A full-stack e-commerce platform with product management, order processing, Iranian payment gateways, vendor panel, admin dashboard, PWA support, blog, and SEO — all in a professional monorepo structure. Fully customizable via environment variables.
- Homepage — Banner slider, featured products, category showcase, page builder
- Product Listing — Search, category/price filters, sorting, pagination
- Product Detail — Image gallery, reviews, ratings, JSON-LD structured data
- Shopping Cart — localStorage-based, quantity management, saved items
- Checkout — Shipping method selection, coupon codes, payment gateway choice
- User Profile — Personal info, order history, wallet, wishlist, addresses
- Authentication — Register/Login with JWT, OTP via SMS/console
- Compare Products — Side-by-side product comparison
- PWA — Installable, offline fallback page, service worker with runtime caching
- Blog — Posts with categories, tags, comments, pagination
- SEO Metadata — Per-page OG, Twitter cards, canonical URLs
- JSON-LD — Organization, WebSite (SearchAction), Article, BreadcrumbList, Product schemas
- Sitemap — Auto-generated XML with products, categories, pages, blog posts
- robots.txt — Configurable via env var
- Dashboard — Real-time sales, orders, users, products stats
- Product Management — Full CRUD with image upload, pricing, categorization
- Category Management — Hierarchical parent/child categories
- Order Management — View, status updates (confirm/ship/deliver/cancel), advanced filters
- Discount Management — Percentage & fixed coupons with expiration
- User Management — User list, details, order history per user
- Vendor Management — Active vendor shops management
- Reports — Sales & performance analytics
- Settings — Store configuration, SEO, contact info
- Rich Text Editor — Tiptap-based content editing
- Vendor Dashboard — Personal store stats (products, orders, revenue)
- My Products — Manage your own products
- My Orders — View orders for your products
- Zarinpal — Live integration with API v4
- Mellat Bank — Simulated (ready for real integration)
- Saman Bank — Simulated (ready for real integration)
- Express / Standard Post
- TIPAX, MAHEX, Snapp Box
- RTL — Full right-to-left support
- Jalali Date — Using
date-fns-jalali - Persian Numerals — Native numeral display
- Full Persian UI — All interfaces in Persian
- Helmet — Security headers (CSP, HSTS, XSS, etc.)
- Rate Limiting — 4 layers (Nginx → NestJS → Edge middleware → Client backoff)
- CORS — Configured with credentials support
- Trust Proxy — Correct IP detection behind Nginx
- Input Validation — class-validator + sanitize-html + DOMPurify
- Dockerfile per service (API, Store, Admin)
- docker-compose.yml with Nginx reverse proxy
- Production-ready deployment
- GitHub Actions — Lint, build, test, E2E, CodeQL, publish
- Dependabot — Automated dependency updates
shop-platform/
├── apps/
│ ├── api/ # NestJS API — port 8000
│ ├── web/ # Storefront (Next.js) — port 3000
│ └── admin/ # Admin Panel (Next.js) — port 3001
├── packages/
│ ├── shared-types/ # Shared TypeScript types
│ ├── api-client/ # Auto-generated API client
│ └── eslint-config/# Shared ESLint configuration
├── docker-compose.yml
├── nginx/
│ └── nginx.conf
├── .github/
│ └── workflows/ # CI/CD pipelines
└── turbo.json # Turborepo configuration
🌐 User
│
▼
┌──────────────────────────────────────────────────┐
│ Nginx (port 80) │
│ / → web:3000 /admin/* → admin:3001 /api → api │
│ PWA headers | Rate limiting | SSL │
└──────────────────────────────────────────────────┘
│ │ │
▼ ▼ ▼
┌──────┐ ┌────────┐ ┌──────────────┐
│ Web │ │ Admin │ │ API │
│:3000 │ │:3001 │ │:8000 │
│ PWA │ │ │ │ Helmet │
│ SW │ │ │ │ Rate Limit │
└──────┘ └────────┘ └──────┬───────┘
│
▼
┌──────────────┐
│ Prisma │
│ (PostgreSQL) │
└──────────────┘
| Layer | Technology |
|---|---|
| Backend | NestJS 11, Prisma 5, Passport JWT, Swagger, Multer |
| Frontend (Store) | Next.js 16, React 19, Tailwind CSS 4, Serwist |
| Frontend (Admin) | Next.js 16, React 19, Tailwind CSS 4, Tiptap |
| Database | PostgreSQL 16 |
| Monorepo | Turborepo 2, npm workspaces |
| Language | TypeScript 5 (entire codebase) |
| State (Client) | TanStack Query + Zustand |
| Authentication | JWT (bcryptjs), httpOnly cookies |
| API Docs | Swagger (OpenAPI) |
| CI/CD | GitHub Actions + Dependabot |
| Container | Docker + docker-compose |
| Jalali Date | date-fns-jalali |
| Payment Gateway | Zarinpal API v4 |
| SMS | Kavenegar (production) / Console (development) |
| Nodemailer |
- Node.js ≥ 22
- npm ≥ 10
- PostgreSQL ≥ 16 (create an empty database)
