Laravel Expert for Enterprise Application
Budget: ₹250,000 – ₹500,000 INR
I am seeking a PHP Laravel expert with extensive experience in application development, particularly for enterprise-grade systems. The core functionalities of the application will include User Authentication, Database Integration with MySQL, and a robust framework to support a large-scale enterprise setup.
Key Requirements:
- User Authentication: Implement secure and scalable user authentication processes to ensure data integrity and confidentiality.
- Database Integration with MySQL: Design and integrate a MySQL database to support the application's data management needs.
- Framework Development: Develop a comprehensive framework specifically catered to the demands and complexities of an enterprise application.
The primary aim of this application is to streamline internal operations within our organization. Therefore, the ideal candidate for this project should have:
- At least 5-10 years of experience in PHP/Laravel development
- Proven track record in handling User Authentication, Database Integration, and framework development.
- Previous experience with enterprise application development would be a significant advantage.
- A professional team of developers to ensure efficient and timely completion of the project.
If you have the skills and experience in these areas and believe you can deliver a high-quality enterprise application, I look forward to reviewing your proposal.
The scope of the framework consist of
1. Authentication, Role Management and Access Control. Forgot password and remember me .
2. Sensitive Information has to be passed using POST method always with encryption. Sensitive data should not be visible at any point of time, strong password policy.
3. Captcha
4. Not to publish the URL in the browser other than domain name.
5. Application should not disclose the software versions or detailed error messages, it should show only custom error page.
6. Exception management and log rotation
5.1 - business exception
5.2 code error
5.3 business logs
5.4 SQL exception
7. Sanitization and validation of input fields (Data type/format/value validation)
8. Taking care of cross site scripting
9. Implementation of csrf token for server side authentication
10. Technique of using the prevention of SQL Injection like query binding or other techniques
11. Proper session management – there should be different session ids before and after the authentication. There should not be multiple concurrent sessions for a user. Idle session timeout implementation.
12. Implementation of security features in Web Services such as use of authentication, encrypted password that only client and server know, or any tokenization method
13. App should whitelist the Access-Control-Allow-Origin. CORS should always be configurable.
14. Code obfuscation
15. DDos Protection - Distributed denial-of-service (DDoS) attacks overload a website with traffic from multiple sources, making it unavailable to legitimate users.
16. Implementation of Caching and CDN
17. Form validation - checking user input to ensure that it is valid and safe to use. Failure to validate user input can result in security vulnerabilities, such as SQL injection, cross-site scripting (XSS), and command injection.
18. Configuration/Look up model ( key value pair)
19. Login through LDAP, Google, or Username or Oauth
20. Multilingual for web page
21. data table with pagination should not bring all data , it should be brought when user clicks on next page or specific page
22. file upload / download should be routed through a controller and files should not be directly visible without login.
23. exception management
business exception
error from code
24. ORM as well as SQL query support with query binding.
25. unit testing
26. logging and log rotation
error logging
business data logging
27. Communication & escalation
Email using template
SMS
Notification
28. Excel and PDF generation based on time /event
29. Import Excel/CSV
30. API authentication (session based and token based)
3rd part API integration
Creation of API to exchange data
31. mobile app secure authentication
32. socket based communication
33. graph and charts
34. GPS tracking
History tracking
Live tracking
35. Common elements
a. Calendar
b. Select and multi select
c. Pagination
d. Data table
e. Validations
f. Form elements
Key Requirements:
- User Authentication: Implement secure and scalable user authentication processes to ensure data integrity and confidentiality.
- Database Integration with MySQL: Design and integrate a MySQL database to support the application's data management needs.
- Framework Development: Develop a comprehensive framework specifically catered to the demands and complexities of an enterprise application.
The primary aim of this application is to streamline internal operations within our organization. Therefore, the ideal candidate for this project should have:
- At least 5-10 years of experience in PHP/Laravel development
- Proven track record in handling User Authentication, Database Integration, and framework development.
- Previous experience with enterprise application development would be a significant advantage.
- A professional team of developers to ensure efficient and timely completion of the project.
If you have the skills and experience in these areas and believe you can deliver a high-quality enterprise application, I look forward to reviewing your proposal.
The scope of the framework consist of
1. Authentication, Role Management and Access Control. Forgot password and remember me .
2. Sensitive Information has to be passed using POST method always with encryption. Sensitive data should not be visible at any point of time, strong password policy.
3. Captcha
4. Not to publish the URL in the browser other than domain name.
5. Application should not disclose the software versions or detailed error messages, it should show only custom error page.
6. Exception management and log rotation
5.1 - business exception
5.2 code error
5.3 business logs
5.4 SQL exception
7. Sanitization and validation of input fields (Data type/format/value validation)
8. Taking care of cross site scripting
9. Implementation of csrf token for server side authentication
10. Technique of using the prevention of SQL Injection like query binding or other techniques
11. Proper session management – there should be different session ids before and after the authentication. There should not be multiple concurrent sessions for a user. Idle session timeout implementation.
12. Implementation of security features in Web Services such as use of authentication, encrypted password that only client and server know, or any tokenization method
13. App should whitelist the Access-Control-Allow-Origin. CORS should always be configurable.
14. Code obfuscation
15. DDos Protection - Distributed denial-of-service (DDoS) attacks overload a website with traffic from multiple sources, making it unavailable to legitimate users.
16. Implementation of Caching and CDN
17. Form validation - checking user input to ensure that it is valid and safe to use. Failure to validate user input can result in security vulnerabilities, such as SQL injection, cross-site scripting (XSS), and command injection.
18. Configuration/Look up model ( key value pair)
19. Login through LDAP, Google, or Username or Oauth
20. Multilingual for web page
21. data table with pagination should not bring all data , it should be brought when user clicks on next page or specific page
22. file upload / download should be routed through a controller and files should not be directly visible without login.
23. exception management
business exception
error from code
24. ORM as well as SQL query support with query binding.
25. unit testing
26. logging and log rotation
error logging
business data logging
27. Communication & escalation
Email using template
SMS
Notification
28. Excel and PDF generation based on time /event
29. Import Excel/CSV
30. API authentication (session based and token based)
3rd part API integration
Creation of API to exchange data
31. mobile app secure authentication
32. socket based communication
33. graph and charts
34. GPS tracking
History tracking
Live tracking
35. Common elements
a. Calendar
b. Select and multi select
c. Pagination
d. Data table
e. Validations
f. Form elements