// the find
arsh342/careercompass
A next-generation AI-powered career platform transforming how employers and job seekers connect
A Next.js 15 and TypeScript app with two sides: job seekers get resume, cover letter, interview prep and salary tools, and employers get candidate ranking, a kanban pipeline and posting help. The AI layer is Genkit flows calling Gemini, with Firebase for auth and data, Stripe for payments and Cloudinary for uploads. It is a full product codebase rather than a library, so it is most useful to someone studying a Genkit app or forking a hiring tool.
- Each AI flow sits in its own file under src/ai/flows with a shared types.ts and a single genkit.ts config, which keeps prompts and schemas easy to find and diff across 17 flows.
- The tree has crypto.ts, key-storage.ts and an EncryptionContext, so chat encryption was designed in rather than added later. I have not read the key handling, so that is a reason to check it, not a claim that it is sound.
- Firestore rules and indexes are checked in (firestore.rules, firestore.indexes.json), and docs/plans has a security hardening design doc. Rules in the repo can be reviewed and reproduced, which many projects of this kind skip.
- Stripe has both a webhook route and a checkout verify route, which is the right pair, since payment state should come from server-side events and not only from the success page.
- No test command is listed in the README, and the visible tree has no test files or test config (the tree is truncated, so this could be incomplete). For an app that calls paid models and takes payments, the flows and access rules have nothing automated guarding them.
- Parts of the README are marketing copy: 'Lighthouse 95+', 'Core Web Vitals: Optimized' and 'Bundle Size: Minimized' are asserted with no numbers, method or date. The feature table lists items such as Team Collaboration and Bulk Outreach that the README does not show working.
- The README describes both Vercel and Firebase App Hosting deployments (apphosting.yaml is present) and does not say which one is live or which one the Stripe and Firebase config targets, so a new reader has to guess.
- A '.modified' file is committed at the repo root, which looks like a stray artifact that should be removed or ignored.