Back to Overview
02 / 06
PROJECT 02•algorithms security

Fluxio Engine

Local-First, Zero-Knowledge Visual Workflow DAG Automation Platform

Live Subdomain DemoView on GitHub
Quick Reviewer Credentials

1-Click preset identity configured on Auth Gate. Vault master key derives client-side into volatile RAM via PBKDF2.

User: developer@fluxio.dev (1-Click Owner)Pass: Set any local PIN on first vault unlock

Technologies & Stack

Next.js 16React 19TypeScriptWeb Crypto APIWeb Locks APIDrizzle ORMPostgreSQLTailwind CSS v4
fluxio.parsadevstudio.ir
IDLE
Fluxio Engine

System Overview & Purpose

Client-driven automation platform executing Directed Acyclic Graphs (DAG) with parallel layer scheduling, in-browser AES-GCM 256-bit cryptographic credential vaults, and multi-tab offline synchronization via Web Locks API.

Core Architecture

Framework-agnostic core domain following Clean Architecture. Ephemeral memory decryption buffers purge on vault lock, and sandbox isolation shields against prototype pollution and SSRF.

Performance Benchmarks

AES-GCM 256

Encryption

Zero-knowledge client-side encryption via PBKDF2

Web Locks Mutex

Concurrency

Guarantees single worker execution across multi-tab sessions

Clean Hexagonal

Architecture

Core DAG engine completely decoupled from React / Next.js

Engineering Challenges & Solutions

Real software roadblocks encountered during production and their architectural resolutions.

01.

Dual-Layer Sandbox & Prototype Pollution Hardening

The Problem: Executing dynamic plugin scripts in-browser and server-side risked Prototype Pollution and sandbox escape via Object.prototype traversal.
The Architectural Solution: Engineered a dual sandbox: server-side node:vm script freezing native prototypes (Object, Function, Array), paired with a client-side recursive Proxy blocking constructor and __proto__ access.
Dual-Layer Sandbox & Prototype Pollution Hardening — Source Solutiontypescript
1234567891011121314151617// Hardening isolated context against prototype traversal & pollution
const sanitizationScript = `
  (function() {
    "use strict";
    const preventAccess = {
      get: function() { throw new Error("Property restricted inside sandbox."); },
      set: function() {},
      configurable: false
    };
    Object.defineProperty(Object.prototype, 'constructor', preventAccess);
    delete Object.prototype.__proto__;
    Object.freeze(Object.prototype);
    Object.freeze(Function.prototype);
    Object.freeze(Array.prototype);
  })();
`;
vmModule.runInContext(sanitizationScript, context);
02.

Multi-Tab Offline Synchronization Race Conditions

The Problem: Restoring connection with multiple open tabs triggered simultaneous queue flushes and duplicate database mutations.
The Architectural Solution: Orchestrated distributed locking with the native Web Locks API (navigator.locks), allowing only the active master tab to drain the mutation queue.
Multi-Tab Offline Synchronization Race Conditions — Source Solutiontypescript
123456789// Distributed cross-tab mutation queue lock via Web Locks API
if (typeof navigator !== 'undefined' && navigator.locks) {
  await navigator.locks.request('fluxio_sync_lock', { ifAvailable: true }, async (lock) => {
    if (lock) {
      result = await this.performSync(onProgress);
    }
  });
  return result;
}

Interface & System Screens

High-resolution captures of the live interface and management panels.

Fluxio Engine Screen 1
01
Fluxio Engine Screen 2
02
Fluxio Engine Screen 3
03
Fluxio Engine Screen 4
04
Previous System
The Last Empire
Next System
Vendora Commerce Engine
Back to Overview