Work / 01

Airframe

Flight logging & analysis

2026TypeScriptReactSupabaseOpen project

I wanted a simple way to keep track of the aircraft I’d flown in.

Flight information had started as scattered notes, which worked until it didn’t. Airframe became an excuse to turn that idea into something more useful while learning how a full-stack application actually behaves beyond the interface.

The goal wasn’t to build a large product. It was to understand what happens when a small application has to behave like a real one.

That meant treating authentication, data access, validation, testing, deployment, observability, and recovery as part of the application itself rather than things to worry about later.

Three layers, one application.

The browser handles the interface and user interaction. Next.js handles server-side operations and acts as the secure bridge between the application and Supabase. Supabase provides authentication, PostgreSQL, database functions, and user records.

Database access is protected again at the database layer through Row Level Security, so authorization does not depend solely on application code.

Trust boundaries matter.

Authentication and authorization are deliberately separated. User-scoped access is enforced through Supabase Row Level Security, while privileged operations remain server-side.

Input validation and cross-user authorization tests were added to make those boundaries explicit and verifiable rather than assumed.

Correctness needs more than a happy path.

Unit and integration tests cover application logic, while Playwright tests exercise the application from the browser.

Linting, type checking, testing, and production builds are also run automatically in CI so a change has to pass the same basic checks before reaching the main branch.

Shipping is part of the system.

GitHub Actions verifies changes before merge, while Vercel handles deployment after changes reach the main branch.

Structured JSON logging records important application events, and a health endpoint checks communication with the database.

A system should be reproducible.

Database schema changes are tracked through versioned migrations, making the structure reproducible rather than dependent on manual changes.

Backups are also pushed to private off-site storage. The remaining work is to formalize and repeatedly validate the full restore procedure.

Airframe taught me that the interesting part of a small application is often everything surrounding the feature itself.

Authentication, data boundaries, tests, deployment, logs, backups, and recovery all change how you think about what “finished” actually means.

I’m leaving the project intentionally small. The point was to understand the fundamentals, not to keep adding features indefinitely.