Security Features
Authentication
File Transfer Pavan authenticates users through Supabase Auth with email and password. Session state is managed globally by theAuthContext React context. Protected routes, including the Dashboard, Admin panel, and Profile pages, are wrapped with the AuthGuard component.
If a user is not authenticated when visiting a protected route, they are redirected to the sign-in page. Once authenticated, the route renders.
Admin Access Control
The admin panel (AdminDashboard.tsx, approximately 130 KB) is reserved for users with elevated privileges. Admins can perform the following actions:
- User management: view, edit, ban, or delete user accounts
- File moderation: review uploaded files, quarantine suspicious items, and delete violations
- Audit log review: inspect entries from the
audit_logstable for forensic review - Bulk notifications: send announcements or alerts to all users or filtered subsets
Database Schema
The following abbreviated schema defines the core tables that enforce access control and audit behavior: uploaded_files
file_collections
download_history
audit_logs