A comprehensive bug tracking system built with Rust and the Actix Web framework. This application provides enterprise-grade bug reporting, assignment, and management capabilities across multiple projects with role-based access control and JWT authentication.
Development Team:
- Jun Wei
- Qi Xun
- Andy
- Tze Kai
- Overview
- Features
- Technology Stack
- Getting Started
- API Documentation
- Authentication
- Usage Examples
- Project Structure
- Security Considerations
- License
This web application is a production-ready bug tracking system designed for development teams requiring efficient defect management workflows. The system provides comprehensive functionality for bug lifecycle management, including:
- Defect Reporting and Tracking: Create and monitor software bugs with detailed metadata
- Assignment Management: Allocate bugs to developers with tracking capabilities
- Project Organization: Manage multiple projects with distinct bug repositories
- Access Control: Role-based authentication system supporting Admin and Developer roles
- Status Management: Update and track bug resolution progress
Built on modern Rust architecture, the application leverages SQLite for reliable data persistence and includes sample data for rapid deployment and testing scenarios.
- Create: Report new bugs with comprehensive details including title, description, severity classification, and project association
- Retrieve: Query all bugs or fetch specific bugs by unique identifier
- Update: Modify bug attributes including status, assignment, and priority
- Delete: Remove resolved or invalid bugs from the system
- Assignment Interface: Web-based form for assigning bugs to development team members
- Authentication: Secure JWT token-based authentication system
- Password Security: Bcrypt hashing with configurable salt for credential protection
- Access Control: Role-based permissions with Admin and Developer privilege levels
- User Registration: Create new developer accounts
- Project Repository: Centralized view of all active projects and their associated bugs
- Project Creation: Administrative capability to instantiate new project workspaces
- Project Association: Link bug reports to specific project contexts
- JWT-based authentication middleware for stateless session management
- Bcrypt password hashing with salt for credential security
- Role-based endpoint protection enforcing privilege separation
- Database-level foreign key constraints ensuring referential integrity
Core Framework:
- Actix Web 4 - High-performance asynchronous web framework built on Tokio
- Tokio - Production-grade asynchronous runtime for Rust
Data Layer:
Security & Authentication:
- jsonwebtoken - JWT token generation and validation
- bcrypt - Adaptive password hashing function
Presentation Layer:
- Tera - Template engine for server-side HTML rendering
- Serde - Serialization framework for JSON/form data handling
Ensure the following software is installed on your development environment:
- Rust (version 1.70 or later) - Installation Guide
- SQLite3 - Generally pre-installed on Unix-based systems; Windows users may need to install separately
- Git - For repository cloning
1. Clone the Repository
git clone https://github.com/Yipjunwei/BugTrackingWebApp.git
cd BugTrackingWebApp2. Build the Project
cargo build --release3. Configure Environment Variables
Create a .env file in the project root directory:
DATABASE_URL=sqlite://bugtrack.db1. Initialize the Database Schema
sqlite3 bugtrack.db < schema.sql2. Load Sample Data (Optional - Recommended for Development/Testing)
sqlite3 bugtrack.db < seed_data.sqlThe seed data includes:
- 3 developer accounts (1 admin, 2 standard developers)
- 3 sample bug reports with varying severity classifications
- Pre-configured bug-to-developer assignments
3. Launch the Application
cargo run --releaseThe server will be accessible at http://127.0.0.1:8080
| Method | Endpoint | Description | Auth Required |
|---|---|---|---|
| GET | /login |
Display login form | No |
| POST | /login |
Authenticate user and receive JWT token | No |
| GET | /enroll |
Display registration form | No |
| POST | /enroll |
Create new developer account | No |
| Method | Endpoint | Description | Auth Required |
|---|---|---|---|
| POST | /bugs/new |
Create a new bug | Yes |
| GET | /bugs |
Get all bugs | Yes |
| GET | /bugs/get/{id} |
Get specific bug by ID | Yes |
| PATCH | /bugs/update/{id} |
Update bug details | Yes |
| DELETE | /bugs/delete/{id} |
Delete a bug | Yes |
| GET | /bugs/assigned |
Get bugs assigned to authenticated user | Yes |
| GET | /bugs/assign |
Display bug assignment form | Yes |
| POST | /bugs/assign |
Process bug assignment | Yes |
| Method | Endpoint | Description | Auth Required |
|---|---|---|---|
| GET | /projects |
Get all projects | Yes |
| POST | /projects |
Create new project (Admin only) | Yes (Admin) |
The application implements JWT (JSON Web Tokens) for stateless authentication. Upon successful login, clients receive a token that must be included in the Authorization header for all protected endpoints.
