Back to projects

Behind the Build / Production Platform / Access Gated

Garage-Pass gives each real car a digital home: identity, ownership context, service records, parts, receipts, events, awards, and community activity connected to one vehicle record.

This case study requires an access password. The production member experience is also access-controlled.

Product stateProduction-facing

Live infrastructure and authenticated member surfaces; broader guest access is intentionally gated.

System shapeFrontend + API + data

SvelteKit on Firebase Hosting, Express on Cloud Run, and Firestore behind a shared data adapter.

VerificationLayered release gate

Static analysis, unit, integration, emulator, build, security, and authenticated browser checks.

Car history is usually fragmented across social posts, receipts, event photos, service notes, ownership paperwork, and memory. Garage-Pass makes the vehicle—not a generic feed—the durable center of that story.

I provide the concept and product direction for Garage-Pass, with a focus on connecting vehicle history, ownership, and community in one experience.

The active frontend is a statically deployed SvelteKit 2 application using Svelte 5 runes and route-based code splitting. Firebase Hosting serves the frontend and rewrites API traffic to an Express 5 service on Cloud Run. Firestore is the production database; local development and most fast tests use SQLite through a shared adapter so business logic is not tied directly to either store.

Short-lived JWT access tokens pair with rotating, hashed refresh tokens. Auth, route guards, rate limiting, input sanitization, and explicit production exposure rules protect member and administrative surfaces. Guest entry is currently restricted by the launch gate.

A static frontend plus independently scaled API keeps CDN delivery and server capacity separate, but requires disciplined client/API contracts. A dual SQLite/Firestore data layer makes local iteration and tests fast, but adapter parity becomes a release responsibility. The public launch gate reduces casual product review, so this case study provides architecture context for an authorized walkthrough.

Behavior is checked at the right boundary.

  • Jest and Supertest cover backend units, service behavior, routes, and integrations.
  • Vitest covers Svelte components and frontend logic.
  • Firestore emulator and rules suites exercise production-store behavior separately.
  • Playwright checks authenticated end-to-end paths in the full release command.

More than a build check.

  • Svelte diagnostics and production build.
  • OpenAPI coverage, link, asset, organization, and adapter-parity checks.
  • Secret scanning plus unsafe HTML and UI-state scanners.
  • Authenticated browser coverage after the lower-level suites.

The vehicle connects the story.

  • Vehicle identity connects ownership context, records, and community activity.
  • Service notes, parts, and receipts belong to the vehicle record.
  • Events and awards add context to the car’s history.
  • Member workflows require authenticated access.