Architecture decisions, OAuth integration, and the file upload pipeline — a deep technical breakdown of my most ambitious project to date.

WorkFlow started as a simple Todo app. It ended up as a full-featured task management system with user authentication, role-based access, file attachments, and real-time updates.

The architecture follows a layered pattern: Controller → Service → Repository, with DTOs separating the API contract from the persistence model. JWT tokens handle stateless authentication, and Spring Security's filter chain provides method-level authorization.

One challenge was file uploads. Multipart handling in Spring is straightforward, but storing files efficiently required a strategy: small files go to the database as BLOBs, large files stream directly to the filesystem with metadata in PostgreSQL. A background cleanup job deletes orphaned uploads.

For the frontend I used Thymeleaf templates with HTMX for interactivity — no heavy JS framework needed. The result is a snappy, server-rendered app with minimal client-side complexity.

Key takeaway: start simple, refactor relentlessly. The first version of WorkFlow was 200 lines of spaghetti. The current version is modular, tested, and deployable with a single Docker Compose file.