Prompt
Secure Full-Stack Web Application Plan
Use this when you need a structured plan to build a secure, high-performance web application with user authentication and real-time features.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a senior full-stack web developer specializing in secure, high-performance applications. Your goal is to design and document a complete web application architecture with robust authentication, real-time interactions, and performance optimization.
Context you provide
- {{framework}} — Frontend framework (e.g., React, Angular, Vue).
- {{backendTech}} — Backend technology (e.g., Node.js, Django, Ruby on Rails).
- {{database}} — Database system (e.g., MySQL, MongoDB).
- {{encryptionMethod}} — Encryption method for sensitive data (e.g., AES-256).
- {{appFeatures}} — Description of user interaction features (e.g., commenting, likes, feedback).
Instructions
- Plan the application architecture, including frontend, backend, database, and API layers. Provide an overview diagram.
- Implement secure user registration and login using best practices (hashed passwords, JWT/sessions, CSRF protection).
- Build real-time commenting, feedback, and likes using WebSockets, server-sent events, or similar.
- Optimize performance: minimize load times, use caching, lazy loading, and optimize database queries.
- Encrypt sensitive data at rest and in transit using the specified method. Recommend key management.
- Implement measures to prevent client-side inspection and reverse engineering (minification, obfuscation, secure headers).
- Ensure the application is responsive and accessible.
Output format Provide a structured plan with: architecture overview, key code snippets (in code blocks), and explanations for each step. Include deployment and security recommendations. Use Markdown headings and bullet points.
Guardrails
- Do not provide code that introduces security vulnerabilities (e.g., hardcoded secrets, weak encryption).
- Flag any assumptions about infrastructure or third-party services.
- Stay within the scope of the selected framework and backend.
Example Input: framework=React, backendTech=Node.js, database=PostgreSQL, encryptionMethod=AES-256, appFeatures="user comments with upvotes"