Build status
An honest map of this build: which flows actually persist data, which content is synthetic, and what has not been built.
Email and password accounts stored in the platform database.
admin, faculty and learner roles live in a separate roles table with row-level security. The first member can claim admin; after that only an admin can grant roles.
Read from the database, not hardcoded.
Written per learner and enforced by row-level security.
Learners submit, faculty grade, learners see grades.
Faculty score each rubric criterion and write feedback; learners see the breakdown on the course and My learning pages.
Enrolled learners ask questions; answers are generated only from that course's lessons and cite lesson references. Not professional advice.
Attempts are scored server-side of the browser and stored per learner.
Admin uploads a JSON package, it is validated, previewed, then explicitly approved. Publication writes real courses and records history.
All seeded and sample content is synthetic. No school children's records and no clinical patient data.
Lesson videos point at a public sample clip; transcripts are synthetic placeholders.
MUYIZZI Publishing Command has not been configured to call this LMS. No delivery from it has been received; the shared secret has not been handed over yet.
POST /api/public/publishing-webhook verifies an HMAC-SHA256 signature, a 5-minute timestamp window and a unique delivery id, then runs the same validation and publish logic as manual intake. The secret is server-only.
Next integration step
- Agree the package schema v1 with the publishing side as a versioned contract.
- Add a backend endpoint POST /api/public/hooks/content-package that verifies an HMAC signature against a secret stored only in backend configuration.
- Have that endpoint call the same validation and publish routine the admin screen uses today.
- Keep explicit admin approval as the default; allow auto-publish only for an allow-listed content set.
Standing constraints
- Learner completion is an academic record and never equals professional credentialing or licensure.
- No school children's data and no clinical patient information is stored in this system.
- No secret, signing key or service credential is present in the frontend.