboard. | | **Deployment** | 🚧 Docker image is built manually (CI can't run DinD on Forgejo); otherwise operational. | The backend implements every planned 2.x phase. The honest open work is the **frontend** (Phase 3) and the operational gaps noted at the bottom. --- ## Phase Progress ### Phase 1: Project Planning ✅ COMPLETE (100%) - [x] Project documentation - [x] Architecture design - [x] Technology stack selection - [x] Initial repository setup **Completed**: 2025-Q4 --- ### Phase 2: Backend Development 🚧 91% COMPLETE #### Phase 2.1: Backend Project Initialization ✅ COMPLETE (100%) - [x] Cargo project setup - [x] Dependency configuration (Axum 0.7, MongoDB 2.8) - [x] Basic project structure - [x] Docker configuration - [x] CI/CD pipeline (Forgejo Actions) **Completed**: 2025-Q4 --- #### Phase 2.2: MongoDB Connection & Models ✅ COMPLETE (100%) - [x] MongoDB 7.0 connection setup - [x] User model with repository pattern - [x] Health data models (medications, stats, lab results) - [x] Database abstraction layer - [x] Error handling infrastructure **Completed**: 2025-Q4 --- #### Phase 2.3: JWT Authentication ✅ COMPLETE (100%) - [x] JWT token generation (jsonwebtoken 9) - [x] Access tokens (15 minute expiry) - [x] Refresh tokens (30 day expiry) - [x] Token rotation system - [x] Login/register/logout endpoints - [x] Password hashing (PBKDF2, 100K iterations) - [x] Authentication middleware **Completed**: 2026-01 --- #### Phase 2.4: User Management Enhancement ✅ COMPLETE (100%) - [x] Password recovery with zero-knowledge phrases - [x] Recovery phrase verification - [x] Password reset with token invalidation - [x] Enhanced profile management - [x] Account deletion with confirmation - [x] Account settings management - [x] Change password endpoint **Completed**: 2026-02-15 --- #### Phase 2.5: Access Control ✅ COMPLETE (100%) - [x] Permission model (Read, Write, Admin) - [x] Share model for resource sharing - [x] Permission middleware - [x] Share management API (CRUD) - [x] Permission check endpoints **Completed**: 2026-02-15 --- #### Phase 2.6: Security Hardening ✅ COMPLETE (100%) - [x] Rate limiting implementation (tower-governor) - [x] Account lockout policies (5 attempts, 15min base, max 24hr) - [x] Security audit logging - [x] Session management (list, revoke sessions) - [x] Security headers middleware **Completed**: 2026-02-20 --- #### Phase 2.7: Health Data Features ✅ IMPLEMENTED - [x] Medication management (CRUD operations) - [x] Medication adherence tracking - [x] Health statistics tracking (weight, BP, etc.) - [x] Lab results storage - [x] OpenFDA API integration for drug data - [x] Comprehensive test coverage **Completed**: 2026-03-08 --- #### Phase 2.8: Drug Interactions ✅ IMPLEMENTED - [x] Drug interaction checking (`/api/interactions/check`, `/check-new`) - [x] Ingredient mapper - [x] Interaction service (in-memory interaction data) - [ ] Automated reminder system *(not yet started)* - [ ] Advanced health analytics *(not yet started)* - [ ] Healthcare data export (FHIR, HL7) *(not yet started)* - [ ] Medication refill tracking *(not yet started)* - [ ] Caregiver access *(not yet started)* **Completed (core)**: drug interaction checking is live. The remaining items are future enhancements; see the [roadmap](./ROADMAP.md). --- #### P0/P1 Security + Tests ✅ IMPLEMENTED - [x] `token_version` validation in the JWT middleware (stale tokens rejected after password change) - [x] Refresh tokens persisted **hashed** in MongoDB (survive restarts; revocable) - [x] `/api/auth/refresh` (rotation + reuse detection) and `/api/auth/logout` - [x] Fail-fast config (`APP_ENVIRONMENT=production` rejects insecure `JWT_SECRET`/`ENCRYPTION_KEY`) - [x] Real client-IP resolution in audit logs (`X-Forwarded-For` → `X-Real-IP` → socket) - [x] Handler `.unwrap()` cleanup (panics → clean error responses) - [x] Integration tests rewritten against an isolated test DB --- ### Phase 3: Frontend Development 🔮 PLANNED (0%) #### Phase 3.1: Frontend Foundation - [ ] React app setup complete - [ ] Basic routing (React Router DOM) - [ ] Authentication flow (login, register, logout) - [ ] API service layer (axios) - [ ] State management (Zustand) **Status**: 10% complete - Basic structure exists #### Phase 3.2: Core Features - [ ] Dashboard with health overview - [ ] Medication management UI - [ ] Health statistics visualization (charts) - [ ] Lab results viewer - [ ] Profile and settings pages #### Phase 3.3: Advanced Features - [ ] Medication reminders UI - [ ] Data export functionality - [ ] Caregiver access management - [ ] Notifications center --- ### Phase 4: Mobile Development 🔮 FUTURE (0%) - [ ] iOS app architecture - [ ] Android app architecture - [ ] Mobile-specific features (biometrics, offline sync) --- ### Phase 5: Advanced Features 🔮 FUTURE (0%) #### Phase 5.1: Integration - [ ] Wearable device integration - [ ] EHR system integration - [ ] Pharmacy APIs - [ ] Telehealth integration #### Phase 5.2: AI/ML Features - [ ] Symptom prediction - [ ] Medication optimization - [ ] Health risk scoring - [ ] Personalized recommendations --- ## Current Status **Backend**: Phase 2.x feature-complete; deployed on Solaria (Docker). **Frontend**: Early stage — Login/Register pages + API/store layer; router not yet wired. **Database**: MongoDB 7.0 **Deployment**: Docker on Solaria (homelab); image built manually (not in CI). **Tests**: 18 unit + 13 integration (auth + medication), CI-gated with MongoDB. ### Known security gaps (tracked, not in current scope) - Rate limiting middleware is a stub (deferred). - A few borderline `.unwrap()` calls remain in repository `inserted_id` paths. --- ## Tech Stack ### Backend - **Language**: Rust (edition 2021) - **Framework**: Axum 0.7 (async web framework) - **Database**: MongoDB 7.0 - **Authentication**: JWT (jsonwebtoken 9) - Access tokens: default 15 minute expiry (configurable) - Refresh tokens: default 7 day expiry (configurable); stored hashed in MongoDB, rotated, revocable - **Password Security**: PBKDF2 (100K iterations) - **Security**: `token_version` invalidation; account lockout; audit logging with real client-IP resolution - **Deployment**: Docker, Docker Compose (image built manually) - **CI/CD**: Forgejo Actions ### Frontend - **Framework**: React 19.2.4 - **Language**: TypeScript 4.9.5 - **UI Library**: Material-UI (MUI) 7.3.9 - **State Management**: Zustand 5.0.11 - **HTTP Client**: Axios 1.13.6 - **Routing**: React Router DOM 7.13.1 - **Charts**: Recharts 3.8.0, MUI X-Charts 8.27.4 ### Development Tools - **Version Control**: Git - **CI/CD**: Forgejo Actions - **Container**: Docker, Docker Compose - **Code Quality**: cargo clippy, cargo fmt --- ## API Endpoints Implemented ### Authentication (`/api/auth`) - ✅ `POST /register` - User registration - ✅ `POST /login` - User login - ✅ `POST /logout` - User logout - ✅ `POST /refresh` - Refresh access token - ✅ `POST /recover-password` - Password recovery ### User Management (`/api/users`) - ✅ `GET /api/users/me` - Get current user - ✅ `PUT /api/users/me` - Update profile - ✅ `DELETE /api/users/me` - Delete account - ✅ `POST /api/users/me/change-password` - Change password - ✅ `GET/PUT /api/users/me/settings` - User settings ### Shares (`/api/shares`) - ✅ `POST /` - Create share - ✅ `GET /` - List shares - ✅ `PUT /:id` - Update share - ✅ `DELETE /:id` - Delete share ### Permissions (`/api/permissions`) - ✅ `POST /check` - Check permissions ### Sessions (`/api/sessions`) - ✅ `GET /` - List sessions - ✅ `DELETE /:id` - Revoke session - ✅ `DELETE /all` - Revoke all sessions ### Medications (`/api/medications`) - ✅ `POST /` - Create medication - ✅ `GET /` - List medications - ✅ `GET /:id` - Get medication - ✅ `POST /:id` - Update medication - ✅ `POST /:id/delete` - Delete medication - ✅ `POST /:id/log` - Log medication dose - ✅ `GET /:id/adherence` - Get adherence data ### Health Statistics (`/api/health-stats`) - ✅ `POST /` - Create health stat - ✅ `GET /` - List health stats - ✅ `GET /:id` - Get health stat - ✅ `PUT /:id` - Update health stat - ✅ `DELETE /:id` - Delete health stat - ✅ `GET /trends` - Get trends ### Drug Interactions (`/api/interactions`) *(Phase 2.8)* - ✅ `POST /check` - Check interactions between a set of medications - ✅ `POST /check-new` - Check a new medication against existing ones ### Health Check - ✅ `GET /health` - Health check endpoint - ✅ `GET /ready` - Readiness check endpoint --- ## Next Milestones 1. 🚧 **Phase 3 — Frontend** — wire the router, build the dashboard and feature UIs. 2. 🔮 **Phase 2.8 follow-ups** — reminders, analytics, data export, caregiver access. 3. 🔮 **Phase 4 — Mobile** — iOS and Android apps. 4. 🔮 **Phase 5 — Advanced** — integrations, AI/ML features. --- ## Dependencies ### Backend (Cargo.toml) ```toml axum = "0.7.9" tokio = "1.41.1" mongodb = "2.8.2" jsonwebtoken = "9.3.1" reqwest = "0.12.28" tower-governor = "0.4.3" ``` ### Frontend (package.json) ```json { "react": "19.2.4", "typescript": "4.9.5", "@mui/material": "7.3.9", "zustand": "5.0.11", "axios": "1.13.6", "react-router-dom": "7.13.1" } ``` --- **Last Updated**: 2026-06-27 **Maintained By**: Project maintainers