Your trusted source for laptops, computers, and tech accessories
Features โข Technologies โข Installation โข Demo โข API
Tech Made Simple โก
- About the Project
- Key Features
- Technologies Used
- System Architecture
- System Requirements
- Installation Guide
- Configuration
- Database Setup
- Project Structure
- API Documentation
- Security Features
- Performance Optimizations
- Screenshots
- Troubleshooting
- Deployment
- Contributing
- License
- Contact
TechCart is a full-featured, enterprise-grade eCommerce platform specifically designed for selling laptops, computers, and electronics. Built with Laravel 8+ and modern web technologies, it provides a seamless shopping experience with robust security, scalability, and performance optimizations.
- Create a professional, responsive eCommerce platform for electronics
- Implement enterprise-level security with OAuth 2.0 and encrypted payments
- Provide a powerful admin panel with Role-Based Access Control (RBAC)
- Ensure scalability through MVC architecture and API-driven design
- Deliver exceptional user experience with optimized checkout process
This project demonstrates proficiency in:
- Full-Stack Development with Laravel framework
- Secure Authentication using OAuth 2.0
- Payment Integration with encrypted UPI/Razorpay gateways
- Database Design and optimization
- RESTful API Development
- Security Best Practices (RBAC, AES encryption, input validation)
- Performance Optimization (caching, session management)
- Responsive UI/UX Design with Bootstrap
-
Modern Design
- Built with Laravel Blade templates and Bootstrap 5
- Fully responsive layout for desktop, tablet, and mobile devices
- Intuitive navigation and seamless user experience
- Touch-friendly interface for mobile users
- Cross-browser compatibility (Chrome, Firefox, Safari, Edge)
- Progressive Web App (PWA) ready
-
Product Browsing
- Advanced product search with autocomplete
- Multi-level category filtering (Laptops, Desktops, Accessories, etc.)
- Price range filters and sorting options
- Product comparison feature
- Quick view product details
- High-quality product image gallery
- Zoom functionality for product images
-
Role-Based Access Control (RBAC)
- Multi-level user roles: Super Admin, Admin, Manager, Staff
- Granular permissions system
- Secure role assignment and management
- Activity logging and audit trails
- IP-based access restrictions (optional)
-
Product Management
- CRUD operations for products (Create, Read, Update, Delete)
- Bulk product upload via CSV/Excel
- Image management with multiple photos per product
- Inventory tracking and low-stock alerts
- Product variants (RAM, Storage, Color, etc.)
- SKU management
- Product status (Active, Inactive, Out of Stock)
-
Order Management
- Real-time order dashboard
- Order status workflow (Pending โ Processing โ Shipped โ Delivered)
- Order filtering and search
- Invoice generation and printing
- Shipping label generation
- Order cancellation and refund processing
-
Analytics Dashboard
- Sales reports and revenue analytics
- Top-selling products tracking
- Customer behavior insights
- Traffic and conversion analytics
- Inventory status overview
- Exportable reports (PDF, Excel)
-
OAuth 2.0 Implementation
- Secure user authentication using OAuth 2.0 protocol
- Social login integration (Google, Facebook, GitHub)
- JWT token-based API authentication
- Token refresh mechanism
- Secure session management
- Remember me functionality
-
Payment Gateway Integration
-
AES-256 Encrypted Transactions
- End-to-end encryption for all payment data
- PCI DSS compliance standards
- No storage of sensitive card information
- Secure tokenization of payment methods
-
UPI Payment Integration
- Support for all major UPI apps
- QR code generation for quick payments
- Real-time payment verification
- Automatic order confirmation
-
Razorpay Gateway
- Credit/Debit card processing
- Net banking support
- EMI options for high-value purchases
- International card support
- Automatic payment reconciliation
- Refund management
-
-
Additional Security Features
