A unified inventory and POS system that enforces digitally-signed, role-gated workflows for every inventory mutation.
StockGate is a unified Inventory & POS system for a single-building retail facility with two zones — a Basement (storage/receiving) and a Shop Floor (sales). It replaces paper-and-memory tracking with digitally-signed, role-gated workflows so every movement of stock is authorised, attributed, and auditable.
Before StockGate, inventory was tracked manually, which produced unexplained missing goods, zero accountability for who moved what, and no digital audit trail from supplier intake to customer sale. StockGate closes all three gaps by making every inventory mutation an atomic, role-checked, logged operation.
SECURITY DEFINER SET search_path = public), giving transactional guarantees and eliminating TOCTOU race conditions. Insufficient stock raises an exception and rolls the whole transaction back.quantity >= 0 enforced by a DB CHECK).users (4 roles, soft-delete) · products (unique indexed barcode) · inventory (per-zone, quantity >= 0) · transfer_requests (JSONB item lists) · audit_logs (immutable) · notifications (capped at 50/user). Constraints — CHECKs, foreign keys, and unique indexes — are enforced at the database level, not just in application code.
| Layer | Technology | Rationale |
|---|---|---|
| Backend | Node.js + Express.js | Lightweight, fast, strong ecosystem |
| Database | Supabase (hosted PostgreSQL) | Production-grade, zero local DB setup |
| Auth | Custom JWT + bcrypt (httpOnly cookies) | Full control over role-based access |
| Mutations | PostgreSQL RPC (SECURITY DEFINER) | Atomic transactions; no TOCTOU races |
| Validation | Zod | Schema-first server-side validation |
| Frontend | Vanilla HTML/CSS/JS | No build step, instant deployment |