Build notes · Goh Kun Ming
FitnessQuest Gamified Fitness Application
Software · Public project
Oct 2024 – Feb 2025
Project overview
A gamified fitness application with accounts, challenges, quests, inventory and ownership-aware application controls.
A responsive gamified fitness application built with Express, MySQL and a vanilla JavaScript interface. It connects user accounts, challenges and game progression with explicit ownership checks and repeatable application tests.
Inside this build
- Built registration, login, profiles, leaderboards, challenges, reviews, pets, inventory, battles, quests and achievements.
- Implemented an Express 5 application for Node.js 22+, backed by MySQL 8.4, JWT authentication and Zod validation.
- Enforced ownership using the authenticated JWT principal instead of trusting client-supplied user identifiers.
- Added password hashing, security headers, request limits, parameterised queries and safe error responses.
- Rendered user content with textContent and separated database migrations and test resets from the application runtime.
- Documented six API, three security and six browser checks; these isolated checks do not establish production reliability.












