corruption-watch-ph/
A public reporting site. A citizen picks a department, describes what happened, and can file without giving a name. An admin console reviews what arrives. The form is the easy half. The hard half is making sure nobody except an admin can ever read what it collects.
A report is only safe if it stays private
Reporting corruption is only safe if the report stays private. A form that accepts anonymous submissions but leaves them world-readable is worse than no form at all. It collects exactly the people who most needed protecting and puts them somewhere findable.
A public form, an admin console, and rules between them
- A public report form covering department, description and optional anonymity, with an inline help responder for people who are not sure what counts.
- An admin console that lists submissions and lets a reviewer work through them.
- Firestore security rules that let anyone create a report and let nobody read one back unless they are an admin.
The security rules are the product
The rules are the product. They get exercised by a test suite that boots the real Firestore emulator and runs assertions as an anonymous visitor, a signed-in non-admin and an admin. That is 25 assertions on this project's rules alone, run on every push and every pull request that touches them. The same workflow runs the repository's other three rules suites in the same way, 144 assertions in total, each against the real emulator rather than a mock.
allow read: if true turned five denial assertions red and exited
non-zero. A test suite that cannot go red guards nothing, so I made it go red on
purpose before trusting it.
The oldest project here, and it shows
This is the oldest project here and it shows. The behaviour lives in inline
<script> blocks inside the HTML, and two JavaScript files sit
empty as stubs from a refactor I never finished. The styling leans on a CDN, which
is a dependency on somebody else's uptime that I would not choose again.
It stays in the portfolio because it is where I learned the lesson the other four projects are built on. The visible part of an app is rarely the part protecting anyone.