25 pages
in the single-page app
85
unit tests
6 roles
resolved by permission, not by name
On-prem
IIS + SQL Server, no cloud at runtime
The brief
A hospital tracking its medical supplies on paper
Al-Tal National Hospital ran its medical-supply inventory — materials, receiving, department requests, deliveries — on paper. Nobody could reliably see what was running low, who asked for what, or who signed for a delivery.
HSMS replaces that with a web system that runs entirely inside the hospital’s network: on-premises IIS and SQL Server, with no cloud services or third-party SDKs at runtime.
I joined 88ninety’s summer internship as a frontend engineer on a ten-person team. Other engineers owned the ASP.NET Core backend; I built the React interface hospital staff actually use.

What I built
Requests, deliveries, and stock — in a fully Arabic interface
I worked on the materials catalog, internal department requests, deliveries, and storage locations. The stack is React 19 with strict TypeScript, TanStack Query for server state, and Ant Design, all inside an Arabic RTL shell.
Every list is built for daily use by busy staff: status tabs, urgency levels, date and department filters, progress at a glance, plus export and print for the paperwork that still has to exist.

The hard part
Permissions that change for everyone, instantly
The system ships with six roles, but the frontend never checks a role name. Every screen, menu item, and action checks a permission key, and a role is just a saved bundle of keys.
An admin flips one toggle and everyone holding that role gains or loses the action immediately. Staff move departments, pharmacists join, auditors need temporary access — the hospital’s own admins handle all of it, without a code change.

Why this design mattered
Hard-coding roles into the frontend would have turned every staffing change into a ticket for developers. Resolving permissions at runtime — in routing and menu rendering, not just by hiding buttons — kept the hospital in control of its own access rules.
Stack
The source is private — the repository holds a public README. Happy to walk through the architecture and components live.