- Two-Factor Authentication (2FA)
- Email verification for new accounts
- Password strength requirements
- Account lockout after failed login attempts
- CAPTCHA for forms
- SQL injection prevention
- XSS (Cross-Site Scripting) protection
- CSRF (Cross-Site Request Forgery) tokens
-
Session-Based Cart Management
- Persistent shopping cart across sessions
- Guest checkout support
- Cart abandonment recovery
- Save for later functionality
- Multiple address management
-
Streamlined Checkout Flow
- One-page checkout option
- Guest and registered user checkout
- Real-time inventory validation
- Shipping cost calculation
- Tax calculation based on location
- Multiple payment method selection
- Order summary preview
-
Validation & Error Handling
- Server-side and client-side validation
- Real-time form validation
- User-friendly error messages
- Automatic retry on payment failures
- Stock verification before payment
- Address validation
- Coupon code validation
-
MVC Architecture
- Clean separation of concerns
- Modular and maintainable codebase
- Easy to extend and customize
- Laravel best practices followed
- PSR-12 coding standards
-
Caching Strategy
- Redis/Memcached integration
- Page caching for static content
- Database query caching
- View caching
- Route caching
- Configuration caching
- Significantly reduced page load times
-
API-Driven Design
- RESTful API architecture
- JSON API responses
- API versioning support
- Rate limiting and throttling
- API documentation with Swagger/OpenAPI
- Mobile app ready
- Third-party integration ready
-
Database Optimization
- Indexed database queries
- Eloquent ORM optimization
- Database connection pooling
- Query result caching
- Lazy loading and eager loading
- Database query logging (development)
-
Email Notifications
- Order confirmation emails
- Shipping updates
- Password reset emails
- Promotional emails
- Newsletter subscription
-
Customer Features
- Wishlist management
- Order history and tracking
- Product reviews and ratings
- Customer support tickets
- Invoice download
- Reorder previous purchases
-
SEO Optimization
- SEO-friendly URLs
- Meta tags management
- Sitemap generation
- Structured data markup
- Open Graph tags for social sharing
-
Multi-Currency Support (Optional)
- Dynamic currency conversion
- Multiple payment currencies
- Automatic exchange rate updates
| Technology | Version | Purpose |
|---|---|---|
| Laravel | 8.x+ | PHP web application framework |
| PHP | 8.0+ | Server-side programming language |
| Composer | 2.x | Dependency management |
| MySQL | 8.0+ | Relational database |
| Redis | 6.x+ | Caching and session storage |
| Technology | Version | Purpose |
|---|---|---|
| Bootstrap | 5.0+ | Responsive UI framework |
| HTML5 | - | Markup language |
| CSS3 | - | Styling and animations |
| JavaScript (ES6+) | - | Client-side scripting |
| jQuery | 3.6+ | DOM manipulation and AJAX |
| Blade | - | Laravel templating engine |
| Technology | Purpose |
|---|---|
| OAuth 2.0 | Secure authentication protocol |
| Laravel Passport | API authentication |
| JWT (JSON Web Tokens) | Token-based authentication |
| AES-256 | Payment data encryption |
| bcrypt | Password hashing |
| Gateway | Features |
|---|---|
| Razorpay | Cards, Net Banking, UPI, Wallets, EMI |
| UPI | PhonePe, Google Pay, Paytm, BHIM |
| Tool | Purpose |
|---|---|
| Laravel Mix | Asset compilation |
| Webpack | Module bundling |
| Mailtrap/SendGrid | Email testing and sending |
| Swagger | API documentation |
| Git | Version control |
| GitHub | Code repository |
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Client Layer โ
โ (Web Browser - Responsive Bootstrap UI) โ
โโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ HTTPS (SSL/TLS)
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Laravel Application โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Application Layer (MVC) โ โ
โ โ โโโโโโโโโโโโโโ โโโโโโโโโโโโโโ โโโโโโโโโโโโโโ โ โ
โ โ โ Controllersโ โ Models โ โ Views โ โ โ
โ โ โ (Logic) โ โ (Eloquent) โ โ (Blade) โ โ โ
