FULL-STACK DEVELOPER – LEGAL PROFESSIONALS CONTACT PLATFORM
Project Description:
Build a contact platform where visitors can search for legal professionals, view profiles, and send inquiries. The legal professionals must be able to update their own selected profile information without a user account.
Existing Tools:
- Domain
- Hostup.se web hosting
- Storage via Hostup.se
- Sitejet / Sitepad
- PHP/MySQL
- Softaculous
- cPanel
Use Hostup.se and free/open-source components where practical.
Technical Requirements:
- PHP/MySQL or equivalent
- Hostup.se
- Open-source code where practical
- Simple architecture
- Responsive design for Android, iOS, and desktop
- Complete source code delivered to the client
Security, GDPR, and Spam Protection:
1. Admin panel protected by appropriate authentication.
2. HTTPS/TLS for all communication.
3. Protection against SQL injection, XSS, CSRF, and unauthorized access, following relevant OWASP guidance.
4. Inquiry data protected against unauthorized access.
5. Spam protection using CAPTCHA, honeypot, rate limiting, or equivalent.
6. GDPR requirements for data minimization, storage limitation, deletion, and security must be supported.
Security Testing:
Before delivery, the application must undergo web-application security testing based on recognized industry practices, preferably relevant OWASP WSTG and/or ASVS requirements.
Testing must cover:
- Authentication and authorization
- Access control
- Session/token security
- SQL injection
- XSS
- CSRF
- Sensitive-data exposure
- Security misconfiguration
- Brute-force/token-guessing resistance
- Unauthorized access to other legal professionals' data
- Unauthorized access to administration functions
A penetration test or equivalent platform security assessment must be completed before final acceptance.
A security-testing report must be provided.
No unresolved critical or high-risk security vulnerabilities may remain at final acceptance.
Functional Requirements:
1. Legal Professionals Database
Fields:
- Name
- Firm
- Region
- City
- Contact information
- Website
- Practice areas
- Hourly rate
- Payment terms
- Languages
- Remote meetings
- Legal expenses insurance
- Legal aid
- Accepting new clients: Yes/No/Limited
- Bio
2. Search and Filtering
Filter by:
- Region
- City
- Practice area
- Languages
- Hourly rate
- Remote meetings
- Legal expenses insurance
- Legal aid
- Accepting new clients
3. Profile Page
Display:
- Name/firm
- Region
- City
- Practice areas
- Hourly rate
- Remote meetings
- Payment terms
- Languages
- Accepting new clients
- Bio
Include a "Send Inquiry" button.
4. Inquiry Form
Collect:
- Name
- Phone
- Message
- Matter type
Options:
- Remote meeting
- Legal expenses insurance
- Legal aid
No visitor login is required.
The inquiry must be sent to the legal professional and stored securely in the database.
5. Legal Professionals' Self-Service
Each legal professional receives a unique, cryptographically random update token.
The update link must allow the legal professional to change:
- Accepting new clients: Yes/No/Limited
- Hourly rate
- Bio
The token must:
- Be unpredictable and sufficiently long
- Not rely on a sequential ID
- Only provide access to that legal professional's own editable data
- Not provide admin access
- Be protected against guessing/brute force
- Be revocable
- Be replaceable with a new token
The developer must describe the token implementation in the offer.
6. Email
When an inquiry is submitted, the legal professional receives:
- Subject: CLIENT INQUIRY
- Inquiry information
- Platform information
- Personal update link
The visitor receives an automatic confirmation email.
7. Administration
The admin panel must allow:
- Add/edit/remove legal professionals
- Publish/unpublish profiles
- Edit practice areas and locations
- Generate/resend update links
- Revoke/replace update links
8. Website
- Website search
- Practice area, region, and city filters
- Responsive design
- User-friendly interface
9. Out of Scope
- Mobile app
- CRM
- Consumer accounts
- Legal professionals' accounts/password login
- Chat
- Payments
- Booking
- Advanced analytics
- AI
- Automatic matching
The secure legal professionals' update link is included.
Testing and Acceptance:
Test:
- Adding/removing legal professionals
- Publishing/unpublishing
- Search/filtering
- Profiles
- Self-service updates
- Availability changes
- Rate changes
- Bio changes
- Token generation/replacement/revocation
- Inquiry submission
- Spam protection
- Email delivery
- Android, iOS, and desktop
Security testing must also verify that update tokens cannot be used to:
- Guess/access another professional
- Modify another professional's data
- Access admin functions
- Access inquiry data
Critical and high-risk vulnerabilities must be resolved and retested before acceptance.
Delivery:
Provide:
- Production-ready website
- Complete source code
- Database and database structure
- Admin panel
- Update-link system
- Installation instructions
- Configuration instructions
- Security-testing report
Payment and Acceptance:
Payment is made after delivery and a two-week acceptance period.
During this period, the client may test functionality, security, and compatibility.
Final acceptance requires:
1. Required functionality delivered
2. Security testing completed
3. No unresolved critical or high-risk vulnerabilities
4. Material defects fixed and retested
Payment will be made through Invozio, a freelance company.
Budget:
Low-budget, cost-effective.
Use existing hosting and free/open-source components where practical.
Application and Quote:
Include:
1. Fixed price excluding VAT
2. Estimated delivery time
3. Technology stack
4. Similar projects
5. Hostup.se compatibility
6. Source-code delivery method
7. External costs
8. Technical solution
9. Testing approach
10. GDPR approach
11. Security measures
12. Spam protection
13. Update-token security
14. Security-testing methodology
15. Confirmation that security testing is included in the price
16. Hostup.se limitations
Application:
Send application and quotation to Zia Zenith: [email protected]