An end-to-end employment screening platform built with .NET 10 and Angular 20. Features include candidate screening, document verification, OCR processing, GDPR compliance, and comprehensive reporting dashboards.
- Backend: .NET 10, ASP.NET Core Web API
- Frontend: Angular 20, TypeScript, SCSS
- Database: SQL Server (Azure SQL)
- Authentication: JWT with refresh tokens
- Infrastructure: Azure App Service, Azure Blob Storage
- CI/CD: GitHub Actions, Docker
validata/
├── src/
│ ├── Validata.Api/ # REST API project
│ │ ├── Controllers/ # API controllers (Auth, Screenings, Documents, GDPR, Reports, Audit)
│ │ ├── HealthChecks/ # Health check endpoints
│ │ └── Program.cs
│ │
│ ├── Validata.Core/ # Domain layer
│ │ ├── Entities/ # Domain entities (User, Candidate, ScreeningRequest, Document, etc.)
│ │ ├── Enums/ # Enumerations (UserRole, ScreeningStatus, DocumentType, etc.)
│ │ └── Interfaces/ # Repository & service interfaces
│ │
│ ├── Validata.Application/ # Application layer
│ │ └── DTOs/ # Data transfer objects for all entities
│ │
│ ├── Validata.Infrastructure/ # Infrastructure layer
│ │ ├── Data/ # DbContext & repositories
│ │ ├── Identity/ # Auth services (JWT, Password hashing)
│ │ └── Services/ # Business services (OCR, Workflow, Reporting, GDPR)
│ │
│ ├── Validata.Integration/ # External integrations
│ │ └── Placeholder for third-party APIs
│ │
│ ├── Validata.Worker/ # Background jobs
│ │
│ └── Validata.Web/ # Angular 20 frontend
│ ├── src/
│ │ ├── app/
│ │ │ ├── core/ # Core services, guards, interceptors
│ │ │ ├── features/ # Feature modules (auth, dashboard, documents, gdpr, reports, audit)
│ │ │ └── shared/ # Shared components
│ │ └── environments/
│ └── angular.json
│
├── tests/
│ └── Validata.Tests/ # Unit tests (xUnit)
│
├── .github/
│ └── workflows/
│ └── ci-cd.yml # CI/CD pipeline
│
├── TECHNICAL_SPECIFICATIONS.md
├── DEVELOPMENT_PLAN.md
├── API_SPECIFICATION.md
├── INFRASTRUCTURE.md
└── README.md
- JWT authentication with refresh tokens
- Role-based access control (Admin, HR Manager, HR Staff, Verifier, Compliance Officer)
- Candidate and screening request management
- Document upload and storage
- Azure Blob Storage integration
- OCR processing with Azure Document Intelligence
- Document validation and verification
- Screening workflow engine with state machine
- SLA monitoring and notifications
- Multiple verification types (Identity, Criminal Record, Education, Employment, Tax, Reference)
- GDPR self-service portal (data export, deletion, rectification, restrict processing)
- Consent management
- Comprehensive audit logging
- Real-time KPI dashboard
- Screening trends analysis
- SLA compliance reports
- CSV export functionality
- .NET 10 SDK
- Node.js 20.19+, 22.12+, or 24 (CI runs 24; the frontend Docker image uses 22)
- SQL Server (or Azure SQL)
- Azure Storage Account (for blob storage)
# Restore dependencies
dotnet restore Validata.slnx
# Build
dotnet build Validata.slnx
# Run migrations (when database is available)
dotnet ef migrations add InitialCreate --project src/Validata.Infrastructure
# Run API
cd src/Validata.Api
dotnet runcd src/Validata.Web
# Install dependencies
npm install
# Run development server
ng serve{
"ConnectionStrings": {
"DefaultConnection": "Server=localhost;Database=ValidataDb;Trusted_Connection=True;TrustServerCertificate=True;"
},
"Jwt": {
"Secret": "your-secure-secret-key-minimum-32-characters",
"Issuer": "Validata",
"Audience": "ValidataUsers",
"AccessTokenExpiryMinutes": 15,
"RefreshTokenExpiryDays": 7
},
"AzureStorage": {
"ConnectionString": "DefaultEndpointsProtocol=https;AccountName=youraccount;AccountKey=yourkey;EndpointSuffix=core.windows.net",
"ContainerName": "documents"
},
"DocumentIntelligence": {
"Endpoint": "https://your-resource.cognitiveservices.azure.com/",
"ApiKey": "your-api-key"
}
}export const environment = {
production: false,
apiUrl: 'http://localhost:5000/api/v1'
};In development mode, the database is automatically seeded with test accounts. All accounts use the password Password123!.
| Role | Organization | |
|---|---|---|
| admin@validata.com | Admin | — |
| hr.manager@acme.com | HR Manager | Acme Corporation |
| hr.staff@acme.com | HR Staff | Acme Corporation |
| candidate@example.com | Candidate | — |
| verifier@validata.com | Verifier | — |
| compliance@validata.com | Compliance Officer | — |
Login via POST /api/v1/auth/login with { "email": "...", "password": "Password123!" }.
POST /api/v1/auth/login- User loginPOST /api/v1/auth/register- Register new userPOST /api/v1/auth/refresh- Refresh access token
GET /api/v1/screenings- List screenings (with filters)POST /api/v1/screenings- Create screeningGET /api/v1/screenings/{id}- Get screening detailsPUT /api/v1/screenings/{id}/status- Update statusPOST /api/v1/screenings/{id}/steps- Add verification step
GET /api/v1/documents- List documentsPOST /api/v1/documents/upload- Upload documentGET /api/v1/documents/{id}- Get document detailsPOST /api/v1/documents/{id}/verify- Verify document
POST /api/v1/gdpr/requests- Create GDPR requestGET /api/v1/gdpr/requests/{id}- Get request statusGET /api/v1/gdpr/export/{candidateId}- Export candidate dataDELETE /api/v1/gdpr/candidates/{candidateId}- Delete candidate data
GET /api/v1/reports/kpi- Get KPI summaryGET /api/v1/reports/dashboard- Get dashboard statsGET /api/v1/reports/trends- Get screening trendsGET /api/v1/reports/sla- Get SLA compliance reportGET /api/v1/reports/generate- Generate report export
GET /api/v1/audit- Get audit logsGET /api/v1/audit/user/{userId}- Get user audit logs
GET /health- Overall health checkGET /health/ready- Readiness checkGET /health/live- Liveness check
# Run all tests
dotnet test
# Run with coverage
dotnet test --collect:"XPlat Code Coverage"- Create Azure App Service (.NET 10)
- Configure application settings
- Set up Azure SQL Database
- Configure Azure Storage account
- Deploy via GitHub Actions
# Build API image
docker build -t validata-api -f src/Validata.Api/Dockerfile .
# Build Frontend image
docker build -t validata-web -f src/Validata.Web/Dockerfile .
# Run containers
docker-compose up -d- Passwords hashed using PBKDF2 with SHA256 (100,000 iterations)
- JWT tokens with short expiry (15 minutes)
- Refresh tokens for session management
- Input sanitization on all user inputs
- HTTPS enforced in production
- Rate limiting recommended for production
MIT