A RESTful Node.js + Express API for managing event ticket bookings, built with MongoDB and tested using Postman & Thunder Client.
- User registration and login (JWT-based)
- Role-based access control (user/admin)
- Create, update, and delete events (admin only)
- Book tickets with seat availability check
- View user bookings
- QR code generation & validation
- Email confirmation on booking (Nodemailer)
- Admin dashboard: shows all events + who booked each
- Smart 404 responses (HTML vs JSON)
- Backend: Node.js + Express
- Database: MongoDB Atlas + Mongoose
- Auth: JSON Web Token (JWT)
- Email: Nodemailer (Gmail App Password)
- QR Code:
qrcodenpm package - Testing: Postman & Thunder Client
| Package | Description |
|---|---|
express |
Web framework for routing and middleware |
mongoose |
MongoDB object modeling and queries |
dotenv |
Loads env variables from .env file |
bcryptjs |
Password hashing and comparison |
jsonwebtoken |
Signing and verifying JWT tokens |
nodemailer |
Sending email confirmations |
qrcode |
Generates QR codes from booking data |
morgan |
Logs HTTP requests to console |
cors |
Enables CORS for frontend integration |
nodemon |
Dev-only tool for auto-restarting server |
Install them with:
npm install express mongoose dotenv bcryptjs jsonwebtoken nodemailer qrcode morgan cors
npm install --save-dev nodemon
.
├── controllers/ # Logic for each route
├── models/ # Mongoose schemas: User, Event, Booking
├── routes/ # Route definitions (auth, events, bookings)
├── middleware/ # JWT auth, role check, 404, error handling
├── utils/ # JWT generation, email helper
├── public/ # Static index.html welcome page
├── server.js # Main Express app
├── .env.example # Sample env file (not committed)
-
Clone this repo:
git clone https://github.com/soksreng/event-ticketing-api.git cd event-ticketing-api -
Install dependencies:
npm install -
Create a
.envfile and fill in your values:PORT=5000 MONGO_URI=your_mongodb_uri JWT_SECRET=your_secret EMAIL_USER=your_gmail@gmail.com EMAIL_PASS=your_gmail_app_password -
Start the server:
npm run dev -
Visit:
http://localhost:5000/ // Welcome page http://localhost:5000/api/events // Event API
POST /api/auth/register— Register a new userPOST /api/auth/login— Login and receive JWT token
GET /api/events— Get all eventsGET /api/events/:id— Get a single eventGET /api/events?category=— Filter by categoryGET /api/events?date=YYYY-MM-DD— Filter by datePOST /api/events— Create event (admin only)PUT /api/events/:id— Update event (admin only)DELETE /api/events/:id— Delete event & related bookings (admin only)
POST /api/bookings— Book tickets (user only)GET /api/bookings— View all user bookingsGET /api/bookings/:id— Get a specific booking (user only)GET /api/bookings/validate/:qr— Validate QR code
GET /api/admin/dashboard— Get all events + users who booked each
POST /api/auth/register
{
"name": "Jack",
"email": "jack@example.com",
"password": "mySecurePassword"
}POST /api/auth/login
{
"email": "jack@example.com",
"password": "mySecurePassword"
}📝 After login, copy the token from the response and use it in the Authorization header for protected routes:
Authorization: Bearer <your_token>
POST /api/events
{
"title": "Tech Conference 2025",
"description": "A 3-day tech expo and networking event",
"category": "Technology",
"venue": "Innovation Hall",
"date": "2025-11-03",
"time": "09:00",
"seatCapacity": 200,
"price": 50
}PUT /api/events/:id
{
"title": "Updated Tech Conference 2025",
"venue": "New Innovation Hub",
"seatCapacity": 220,
"price": 55
}POST /api/bookings
{
"event": "replace_with_valid_event_id",
"quantity": 2
}GET /api/bookings
(No body needed, just include token in header)
Headers:
Authorization: Bearer <your_token>
GET /api/bookings/:id
(Replace :id with your actual booking ID)
Headers:
Authorization: Bearer <your_token>
GET /api/bookings/validate/QR-abcdef1234
(No body or token needed — just use a valid QR code string)
This project was thoroughly tested using:
- ✅ Thunder Client (VS Code extension)
- ✅ Postman (API client)
To test protected routes:
- Login via
/api/auth/login - Copy the returned token
- Add header:
Authorization: Bearer <your_token>
By Sok Sreng CHAN — 2025