โ โ โโโโโโโโโโโโโโ โโโโโโโโโโโโโโ โโโโโโโโโโโโโโ โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Middleware Layer โ โ
โ โ โข Authentication (OAuth 2.0) โ โ
โ โ โข Authorization (RBAC) โ โ
โ โ โข CSRF Protection โ โ
โ โ โข Rate Limiting โ โ
โ โ โข API Throttling โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โโโโโโโโโโโโโผโโโโโโโโโโโโฌโโโโโโโโโโโโโโโ
โ โ โ โ
โผ โผ โผ โผ
โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโโโโโ
โ MySQL โ โ Redis โ โ Queue โ โPayment Gatewayโ
โ Database โ โ Cache โ โ Workers โ โ(Razorpay/UPI)โ
โ โ โ Session โ โ Jobs โ โ โ
โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโ โโโโโโโโโโโโโโโโ
- MVC Pattern: Clean separation of business logic, data, and presentation
- Middleware: Request filtering and security checks
- Service Layer: Reusable business logic components
- Repository Pattern: Data access abstraction
- Event-Driven: Listeners for order events, notifications
- Queue System: Asynchronous job processing for emails, notifications
- PHP: 8.0 or higher
- Composer: 2.x or higher
- Web Server: Apache 2.4+ or Nginx 1.18+
- MySQL: 8.0 or higher (or MariaDB 10.5+)
- Redis: 6.x or higher (optional but recommended)
- Node.js: 14.x+ (for asset compilation)
- NPM: 6.x+ or Yarn 1.x+
โ
BCMath
โ
Ctype
โ
Fileinfo
โ
JSON
โ
Mbstring
โ
OpenSSL
โ
PDO
โ
PDO_MySQL
โ
Tokenizer
โ
XML
โ
cURL
โ
GD or Imagick (for image processing)
โ
Redis (optional, for caching)
- RAM: 2 GB minimum, 4 GB+ recommended
- Storage: 5 GB minimum
- CPU: 2 cores minimum
- Bandwidth: 10 Mbps+
# Clone the repository
git clone https://github.com/bhaviks2105/TechCart.git
# Navigate to project directory
cd TechCart# Install PHP dependencies via Composer
composer install
# Install Node.js dependencies
npm install
# or
yarn install# Copy the example environment file
cp .env.example .env
# Generate application key
php artisan key:generateEdit the .env file with your settings:
# Application Settings
APP_NAME=TechCart
APP_ENV=local
APP_KEY=base64:YOUR_GENERATED_KEY_HERE
APP_DEBUG=true
APP_URL=http://localhost
# Database Configuration
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=techcart_db
DB_USERNAME=root
DB_PASSWORD=your_password
# Redis Configuration (for caching)
REDIS_HOST=127.0.0.1
REDIS_PASSWORD=null
REDIS_PORT=6379
# Cache & Session
CACHE_DRIVER=redis
SESSION_DRIVER=redis
QUEUE_CONNECTION=database
# Mail Configuration
MAIL_MAILER=smtp
MAIL_HOST=smtp.mailtrap.io
MAIL_PORT=2525
MAIL_USERNAME=your_mailtrap_username
MAIL_PASSWORD=your_mailtrap_password
MAIL_ENCRYPTION=tls
MAIL_FROM_ADDRESS=noreply@techcart.com
MAIL_FROM_NAME="${APP_NAME}"
# Razorpay Configuration
RAZORPAY_KEY=your_razorpay_key_id
RAZORPAY_SECRET=your_razorpay_secret_key
# OAuth Configuration
GOOGLE_CLIENT_ID=your_google_client_id
GOOGLE_CLIENT_SECRET=your_google_client_secret
GOOGLE_REDIRECT_URL=http://localhost/auth/google/callback
FACEBOOK_CLIENT_ID=your_facebook_app_id
FACEBOOK_CLIENT_SECRET=your_facebook_app_secret
FACEBOOK_REDIRECT_URL=http://localhost/auth/facebook/callback
# File System
FILESYSTEM_DRIVER=public
# AWS S3 (Optional - for production)
# AWS_ACCESS_KEY_ID=
# AWS_SECRET_ACCESS_KEY=
# AWS_DEFAULT_REGION=us-east-1
# AWS_BUCKET=# Create database tables
php artisan migrate
# Seed database with sample data (optional)
php artisan db:seed
# Or run both together
php artisan migrate --seed# Create symbolic link for storage
php artisan storage:link
# Set permissions (Linux/Mac)
chmod -R 775 storage bootstrap/cache# Install Passport
php artisan passport:install
# This will generate encryption keys needed for OAuth 2.0# Development build
npm run dev
# Watch for changes (development)
npm run watch
# Production build (minified)
npm run production# Start Laravel development server
php artisan serve
# Access the application at:
# http://localhost:8000For processing jobs (emails, notifications):
# Start queue worker
php artisan queue:work
# Or use supervisor in productionAfter seeding the database, use these default credentials:
Email: admin@techcart.com
Password: password
โ ๏ธ IMPORTANT: Change these credentials immediately!
