Obsidian Notes Knowledge Search with MongoDB
Web-based knowledge search system that indexes Obsidian (.md, .txt) Vaults into MongoDB (NoSQL), supporting recursive vault scanning, metadata-aware search, advanced indexing, a note reader UI, and fallback caching for production deployments.

A search and management system for an Obsidian vault, built on Express 5 and MongoDB: public full-text search over the notes, and a JWT-protected admin panel for editing them, batch-importing files, and managing the folder tree — deployed serverless on Vercel.
Highlights
- Search that survives typos — a MongoDB text index handles the normal case, with a regex fallback behind it for queries the index cannot match. Results are scored by where the hit landed: title outranks filename, which outranks path, which outranks folder, which outranks body text.
- The native MongoDB driver, not Mongoose — no ODM layer, so queries and indexes are written directly. Indexes (text, regular, and a unique index on email) are created at startup rather than assumed to exist.
- It keeps answering when the database is down — a JSON cache at
data/notes-cache.jsonserves as a fallback when MongoDB is unreachable, so a connection failure degrades the site instead of taking it offline. - Serverless-shaped connection handling — pooling capped at 10 connections with automatic reconnect and a 25-second ping, because a serverless function that assumes a long-lived connection is exactly what fails first on Vercel.
- Uploads that never touch the filesystem — multer runs in memory, since a serverless function has no writable disk to stage a batch import onto.
- Two ways to create the first admin, both single-use — an interactive CLI, or a one-shot HTTP endpoint gated by
SETUP_KEY, so bootstrapping never requires leaving a default password in place.
Key Features
- Public search — full-text query, autocomplete suggestions from note titles, folder-tree browsing with per-folder note counts, and individual note reading, all without an account.
- Rate limiting where it matters — 60 searches per minute per IP (localhost exempted) and 10 login attempts per 15 minutes, so the expensive endpoints and the credential endpoint are protected separately.
- Admin CRUD — create, read, update and delete notes with pagination, filtering and sorting.
- Folder management — create, bulk rename, and recursive delete across the tree.
- Batch import — upload
.mdand.txtfiles while preserving their folder structure, via drag-and-drop in the admin UI. - Hardened by default — helmet security headers, CORS, and a 1 MB body limit, with JWT (HS256, 24-hour) sessions over bcrypt password hashes at 12 rounds.
Tech Stack
- Node.js ≥ 18 (CommonJS)
- Express 5.2.1
- MongoDB 7.x (native driver, no Mongoose)
- jsonwebtoken 9 (HS256, 24 h) + bcryptjs 3 (12 rounds)
- helmet 8, express-rate-limit 8, cors
- multer 1.4.5 (in-memory uploads)
- HTML + CSS + vanilla JavaScript frontend (no framework)
- Vercel serverless (
@vercel/node)
Status & Maturity
Active, and the best-tested project in this catalogue: 176 tests, all passing. It is also the backend that the Catatan Android client talks to — that app stores nothing locally and holds no database credentials, so every guarantee it makes about access control is really this service's verifyAdmin doing the work.
Measured Metrics
| Commits | 95 |
| Date Range | 17 Apr 2026 – 13 Aug 2026 |
| Lines of code | 21,351 |
| Tests | 176, all passing |