The following credentials are available when using the provided seed data:
Administrative Account:
- Username:
admin - Password:
password
Developer Accounts:
- Username:
alice/ Password:alice123 - Username:
bob/ Password:bob123
Unix/Linux/macOS (using curl):
# Administrative login
TOKEN=$(curl -X POST http://127.0.0.1:8080/login \
-H "Content-Type: application/json" \
-d '{
"username": "admin",
"password": "password"
}' | jq -r '.token')
# Developer login
TOKEN=$(curl -X POST http://127.0.0.1:8080/login \
-H "Content-Type: application/json" \
-d '{
"username": "alice",
"password": "alice123"
}' | jq -r '.token')Windows (using PowerShell):
# Administrative login
$response = Invoke-RestMethod -Uri "http://127.0.0.1:8080/login" `
-Method POST `
-ContentType "application/json" `
-Body '{"username":"admin","password":"password"}'
$TOKEN = $response.token
# Developer login
$response = Invoke-RestMethod -Uri "http://127.0.0.1:8080/login" `
-Method POST `
-ContentType "application/json" `
-Body '{"username":"alice","password":"alice123"}'
$TOKEN = $response.tokencurl -X POST http://127.0.0.1:8080/bugs/new \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"title": "Database Connection Timeout",
"description": "Application fails to connect to database after 30 seconds",
"severity": "Critical",
"project_id": 1
}'curl -X GET http://127.0.0.1:8080/projects \
-H "Authorization: Bearer $TOKEN"curl -X POST http://127.0.0.1:8080/projects \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"name": "Project Apollo"}'curl -X GET http://127.0.0.1:8080/bugs/assigned \
-H "Authorization: Bearer $TOKEN"curl -X PATCH http://127.0.0.1:8080/bugs/update/bug1 \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"title": "Updated Bug Title",
"severity": "High"
}'Navigate to http://127.0.0.1:8080/bugs/assign in a web browser after authentication to access the assignment interface.
BugTrackingWebApp/
├── src/
│ ├── main.rs # Application entry point and server configuration
│ ├── auth.rs # JWT authentication and middleware
│ ├── db.rs # Database initialization and connection pooling
│ ├── handlers.rs # HTTP request handlers and route logic
│ └── models.rs # Data models and structures
├── templates/
│ ├── index.html # Home page template
│ ├── login.html # Login form template
│ ├── create_account.html # Registration form template
│ └── bug_assignment.html # Bug assignment form template
├── schema.sql # Database schema definition
├── seed_data.sql # Sample data for testing
├── Cargo.toml # Project dependencies and metadata
├── .env # Environment variables
└── README.md # This file
The .env file should contain:
DATABASE_URL=sqlite://bugtrack.dbCore dependencies are defined in Cargo.toml:
- actix-web (v4) - Web framework
- sqlx (v0.7) - Database driver with SQLite, Tokio runtime, and compile-time query checking
- jsonwebtoken (v9) - JWT authentication
- bcrypt (v0.15) - Password hashing
- tera (v1.19) - Template engine
- serde (v1.0) - Serialization framework with derive macros
The application uses four main tables:
- developers - Stores developer information and credentials
- roles - Manages admin/developer role assignments
- bugs - Contains bug reports and details
- assignments - Links bugs to assigned developers
See schema.sql for the complete schema definition.
The application implements multiple security layers:
- Password Security: All passwords are hashed using bcrypt with a configurable salt (default:
bugtrack2025) - Authentication: JWT tokens required for all protected endpoints with expiration handling
- Authorization: Role-based access control enforces privilege separation between Admin and Developer roles
- Input Validation: Parameterized SQL queries via SQLx prevent injection attacks
- Data Integrity: Database-level foreign key constraints ensure referential integrity
Note: For production deployment, ensure to:
- Change the default bcrypt salt
- Use environment-specific secrets for JWT signing
- Enable HTTPS/TLS for encrypted communication
- Implement rate limiting and additional security headers
This project is developed as part of an academic assignment.
Technology Stack: Rust | Actix Web | SQLite | JWT | Bcrypt