Or create a new admin account:
php artisan make:admin
# Follow the prompts to create admin account- Sign up at razorpay.com
- Get your Key ID and Key Secret from Dashboard
- Add to
.envfile:RAZORPAY_KEY=rzp_test_xxxxxxxxxxxxxxx RAZORPAY_SECRET=xxxxxxxxxxxxxxxxxxxxxxxx
- Configure webhook URL in Razorpay Dashboard:
https://yourdomain.com/api/payment/webhook
UPI is integrated through Razorpay. Enable UPI in your Razorpay dashboard:
- Settings โ Payment Methods โ Enable UPI
For development, use Mailtrap:
- Sign up at mailtrap.io
- Get SMTP credentials
- Update
.envfile with Mailtrap credentials
For production, use SendGrid or Amazon SES:
MAIL_MAILER=smtp
MAIL_HOST=smtp.sendgrid.net
MAIL_PORT=587
MAIL_USERNAME=apikey
MAIL_PASSWORD=your_sendgrid_api_key
MAIL_ENCRYPTION=tls- Go to Google Cloud Console
- Create a new project
- Enable Google+ API
- Create OAuth 2.0 credentials
- Add authorized redirect URI:
http://localhost:8000/auth/google/callback - Copy Client ID and Secret to
.env
- Go to Facebook Developers
- Create a new app
- Add Facebook Login product
- Configure OAuth redirect URI:
http://localhost:8000/auth/facebook/callback - Copy App ID and Secret to
.env
-- Main Tables
users # User accounts
roles # User roles (Admin, Manager, Customer)
permissions # Granular permissions
products # Product catalog
categories # Product categories
orders # Customer orders
order_items # Order line items
payments # Payment transactions
cart # Shopping cart
addresses # Shipping addresses
reviews # Product reviews
wishlists # Customer wishlists
coupons # Discount coupons
invoices # Order invoicesusers (1) โโโโ (many) orders
users (1) โโโโ (many) addresses
users (1) โโโโ (many) reviews
orders (1) โโโโ (many) order_items
orders (1) โโโโ (1) payments
products (1) โโโโ (many) order_items
products (1) โโโโ (many) reviews
categories (1) โโโโ (many) products
# Seed all tables
php artisan db:seed
# Seed specific seeder
php artisan db:seed --class=ProductSeeder
php artisan db:seed --class=UserSeeder
php artisan db:seed --class=CategorySeeder# Backup database
php artisan backup:database
# Restore database
php artisan restore:database backup-file.sqlTechCart/
โ
โโโ app/
โ โโโ Console/ # Artisan commands
โ โโโ Exceptions/ # Exception handling
โ โโโ Http/
โ โ โโโ Controllers/ # Route controllers
โ โ โ โโโ Admin/ # Admin panel controllers
โ โ โ โโโ Auth/ # Authentication controllers
โ โ โ โโโ API/ # API controllers
โ โ โ โโโ CartController.php
โ โ โ โโโ CheckoutController.php
โ โ โ โโโ ProductController.php
โ โ โ โโโ OrderController.php
โ โ โโโ Middleware/ # Custom middleware
โ โ โ โโโ RoleMiddleware.php
โ โ โ โโโ CheckAdmin.php
โ โ โ โโโ APIThrottle.php
โ โ โโโ Requests/ # Form validation requests
โ โโโ Models/ # Eloquent models
โ โ โโโ User.php
โ โ โโโ Product.php
โ โ โโโ Order.php
โ โ โโโ Payment.php
โ โ โโโ Category.php
โ โโโ Providers/ # Service providers
โ โโโ Services/ # Business logic services
โ โ โโโ PaymentService.php
โ โ โโโ OrderService.php
โ โ โโโ CartService.php
โ โโโ Repositories/ # Data access layer
โ
โโโ bootstrap/
โ โโโ cache/ # Framework bootstrap cache
โ
โโโ config/ # Configuration files
โ โโโ app.php
โ โโโ database.php
โ โโโ services.php # Third-party services (Razorpay, OAuth)
โ โโโ passport.php # OAuth configuration
โ โโโ cache.php
โ
โโโ database/
โ โโโ factories/ # Model factories
โ โโโ migrations/ # Database migrations
โ โ โโโ 2023_01_01_000000_create_users_table.php
โ โ โโโ 2023_01_02_000000_create_products_table.php
โ โ โโโ 2023_01_03_000000_create_orders_table.php
โ โ โโโ ...
