<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/b64c92c3838f4131b67490ae44d167b0&quot; frameborder=&quot;0&quot; width=&quot;1370&quot; height=&quot;1028&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1028</height><width>1370</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1028</thumbnail_height><thumbnail_width>1370</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/b64c92c3838f4131b67490ae44d167b0-55e094d4404e169e.gif</thumbnail_url><duration>1142.185</duration><title>Traveler Gateway Code Review Milestone 1</title><description>This Loom provides a code review of the Traveler Gateway full-stack web application built with an Express backend and Angular 18 admin SPA. The author spends most time on security, noting the current JWT authentication checks only token existence, not user roles, which creates a serious authorization vulnerability and allows authenticated users full admin privileges. They also point out missing role fields in the MongoDB user schema and that the Angular guard only checks for a token in local storage. For performance and database design, they identify inefficiencies like fetching all trips without MongoDB filtering or pagination, and they propose adding compound indexes, pagination, schema validation, and MongoDB aggregation reports restricted to admin users.</description></oembed>