Skip to content
Mehedi Hasan Sarkar
All case studies

Taking over a live salon booking system

Salon booking · TasmaniaIndependent Contractor, 2026 to present

Problem

A multi-branch beauty salon in Tasmania already had a booking system. Another team built this first version. It took bookings, but it had problems that nobody had written down:

  • missing role checks (permission checks) on booking and admin routes
  • email templates missing from production builds
  • cancellations that staff never saw
  • missing branch and service checks
  • stale (out-of-date) prices
  • booking times in the wrong format

The customer site was also slow. On mobile, it loaded 17.2 MB before anyone could book.

Solution

I started with a full audit. I documented 31 defects for the client, covering security, booking logic and delivery. Then I fixed them in order of priority.

Role checks and price calculation moved to the server, so the client application can no longer bypass them. The system reads booking times in the salon's own time zone. It does not matter which server the code runs on.

I rebuilt the customer site. I moved the staff admin into its own application and set up deployment.

The system sends reminders 24 hours and 2 hours before the appointment, by email, SMS or both. A reminder is marked as sent only after a channel (email or SMS) actually delivered it.

To make the site faster, I:

  • subset the icon font, so it includes only the icons the site uses
  • served different media for each screen size (breakpoint)
  • converted images to AVIF, a modern image format with smaller files
  • added immutable cache headers, so browsers do not download the same files again
  • removed unused assets

The trade-offs. Security came first. The audit's first finding was that no admin route checked the user's role. So I added a role check to every admin route group. After that, I kept changes to the client's existing data small. Some old bookings point to a service or combo that was later deleted. These bookings keep their history and show a "Deleted service" label. They do not break the bookings page, and they are not rewritten. Also, booking lists in the staff admin are no longer cached. This is a little slower. In return, staff never confirm a booking and then still see it as pending.

Impact

  • The salon takes 200 to 300 bookings a month through the system.
  • 31 defects documented and fixed in order of priority.
  • Mobile payload cut from 17.2 MB to 1.7 MB.
  • The client application can no longer bypass role checks or prices.
  • Reminders count as sent only when they were delivered.

Related case studies

Have a similar problem?

Tell me what is breaking or what you need built. I will reply with how I would approach it.

Let's talk