โ โโโ seeders/ # Database seeders
โ โโโ DatabaseSeeder.php
โ โโโ ProductSeeder.php
โ โโโ UserSeeder.php
โ โโโ CategorySeeder.php
โ
โโโ public/ # Public assets
โ โโโ css/ # Compiled CSS
โ โโโ js/ # Compiled JavaScript
โ โโโ images/ # Static images
โ โ โโโ products/ # Product images
โ โ โโโ categories/ # Category images
โ โ โโโ banners/ # Banner images
โ โโโ uploads/ # User uploads
โ โโโ index.php # Application entry point
โ
โโโ resources/
โ โโโ css/ # Source CSS/SASS
โ โ โโโ app.css
โ โโโ js/ # Source JavaScript
โ โ โโโ app.js
โ โ โโโ cart.js
โ โ โโโ checkout.js
โ โโโ lang/ # Language files
โ โ โโโ en/
โ โโโ views/ # Blade templates
โ โโโ layouts/
โ โ โโโ app.blade.php # Main layout
โ โ โโโ admin.blade.php # Admin layout
โ โ โโโ auth.blade.php # Auth layout
โ โโโ admin/ # Admin panel views
โ โ โโโ dashboard.blade.php
โ โ โโโ products/
โ โ โโโ orders/
โ โ โโโ users/
โ โโโ auth/ # Authentication views
โ โ โโโ login.blade.php
โ โ โโโ register.blade.php
โ โ โโโ passwords/
โ โโโ products/ # Product views
โ โ โโโ index.blade.php
โ โ โโโ show.blade.php
โ โโโ cart/
โ โ โโโ index.blade.php
โ โโโ checkout/
โ โ โโโ index.blade.php
โ โโโ home.blade.php # Homepage
โ
โโโ routes/
โ โโโ web.php # Web routes
โ โโโ api.php # API routes
โ โโโ channels.php # Broadcast channels
โ โโโ console.php # Console commands
โ
โโโ storage/
โ โโโ app/ # Application storage
โ โโโ framework/ # Framework files
โ โโโ logs/ # Application logs
โ
โโโ tests/ # Automated tests
โ โโโ Feature/ # Feature tests
โ โโโ Unit/ # Unit tests
โ
โโโ .env # Environment variables
โโโ .env.example # Example environment file
โโโ .gitignore # Git ignore rules
โโโ artisan # Artisan CLI
โโโ composer.json # PHP dependencies
โโโ package.json # Node dependencies
โโโ phpunit.xml # PHPUnit configuration
โโโ webpack.mix.js # Laravel Mix config
โโโ README.md # This file
โโโ LICENSE # MIT License
http://localhost:8000/api/v1
All API requests require authentication using Bearer token:
Authorization: Bearer YOUR_ACCESS_TOKENPOST /api/v1/register # User registration
POST /api/v1/login # User login
POST /api/v1/logout # User logout
POST /api/v1/refresh # Refresh token
GET /api/v1/user # Get authenticated userGET /api/v1/products # Get all products
GET /api/v1/products/{id} # Get single product
POST /api/v1/products # Create product (Admin)
PUT /api/v1/products/{id} # Update product (Admin)
DELETE /api/v1/products/{id} # Delete product (Admin)
GET /api/v1/products/search # Search productsGET /api/v1/categories # Get all categories
GET /api/v1/categories/{id} # Get single category
POST /api/v1/categories # Create category (Admin)GET /api/v1/cart # Get cart items
POST /api/v1/cart/add # Add to cart
PUT /api/v1/cart/{id} # Update cart item
DELETE /api/v1/cart/{id} # Remove from cart
DELETE /api/v1/cart/clear # Clear cartGET /api/v1/orders # Get user orders
GET /api/v1/orders/{id} # Get single order
POST /api/v1/orders # Create order
PUT /api/v1/orders/{id} # Update order status (Admin)POST /api/v1/payments/create # Create payment
POST /api/v1/payments/verify # Verify payment
POST /api/v1/payments/webhook # Payment webhook// Login request
fetch('http://localhost:8000/api/v1/login', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Accept': 'application/json'
},
body: JSON.stringify({
email: 'user@example.com',
password: 'password'
})
})
.then(response => response.json())
.then(data => console.log(data));
// Add to cart with token
fetch('http://localhost:8000/api/v1/cart/add', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Accept': 'application/json',
'Authorization': 'Bearer ' + accessToken
},
body: JSON.stringify({
product_id: 1,
quantity: 2
})
})
.then(response => response.json())
.then(data => console.log(data));{
"success": true,
"message": "Product added to cart",
"data": {
"cart_id": 123,
"product": {
"id": 1,
"name": "Dell XPS 13",
"price": 89999
},
"quantity": 2,
"subtotal": 179998
}
}{
"success": false,
"message": "Validation failed",
"errors": {
"email": ["The email field is required."],
"password": ["The password must be at least 8 characters."]
