Investment Plans workspace
Open raw ↗

Project: HAD Digital MVP Skeleton

Architecture

System Architecture Overview

The HAD Digital MVP (Hospitalisation à Domicile Oncology Care Platform) is designed as a zero-dependency, local-first standalone Windows application.

+-------------------------------------------------------------------------+
|                  HAD Digital MVP - Standalone Architecture              |
+-------------------------------------------------------------------------+
| [Client Browser] (Chrome / Edge / Firefox)                              |
|        ^                                                                |
|        | HTTP / REST (127.0.0.1:8080) - HttpOnly Session Cookies       |
|        v                                                                |
| [ThreadingHTTPServer] (Pure Python Stdlib, zero external dependencies)  |
|    ├── Static Asset Handler (serves bundled HTML5 / CSS3 / Vanilla JS)  |
|    ├── REST API Router (19 endpoints: auth, reports, timeline, etc.)   |
|    └── Security Headers (CSP, X-Content-Type-Options, X-Frame-Options)  |
|        │                                                                |
|        ├──> [CTCAE Grading Engine] <── [ctcae_rules.json] (Bundled)     |
|        ├──> [Alert Engine] (Routine / Urgent / Emergency routing)       |
|        ├──> [Audit Logger] (Immutable append-only audit trail)          |
|        └──> [User Store & Auth] (scrypt password hashing + salt)        |
|                 │                                                       |
|                 v                                                       |
|        [Database Manager] (SQLite with WAL mode, foreign keys, thread-local)
|                 │                                                       |
|                 v                                                       |
|        [Persistent Data Storage] (Outside sys._MEIPASS)                 |
|        ├── data/had.db (Users, Patients, Reports, Grades, Timeline)     |
|        └── logs/audit.log                                               |
+-------------------------------------------------------------------------+

Storage Decoupling Architecture

To prevent the PyInstaller _MEIPASS ephemeral data-loss bug:


Feature Inventory

#FeatureDescriptionMilestoneSource
1User Login (/api/login)Authenticates credentials using scrypt; returns ok: true, user object, and sets HAD_SESSION cookieM1ORIGINAL_REQUEST §R2
2User Logout (/api/logout)Clears active session and expires session cookieM1Survey
3Session Check (/api/whoami)Returns active session role/profile or {authenticated: false}M1Survey
4Account LockoutLocks account for 30 minutes after 5 consecutive failed login attemptsM1Survey
5List Patients (/api/patients)Retrieves patient roster filtered by caller roleM1Survey
6Patient Detail (/api/patients/{id})Retrieves patient demographics, active regimen, recent grades, alertsM1Survey
7Patient Self-Report (/api/reports)Ingests toxicity symptoms, auto-grades via CTCAE, logs audit & timeline, routes alertsM1ORIGINAL_REQUEST §R2
8Clinician Observation EntryClinicians submit home-visit clinical findings and vital signsM1Survey
9List Reports (/api/reports)Returns historical toxicity reports for a specified patientM1ORIGINAL_REQUEST §R2
10CTCAE Automated Grading EngineEvaluates symptom inputs against CTCAE v5.0 thresholds; assigns grades 1-5M1Survey
11List Grades (/api/grades)Retrieves graded toxicity assessments for a patientM1Survey
12List Symptoms (/api/symptoms)Enumerates configured CTCAE symptom terms and categoriesM1Survey
13Confirm Provisional GradeOncologist confirms or overrides provisional automated gradeM1Survey
14Tiered Alert RoutingRoutes grades to Routine (timeline), Urgent (HAD nurse), or Emergency (oncologist)M1Survey
15List Alerts (/api/alerts)Retrieves alerts filtered by patient, status, or roleM1Survey
16Acknowledge Alert (/api/alerts/{id}/ack)Clinician marks an alert acknowledged with timestampM1Survey
17Care Coordination Timeline (/api/timeline)Unified chronological stream of reports, grades, alerts, and care notesM1ORIGINAL_REQUEST §R2
18Treatment Plan View (/api/treatment-plan)Displays protocol name, regimen, cycles, drugs, supportive careM1Survey
19Send Message (/api/messages)Secure direct or role-directed care team messagingM1Survey
20List Messages (/api/messages)Lists messages where caller is sender, recipient, or role memberM1Survey
21Toxicity Summary Export (/api/export/summary)Compiles structured JSON summary with patient metadata and grade historyM1Survey
22Patient Guidance (/api/guidance)Delivers actionable French guidance per symptom and gradeM1Survey
23Immutable Audit Log (/api/audit-log)Records timestamped actions, resources, IPs; admin accessM1Survey
24Pluggable AI Assistant (/api/chat)Natural language assistant supporting stub (offline) and glm (online)M1Survey
25Demo Data Auto-SeederSeeds realistic patients, treatment plans, users across all 8 roles on first runM1Survey
26Persistent SQLite Storage EngineDecouples read-only bundle from persistent writable SQLite DB with WAL modeM1ORIGINAL_REQUEST §R1
27Responsive UI Shell & NavigationMobile-first SPA shell, vanilla JS router, role-customized nav bar, modal overlaysM2ORIGINAL_REQUEST §R3
28UI Login & Auth ViewLogin form handling ok: true, error display, demo credential helper buttonsM2ORIGINAL_REQUEST §R2, §R3
29Patient Toxicity Reporting FormInteractive symptom questionnaire supporting multiple symptom domains and submissionM2ORIGINAL_REQUEST §R2, §R3
30Clinician Care Timeline ViewInteractive chronological stream displaying reports, grades, alerts, and filtersM2ORIGINAL_REQUEST §R2, §R3
31PyInstaller Single-File PackagingSingle-file Windows .exe bundle embedding Python runtime, server, and static assetsM3ORIGINAL_REQUEST §R1
32Automated Build Script (04_Build/build_exe.py)Automation script executing PyInstaller build, verifying zero external runtime dependenciesM3ORIGINAL_REQUEST §Criteria
33Programmatic Verification Script (05_Test/verify_mvp.py)CLI verification harness testing launch, health ping, auth, submission, persistence, and timelineM4ORIGINAL_REQUEST §Criteria
34E2E Test Suite Tiers 1-4Opaque-box test suite covering feature coverage, boundary values, pairwise, and clinical workflowsTest TrackTest Methodology
35Tier 5 Adversarial HardeningWhite-box stress, concurrency, brute-force lockout, and security hardening testsM4Quality Standard

