Express + MongoDB + Socket.IO backend for a proctored exam platform (soft proctoring: tab/focus tracking, screenshot requests, event logging).
- Install deps:
npm install .envrequired:MONGO_URI,JWT_SECRET; optionalPORT(default 5000),JWT_EXPIRES_IN(default 7d)- Run:
node server.js - Health:
GET /→API running
- Roles: student, teacher, proctor, admin
- Key endpoints (send
Authorization: Bearer <token>when protected):POST /api/auth/registerStudent–{ name, email, password }POST /api/auth/registerTeacher– admin only –{ name, email, password }POST /api/auth/login–{ email, password }→{ token }POST /api/auth/setUserRole– admin only –{ userId, role }
GET /api/users/teacher/getUserData– teacherGET /api/users/student/getUserData– studentGET /api/users/proctor/getUserData– proctorGET /api/users/admin/getUserData– adminGET /api/users/getStudentList– admin|teacherGET /api/users/getTeacherList– admin
POST /api/exams/create– teacher|admin –{ title, description?, proctoredBy, startTime, endTime, questions? }GET /api/exams/getAll– teacher|adminGET /api/exams/proctored/:userId– teacher|admin|proctorGET /api/exams/student/:userId– student|teacher|admin|proctor (self-checks for student/proctor enforced)POST /api/exams/startAttempt/:examId– studentGET /api/exams/questions/:examId– studentPOST /api/exams/attempt/:attemptId/submit– student –{ answers: [...] }
GET /api/results/student/:userId– student|teacher|admin|proctor – returns attempts for the student
GET /api/proctoring/events– teacher|admin – query:attemptId?,eventType?,limit?,skip?- Socket events:
user_online,tabSwitch,windowFocusChange,examStarted,examEnded,proctoringAlert,screenshot-upload; server emitsrequest-screenshotand marks attemptsterminatedon tab/focus violations
Create exam (teacher/admin) — includes question payload (note: Exam schema currently ignores questions; persist questions via Question collection if needed):
curl -X POST http://localhost:5000/api/exams/create \
-H "Authorization: Bearer <teacherToken>" \
-H "Content-Type: application/json" \
-d '{
"title":"Midterm",
"description":"Chapters 1-3",
"proctoredBy":"<proctorId>",
"startTime":"2025-01-10T09:00:00Z",
"endTime":"2025-01-10T11:00:00Z",
"questions":[
{
"type":"mcq",
"text":"What is 2 + 2?",
"options":["1","2","3","4"],
"correctAnswer":"4",
"points":2,
"order":1
},
{
"type":"short",
"text":"Name the sorting algorithm used by V8.",
"correctAnswer":"Timsort",
"points":3,
"order":2
}
]
}'Start attempt (student):
curl -X POST http://localhost:5000/api/exams/startAttempt/<examId> \
-H "Authorization: Bearer <studentToken>"Fetch proctor events (teacher/admin):
curl -H "Authorization: Bearer <adminToken>" \
"http://localhost:5000/api/proctoring/events?attemptId=<attemptId>&limit=20"- Screenshots served statically from
/screenshots/<examId>/...; secure in production. - CORS is permissive; tighten for production.
- No automated tests yet; add coverage before deployment.