# TREK Server Features: Core Capabilities of the Node.js Travel Planning Backend

> Explore TREK server features including multi-method authentication, real-time collaborative trip management, weather integration, and NestJS migration. Discover core Node.js capabilities.

- Repository: [Maurice/TREK](https://github.com/mauriceboe/TREK)
- Tags: features
- Published: 2026-06-27

---

**The TREK server implements a comprehensive full-stack Node.js backend featuring multi-method authentication (password, OIDC, WebAuthn passkeys, and TOTP MFA), collaborative trip management with real-time WebSocket updates, weather integration, and a strangler-pattern migration to NestJS.**

The TREK server is the core engine behind a collaborative travel-planning application. Located in the `mauriceboe/TREK` repository, this backend architecture combines a legacy Express API with a modern NestJS migration layer to deliver secure user management, dynamic trip orchestration, and domain-specific services ranging from weather forecasting to budget tracking.

## Authentication & Security Architecture

The TREK server provides defense-in-depth authentication through multiple identity verification methods implemented in [`server/src/services/authService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/authService.ts).

### Password-Based & SSO Authentication

**Traditional authentication** uses `loginUser` and `registerUser` functions with bcrypt hashing and constant-time comparison checks to prevent timing attacks. The system includes a dummy hash mitigation strategy for non-existent users.

**OIDC integration** enables single sign-on through configurable environment variables. The `resolveAuthToggles` function determines when OIDC-only mode is active, allowing enterprises to mandate SSO exclusively.

### WebAuthn Passkeys & MFA

**Passkey (WebAuthn) support** provides phishing-resistant authentication via RP-ID discovery, controlled by the `isPasskeyConfigured` toggle.

**Multi-factor authentication (TOTP)** implements full MFA lifecycle management through `setupMfa`, `enableMfa`, `disableMfa`, and `verifyMfaLogin`. The system generates backup codes for account recovery and encrypts TOTP secrets using [`server/src/services/mfaCrypto.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/mfaCrypto.ts).

### Session Management & Demo Mode

**JWT handling** occurs through `generateToken` and `verifyJwtAndLoadUser` middleware, supporting configurable secrets and "remember me" extended expiry. Tokens include password-version claims for instant revocation upon password changes.

**Demo mode** allows instant access via `demoLogin`, returning pre-filled credentials for evaluation purposes without registration friction.

## Trip & Day Management

The trip management system in [`server/src/services/tripService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/tripService.ts) handles complex travel itineraries with automatic day generation and deep-copy capabilities.

### Core CRUD & Day Generation

**Trip lifecycle management** includes create, read, update, delete, archive, and cover-image operations. The `generateDays` function implements complex renumbering logic to preserve place assignments when adjusting start dates, end dates, or explicit `day_count` parameters.

### Collaboration & Export Features

**Member sharing** uses `addMember`, `removeMember`, and `listMembers` to manage trip access via email or username invitations with role-based permissions.

**iCalendar export** generates standards-compliant `.ics` files through `exportICS`, encoding trips, days, assignments, and reservations for external calendar integration.

**Trip duplication** creates deep copies via `copyTripById`, cloning all related data including days, places, assignments, reservations, budget items, packing lists, and notes without manual re-entry.

## Real-Time Collaboration & Notifications

The server maintains synchronous collaboration through WebSocket connections and multi-channel alerting.

**WebSocket gateway** ([`server/src/websocket.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/websocket.ts)) pushes real-time updates to connected clients when trip data changes, new reservations are added, or collaborators make edits.

**In-app collaboration** tools including chat, polls, and notes are managed through [`server/src/services/collabService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/collabService.ts), providing isolated CRUD operations for collaborative artifacts.

**Notification system** ([`server/src/services/notifications.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/notifications.ts) and [`notificationService.ts`](https://github.com/mauriceboe/TREK/blob/main/notificationService.ts)) supports email, webhook, and in-app channels with per-user configuration options.

## Domain-Specific Services

The architecture isolates business logic into focused service modules.

### Weather & Places

**Weather integration** ([`server/src/services/weatherService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/weatherService.ts)) fetches current conditions, forecasts, and climate data with caching layers, hourly breakdowns, and multilingual descriptions via the `getWeather` function.

**Place enrichment** ([`server/src/services/placeEnrichment.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/placeEnrichment.ts)) connects to the Google Places API for autocomplete and detailed place information, with secure API key storage handled by [`server/src/services/apiKeyCrypto.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/apiKeyCrypto.ts).

### Reservations & Logistics

**Reservation management** ([`server/src/services/reservationService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/reservationService.ts)) provides CRUD operations for flights, hotels, train tickets, and restaurant bookings, including endpoint handling for multi-leg transport segments.

