JJachAI

The engineering behind JachAI

An assessment should still make sense after it ends.

That requirement shaped the product: the server owns time and scoring, published questions keep their version, and a payment or AI response never becomes official just because a browser says so.

See the assessment journey

One product, clear boundaries

PeopleAcademy · Talent · personal practice
InterfaceSame-origin HTML, CSS & JavaScript
DecisionsJava 21 · Spring Boot services
StateMongoDB · Redis

External AI, email, Google sign-in and payment sandboxes connect at the edges. The core rules stay on the server.

What we use

Small number of moving parts, each with a defined job.

Application
Java 21, Spring Boot, Spring Security and Thymeleaf serve the REST API and public pages together.
Browser
HTML, CSS and JavaScript power the current workspace. A separate React practice pilot is design research, not a second production dashboard.
Data
MongoDB holds accounts, assessments, attempts, audit events, orders and email jobs. Redis coordinates production limits, reservations and cache.
Connections
Google Identity Services, SMTP, configured AI providers, and bKash/SSLCOMMERZ sandbox adapters are optional integrations with explicit checks.
Delivery
Maven tests, frontend journey checks, opt-in MongoDB integration tests and a Dockerfile support repeatable releases.

Problems that changed the design

Each response came from a failure mode we could point to.

Answers can arrive late or twice.

Attempts use a server deadline and stable submission state. Published versions freeze the questions used for scoring; short answers wait for staff review and release.

One person can have several roles.

Personal practice stays outside official workspace scores. Academy and Talent data stays tenant-scoped, and services check membership again on every request.

Networks retry; providers disagree.

Email jobs, quota reservations and payment callbacks use durable identifiers and conditional updates. A checkout redirect never grants a plan; the server validates the sandbox payment independently.

A query can stop the whole app.

A derived MongoDB sum over BigDecimal failed at startup. We replaced it with a deliberate aggregation and kept reconciliation auditable rather than guessing at missing usage.

AI can help without becoming the examiner.

Generated questions remain drafts for approval. The Tutor can explain a released result to a learner or candidate, but cannot grade an active exam or publish official content.

What is proven so far?

Local checks covered Java tests, frontend journeys and all six demo-role sign-ins. They are useful evidence, not a production stamp. Real inbox delivery, final-domain Google login, live AI responses, hosted MongoDB/Redis readiness and completed sandbox payments still need separate verification.

Explore the demo roles