CareSync is a comprehensive, scalable, and secure healthcare management platform. This repository contains the Backend API services, powering the telemedicine capabilities, AI health assistants, real-time communications, and database management for the entire platform.
- Framework: Node.js with Express.js
- Database: PostgreSQL
- ORM: Prisma (Type-safe database access and migrations)
- Real-Time: Socket.IO (Chat, notifications, WebRTC signaling)
- Security: JWT (JSON Web Tokens),
bcryptjs,helmet,xss - AI Integration: Azure OpenAI (Smart healthcare assistant)
- Telemedicine: Azure Communication Identity (Token generation for video calls)
- File Uploads: Multer (For medical reports, profile pictures, and service images)
- Email Service: Nodemailer (OTP verification, appointment alerts)
- Payment Gateway: PayHere
- Node.js (v18 or higher recommended)
- PostgreSQL database
- npm or yarn
-
Clone the repository and navigate to the backend directory:
cd CareSyncBackend -
Install dependencies:
npm install
-
Set up environment variables: Create a
.envfile in the root directory based on the following template:# Server Config PORT=5000 NODE_ENV=development # JWT Security JWT_SECRET=supersecretjwtkey12345! JWT_EXPIRES_IN=7d # Mailtrap / Nodemailer SMTP_HOST=sandbox.smtp.mailtrap.io SMTP_PORT=2525 SMTP_USER=your_smtp_user SMTP_PASS=your_smtp_password # Prisma URL (PostgreSQL) DATABASE_URL="postgres://user:password@localhost:5432/caresync?sslmode=disable" # Azure OpenAI & Telemedicine ACS_CONNECTION_STRING=your_acs_connection_string AZURE_OPENAI_ENDPOINT=your_openai_endpoint AZURE_OPENAI_KEY=your_openai_key AZURE_OPENAI_API_VERSION=2024-02-15-preview AZURE_OPENAI_EMBEDDING_DEPLOYMENT_NAME=text-embedding-3-small AZURE_OPENAI_CHAT_DEPLOYMENT_NAME=my-chatbot-model # PayHere PAYHERE_MERCHANT_ID=your_merchant_id PAYHERE_SECRET=your_payhere_secret
-
Initialize Prisma and push the schema to your database (or run migrations):
npm run migrate
(Depending on your workflow, you can also use
npx prisma db pushornpx prisma migrate dev) -
Seed the database (if applicable):
npx prisma db seed
- Development Mode (with nodemon auto-reload):
npm run dev
- Production Mode:
The API should now be running on
npm start
http://localhost:5000.
users: Core identity table storing all roles (Patient, Doctor, Admin, Receptionist) and biometric descriptors.doctor_profiles&doctor_schedules: Manages doctor-specific metadata, pricing, and availability constraints.appointments&service_bookings: The central transactional tables tracking all consultations and hospital services (e.g., MRI, X-Ray).medical_reports: Stores metadata and file paths for uploaded patient records.reviews: Links patients, doctors, and appointments for quality assurance.
- Data in Transit: External traffic is forcefully encrypted via HTTPS / TLS.
- Authentication: Stateless JWT authentication prevents session hijacking and CSRF vulnerabilities.
- Data Protection: All user passwords are irreversibly hashed with
bcrypt. API keys are securely loaded from env variables. - Validation:
helmetandxssmodules are utilized to protect against XSS and similar injection attacks. - Rate Limiting:
express-rate-limitprevents brute-force and DDoS attacks on the API.
-
Provision Azure App Service:
- Create a new Web App in the Azure Portal.
- Set the runtime stack to Node.js 18 LTS.
- Configure environment variables in the App Service configuration settings matching the
.envfile.
-
Deploy via Azure CLI or GitHub Actions: You can deploy directly using the Azure CLI:
az webapp up --name caresync-backend --resource-group your-resource-group --runtime "NODE:18-lts"Alternatively, configure Continuous Deployment (CI/CD) via GitHub Actions using the Azure Web App deployment template.
-
Database Migrations: Ensure your PostgreSQL instance is accessible. You can run migrations directly from the Kudu console or using SSH in the App Service:
npm run migrate