Milestones

#NameScopeDependenciesStatus
Test TrackE2E Testing Suite TrackDesign and implement opaque-box E2E test suite (Tiers 1-4) in 05_Test/ and publish TEST_READY.mdnoneDONE
M1Core Server & Storage EngineResolve _MEIPASS data-loss trap, fix API contract inconsistencies (login ok: true, report payload flexibility), ensure persistent SQLite WAL database, auth, and REST endpointsnoneDONE
M2Responsive Local FrontendFix UI login handler, update demo credentials display, verify responsive toxicity questionnaire and care timeline view in MVP/static/M1DONE
M3Packaging & Build AutomationImplement 04_Build/build_exe.py and HAD Digital.spec for single-file Windows .exe packaging with bloat exclusionsM1, M2DONE
M4E2E Verification & HardeningPhase 1: Verify 100% pass on E2E test suite (Tiers 1-4) against both Python server and standalone .exe using 05_Test/verify_mvp.py. Phase 2: Tier 5 Adversarial Coverage HardeningTest Track, M3DONE (Gate PASS)

Interface Contracts

Client Frontend ↔ Backend REST API (/api)

Server Runtime ↔ Storage Engine


Code Layout

c:\AI Projects\Kais Project\
├── 00_Governance/                 # Governance & Project Status
├── 01_System/                     # System specifications & architecture docs
├── 02_Requirements/               # Functional requirements & CTCAE rules
├── 03_Architecture/               # Architecture documents & API contracts
├── 04_Build/                      # Automated build scripts & PyInstaller spec
│   ├── build_exe.py              # Automated build script packaging single-file .exe
│   └── HAD Digital.spec          # Single-file PyInstaller specification
├── 05_Test/                       # Comprehensive E2E test suite & verification harness
│   ├── verify_mvp.py             # Standalone programmatic verification script
│   ├── test_e2e_tier1.py         # Tier 1: Feature coverage tests
│   ├── test_e2e_tier2.py         # Tier 2: Boundary & corner cases
│   ├── test_e2e_tier3.py         # Tier 3: Cross-feature combination tests
│   ├── test_e2e_tier4.py         # Tier 4: Clinical workflow scenarios
│   └── test_e2e_tier5_adversarial.py # Tier 5: Adversarial hardening & stress tests
├── MVP/                           # Application source code
│   ├── app.py                    # ThreadingHTTPServer & REST API routing
│   ├── config_manager.py         # Storage path decoupling & configuration
│   ├── database.py               # SQLite WAL thread-local database manager
│   ├── user_store.py             # Scrypt authentication & session management
│   ├── ctcae_engine.py           # CTCAE v5.0 rule evaluation
│   ├── alert_engine.py           # Triage & alert routing
│   ├── audit_logger.py           # Immutable audit logging
│   ├── seed_demo.py              # Demo patient & user data seeder
│   ├── static/                   # Frontend assets
│   │   ├── index.html            # Single Page Application HTML shell
│   │   ├── app.css               # Responsive design & component styling
│   │   └── app.js                # Frontend routing, auth, form & timeline logic
│   ├── data/                     # ctcae_rules.json
│   └── guidance/                 # guidance.json
├── dist/                          # Output directory for compiled standalone .exe
│   └── HAD Digital.exe           # Single-file standalone Windows executable (9.78 MB)
└── PROJECT.md                     # Living project scope & architecture index