### Financial & Inventory Tracking

**Budget service** ([`server/src/services/budgetService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/budgetService.ts)) tracks items, categories, and running totals across currencies.

**Packing service** ([`server/src/services/packingService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/packingService.ts)) manages checklists with item status, bag grouping, and assignment to specific travelers.

## NestJS Migration Architecture

The TREK server implements a **strangler pattern** migration co-hosting legacy Express routes alongside a modern NestJS application under `server/src/nest/`.

**Request routing** ([`server/src/nest/strangler.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/nest/strangler.ts)) dispatches traffic between Express and Nest modules based on static prefixes and dynamic `:param` patterns, allowing incremental migration without downtime.

**Domain modules** follow a consistent layout with Zod schema contracts, services, controllers, and modules for domains like `weather`, `airport`, and `vacay`.

**Idempotency guarantees** are enforced by [`server/src/nest/common/idempotency.interceptor.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/nest/common/idempotency.interceptor.ts), which replays responses for duplicate `X-Idempotency-Key` headers to ensure safe retries.

**Parity testing** validates migrated routes through unit, parity, and E2E tests in `tests/parity/` and `tests/e2e/`, ensuring byte-identical responses between legacy and Nest implementations.

## Background Processing & Scheduling

**Trip reminders** run via [`server/src/scheduler.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/scheduler.ts), executing daily to check `reminder_days` configurations per trip and dispatch notifications through configured channels.

**Demo data management** utilities in [`server/src/demo/demo-seed.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/demo/demo-seed.ts) and [`server/src/demo/demo-reset.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/demo/demo-reset.ts) populate or wipe demonstration databases for testing environments.

## Code Examples

Generate a JWT after successful authentication:

```typescript
import { generateToken } from './services/authService';
const token = generateToken(
  { id: user.id, password_version: user.password_version }, 
  rememberMe
);

```

Fetch a localized weather forecast:

```typescript
import { getWeather } from './services/weatherService';
const forecast = await getWeather('48.8566', '2.3522', null, 'de');

```

Create a trip with automatic day generation:

```typescript
import { createTrip } from './services/tripService';
const { trip, tripId } = createTrip(userId, {
  title: 'Alpine Adventure',
  start_date: '2024-07-01',
  end_date: '2024-07-10',
  currency: 'CHF',
});

```

## Summary

- **Multi-factor authentication** supports passwords, OIDC SSO, WebAuthn passkeys, and TOTP with backup codes, all implemented in [`authService.ts`](https://github.com/mauriceboe/TREK/blob/main/authService.ts).
- **Comprehensive trip management** includes dynamic day generation (`generateDays`), member sharing, iCalendar export (`exportICS`), and deep-copy duplication (`copyTripById`).
- **Real-time collaboration** uses WebSocket gateways for live updates and isolated services for chat, polls, and notifications.
- **Domain services** cover weather forecasting, Google Places integration, reservation tracking, budgeting, and packing lists.
- **Strangler pattern migration** allows gradual transition from Express to NestJS with idempotency interceptors and parity testing.
- **Background scheduling** automates trip reminders and demo data seeding.

## Frequently Asked Questions

### What authentication methods does the TREK server support?

The TREK server supports password-based login with bcrypt hashing, OIDC single sign-on, WebAuthn passkeys for phishing-resistant authentication, and TOTP-based multi-factor authentication with encrypted backup codes. This flexibility allows deployments to choose between traditional credentials or enterprise SSO requirements.

### How does the TREK server handle real-time collaboration?

Real-time features are implemented through a WebSocket gateway in [`server/src/websocket.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/websocket.ts) that pushes updates to connected clients when trip data changes. Collaborative tools including chat, polls, and notes are managed through [`server/src/services/collabService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/collabService.ts), while the notification system supports email, webhook, and in-app channels.

### What is the NestJS migration strategy used in TREK?

The repository uses a strangler pattern to incrementally migrate from Express to NestJS. The [`server/src/nest/strangler.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/nest/strangler.ts) file routes requests between legacy and modern implementations, while domain modules in `server/src/nest/` follow a standardized structure with Zod schemas. An idempotency interceptor ensures safe retries during the transition, and parity tests verify identical responses between old and new implementations.

### How does trip duplication work in TREK?

The `copyTripById` function in [`server/src/services/tripService.ts`](https://github.com/mauriceboe/TREK/blob/main/server/src/services/tripService.ts) creates deep copies of trip data, cloning not just the trip metadata but also all related entities including days, place assignments, reservations, budget items, packing lists, and collaborative notes. This allows users to template previous trips without manual data re-entry.