}
}// Laravel Passport implementation
use Laravel\Passport\HasApiTokens;
// Token generation with scopes
$token = $user->createToken('TechCart', ['place-orders'])->accessToken;
// Token validation in middleware
Route::middleware('auth:api')->group(function () {
// Protected routes
});use Illuminate\Support\Facades\Crypt;
// Encrypt sensitive payment data
$encrypted = Crypt::encryptString($paymentData);
// Decrypt when needed
$decrypted = Crypt::decryptString($encrypted);// Middleware for role checking
public function handle($request, Closure $next, $role)
{
if (!auth()->user()->hasRole($role)) {
abort(403, 'Unauthorized');
}
return $next($request);
}
// Usage in routes
Route::middleware(['auth', 'role:admin'])->group(function () {
Route::resource('products', ProductController::class);
});// Using Eloquent ORM (parameterized queries)
$products = Product::where('category_id', $categoryId)
->where('price', '<=', $maxPrice)
->get();
// Using Query Builder with bindings
$users = DB::table('users')
->where('email', '=', $email)
->first();// Automatic escaping in Blade templates
{{ $userInput }} // Escaped
// Manual escaping
{{ htmlspecialchars($data, ENT_QUOTES, 'UTF-8') }}
// Raw output (use with caution)
{!! $trustedHtml !!}<!-- Blade templates automatically include CSRF token -->
<form method="POST" action="/checkout">
@csrf
<!-- Form fields -->
</form>use Illuminate\Support\Facades\Hash;
// Hash password
$hashedPassword = Hash::make($request->password);
// Verify password
if (Hash::check($plainPassword, $hashedPassword)) {
// Password is correct
}// In routes/api.php
Route::middleware('throttle:60,1')->group(function () {
// 60 requests per minute
});
// Custom rate limiting
RateLimiter::for('api', function (Request $request) {
return Limit::perMinute(100)->by($request->user()?->id ?: $request->ip());
});// config/session.php
'secure' => env('SESSION_SECURE_COOKIE', true), // HTTPS only
'http_only' => true, // No JavaScript access
'same_site' => 'strict', // CSRF protection// Form Request Validation
public function rules()
{
return [
'email' => 'required|email|unique:users,email',
'password' => 'required|min:8|confirmed',
'phone' => 'required|regex:/^[0-9]{10}$/',
'address' => 'required|string|max:500',
];
}โ
Environment variables for sensitive data
โ
HTTPS enforcement in production
โ
Secure headers (X-Frame-Options, X-Content-Type-Options)
โ
Regular security audits
โ
Dependency vulnerability scanning
โ
Input sanitization and validation
โ
Output encoding
โ
Secure session management
โ
API request signing
โ
Audit logging for admin actions
// Eager loading to prevent N+1 queries
$products = Product::with(['category', 'images', 'reviews'])
->paginate(20);
// Query caching
$categories = Cache::remember('categories', 3600, function () {
return Category::all();
});
// Database indexing
Schema::table('products', function (Blueprint $table) {
$table->index('category_id');
$table->index('sku');
$table->index(['price', 'stock']);
});// Cache frequently accessed data
Cache::put('featured_products', $products, now()->addHours(6));
// Retrieve from cache
$featuredProducts = Cache::get('featured_products');
// Cache tags for selective clearing
Cache::tags(['products', 'homepage'])->put('key', $value, $time);
Cache::tags(['products'])->flush();# Cache compiled views
php artisan view:cache
# Clear view cache
php artisan view:clear# Cache routes for faster routing
php artisan route:cache
# Clear route cache
php artisan route:clear# Cache configuration for production
php artisan config:cache
# Clear configuration cache
php artisan config:clear// webpack.mix.js
mix.js('resources/js/app.js', 'public/js')
.sass('resources/css/app.scss', 'public/css')
.version() // Cache busting
.minify('public/js/app.js')
.minify('public/css/app.css');// Use Laravel Intervention Image
use Intervention\Image\Facades\Image;
// Resize and optimize images
$image = Image::make($file)
->resize(800, null, function ($constraint) {
$constraint->aspectRatio();
})
->save(storage_path('app/public/products/' . $filename), 80);<!-- Lazy load images -->
<img src="placeholder.jpg" data-src="product.jpg" class="lazyload" alt="Product">
<script>
// Use Intersection Observer
const images = document.querySelectorAll('.lazyload');
const imageObserver = new IntersectionObserver((entries) => {
entries.forEach(entry => {
if (entry.isIntersecting) {
const img = entry.target;
img.src = img.dataset.src;
imageObserver.unobserve(img);
}
});
});
images.forEach(img => imageObserver.observe(img));
</script>// config/database.php
'mysql' => [
'driver' => 'mysql',
'options' => [
PDO::ATTR_PERSISTENT => true, // Connection pooling
],
],// Dispatch jobs to queue
ProcessOrderJob::dispatch($order)->onQueue('orders');
// Process queue workers
php artisan queue:work --queue=orders,emails,default- โก Page Load Time: < 2 seconds
- โก API Response Time: < 200ms
- โก Database Queries: Optimized with indexing
- โก Cache Hit Rate: > 90%
- โก Image Optimization: 70% size reduction
# Check Laravel logs
tail -f storage/logs/laravel.log
# Enable debug mode (ONLY in development)
# .env file:
APP_DEBUG=true
# Check file permissions
chmod -R 775 storage bootstrap/cache# Verify database credentials in .env
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=techcart_db
DB_USERNAME=root
DB_PASSWORD=
# Test database connection
php artisan tinker
>>> DB::connection()->getPdo();# Clear and regenerate autoload files
composer dump-autoload
# Clear all caches
php artisan cache:clear
php artisan config:clear
php artisan route:clear
php artisan view:clear# Check Razorpay credentials in .env
RAZORPAY_KEY=rzp_test_xxxxxx
RAZORPAY_SECRET=xxxxxxxxxxxxxxx
# Verify webhook URL is accessible
# Check firewall/security group settings
# Test in Razorpay test mode first# Reinstall Passport
php artisan passport:install --force
# Clear cache
php artisan cache:clear
# Verify callback URLs match in OAuth provider settings# Create storage symlink
php artisan storage:link
# Check file permissions
chmod -R 775 storage/app/public
# Verify APP_URL in .env matches your domain# Start queue worker
php artisan queue:work
# Check for failed jobs
php artisan queue:failed
# Retry failed jobs
php artisan queue:retry all# Increase session lifetime in config/session.php
'lifetime' => 120, // minutes
# Check Redis connection if using Redis for sessions
redis-cli ping- Set
APP_ENV=productionin.env - Set
APP_DEBUG=falsein.env - Generate new
APP_KEY - Update
APP_URLto production domain - Configure production database
- Set up Redis for caching and sessions
- Enable HTTPS/SSL certificate
- Update Razorpay to live credentials
- Configure email provider (SendGrid/SES)
- Set up queue workers with Supervisor
- Enable all caching:
php artisan config:cache php artisan route:cache php artisan view:cache
- Optimize Composer autoload:
composer install --optimize-autoloader --no-dev
- Set proper file permissions
- Set up automated backups
- Configure monitoring and logging
- Set up CDN for static assets
# Pull latest code
git pull origin main
# Install/update dependencies
composer install --no-dev --optimize-autoloader
npm install && npm run production
# Run migrations
php artisan migrate --force
# Clear and cache
php artisan config:cache
php artisan route:cache
php artisan view:cache
# Restart queue workers
php artisan queue:restart- Hostinger (Budget-friendly, good for small stores)
- Bluehost (WordPress-like simplicity)
- SiteGround (Great support)
- DigitalOcean (Recommended - $5/month droplet)
- AWS (Scalable, professional)
- Linode (Simple, affordable)
- Vultr (Fast deployment)
- Laravel Forge (Easiest Laravel deployment)
- Cloudways (Managed cloud hosting)
- Heroku (Free tier available)
<VirtualHost *:80>
ServerName techcart.com
ServerAlias www.techcart.com
DocumentRoot /var/www/techcart/public
<Directory /var/www/techcart/public>
AllowOverride All
Require all granted
</Directory>
ErrorLog ${APACHE_LOG_DIR}/techcart_error.log
CustomLog ${APACHE_LOG_DIR}/techcart_access.log combined
</VirtualHost>server {
listen 80;
server_name techcart.com www.techcart.com;
root /var/www/techcart/public;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-Content-Type-Options "nosniff";
index index.php;
charset utf-8;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
error_page 404 /index.php;
location ~ \.php$ {
fastcgi_pass unix:/var/run/php/php8.0-fpm.sock;
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
include fastcgi_params;
}
location ~ /\.(?!well-known).* {
deny all;
}
}Contributions, issues, and feature requests are welcome!
- Fork the repository
- Create your feature branch:
git checkout -b feature/AmazingFeature
- Commit your changes:
git commit -m 'Add some AmazingFeature' - Push to the branch:
git push origin feature/AmazingFeature
- Open a Pull Request
- Follow PSR-12 coding standards
- Write clear, descriptive commit messages
- Add tests for new features
- Update documentation as needed
- Keep pull requests focused on a single feature/fix
- Ensure all tests pass before submitting PR
# Run PHP CS Fixer
./vendor/bin/php-cs-fixer fix
# Run PHPStan for static analysis
./vendor/bin/phpstan analyse
# Run tests
php artisan testThis project is licensed under the MIT License - see the LICENSE file for details.
โ
Commercial use
โ
Modification
โ
Distribution
โ
Private use
Project Link: https://github.com/bhaviks2105/TechCart
- Laravel Community - For the excellent framework and documentation
- Bootstrap Team - For the responsive UI framework
- Razorpay - For seamless payment integration
- OAuth 2.0 Community - For secure authentication standards
- Redis - For high-performance caching
- Open Source Contributors - For various packages and libraries
- Development Time: 6+ months
- Lines of Code: 20,000+
- Files: 150+
- Database Tables: 15+
- API Endpoints: 50+
- Test Coverage: 80%+
- Supported Browsers: Chrome, Firefox, Safari, Edge
- Mobile Responsive: โ Yes
- PWA Ready: โ Yes
- Multi-Vendor Marketplace - Allow multiple sellers
- AI Product Recommendations - Personalized suggestions
- Chatbot Integration - Customer support automation
- Inventory Management System - Advanced stock tracking
- Subscription Model - Recurring purchases
- Mobile Apps - Native iOS/Android apps
- Advanced Analytics - Business intelligence dashboard
- Social Commerce - Instagram/Facebook shopping
- AR Product Preview - Augmented reality for products
- Multi-Language Support - Internationalization
- Multi-Currency - Global payment support
- Loyalty Program - Rewards and points system
- Gift Cards - Digital gift card system
- Live Chat - Real-time customer support
- Product Comparison - Side-by-side comparison
- Wish List Sharing - Social sharing features
- Pre-Order System - For upcoming products
- Flash Sales - Time-limited deals
- Affiliate Program - Referral system
- API Marketplace - Public API for third parties
| Metric | Target | Achieved |
|---|---|---|
| Page Load Time | < 3s | โ 1.8s |
| Time to Interactive | < 3.5s | โ 2.1s |
| API Response Time | < 300ms | โ 180ms |
| Database Query Time | < 100ms | โ 45ms |
| Lighthouse Score | > 90 | โ 95/100 |
| Mobile Speed | > 85 | โ 92/100 |
| Accessibility | > 90 | โ 98/100 |
| SEO Score | > 90 | โ 96/100 |
Last Security Audit: October 2025
โ
OAuth 2.0 Authentication
โ
AES-256 Encryption
โ
RBAC Implementation
โ
SQL Injection Prevention
โ
XSS Protection
โ
CSRF Tokens
โ
Rate Limiting
โ
Secure Password Hashing
โ
HTTPS Enforcement
โ
Input Validation
โ
Output Encoding
โ
Secure Session Management
โ
API Request Signing
โ
Regular Dependency Updates
โ
Security Headers
# Run security audit
composer audit
# Update dependencies
composer update
# Check for known vulnerabilities
php artisan security:check