# 1. Clone the repository
git clone <https://github.com/Hordekiller/Atlas-Shop>
cd shop-platform
# 2. Set up environment variables
cp .env.example .env
# Edit .env and fill in the values (database URL, JWT secret, etc.)
# 3. Install dependencies
npm install
# 4. Generate Prisma client & run migrations
npx prisma generate -w @atlas-shop/api
npx prisma migrate dev -w @atlas-shop/api
# 5. Seed the database with initial data
npm run db:seed -w @atlas-shop/api
# 6. Run all services
npm run dev| Role | Password | |
|---|---|---|
| Super Admin | admin@example.com |
admin123 |
| Customer | Register via website | — |
The first user to register automatically gets the SUPER_ADMIN role.
| Service | URL |
|---|---|
| Storefront | http://localhost:3000 |
| Admin Panel | http://localhost:3001 |
| API | http://localhost:8000/api/v1 |
| API Docs | http://localhost:8000/api/docs |
# Full deployment
docker compose up -d
# Services:
# - Nginx: port 80
# - API: port 8000
# - Storefront: port 3000
# - Admin Panel: port 3001| Variable | Required | Default | Description |
|---|---|---|---|
DATABASE_URL |
✅ | — | PostgreSQL connection string |
JWT_SECRET |
✅ | — | Secret for signing JWT tokens |
ENCRYPTION_KEY |
✅ | — | 32-char key for encrypting sensitive data |
NEXT_PUBLIC_SITE_URL |
— | http://localhost:3000 |
Public site URL for SEO, sitemap, PWA |
NEXT_PUBLIC_SITE_NAME |
— | فروشگاه من |
Brand name (titles, metadata, JSON-LD) |
NEXT_PUBLIC_SITE_SHORT_NAME |
— | فروشگاه |
Short brand name (PWA manifest, footer) |
NEXT_PUBLIC_SITE_DESCRIPTION |
— | Generic description | Site description (OG, metadata) |
NEXT_PUBLIC_API_URL |
— | http://localhost:8000/... |
Client-side API URL |
SITE_NAME |
— | فروشگاه من |
Brand name for API (email, SMS, invoices) |
SUPPORT_EMAIL |
— | info@example.com |
Support email for notifications |
MAIL_* |
— | — | SMTP configuration |
ZARINPAL_MERCHANT_ID |
— | — | Zarinpal merchant ID |
SMS_PROVIDER |
— | console |
console or kavenegar |
SMS_API_KEY |
— | — | Kavenegar API key |
Full list in .env.example.
The project has 4 GitHub Actions workflows:
Runs on every push/PR to main:
- 🔍 Lint & TypeCheck — ESLint for API,
tsc --noEmitfor all apps - 🏗️ Build All Apps — Prisma generate + Turborepo build
- 🧪 Unit Tests — Jest (AuthService tests)
- 🧪 E2E Tests — API smoke test with PostgreSQL service
Weekly security analysis + on push/PR to main.
Publishes packages to GitHub Packages on release.
Automated dependency updates.
# Unit tests (API)
npm test -w @atlas-shop/api
# E2E tests (requires PostgreSQL)
npm run test:e2e -w @atlas-shop/api
# Coverage
npm run test:cov -w @atlas-shop/api| Script | Description |
|---|---|
npm run dev |
Run all apps in development mode |
npm run build |
Build all apps for production |
npm run lint |
Lint and type-check all apps |
npm run dev:api |
Run API only |
npm run dev:web |
Run storefront only |
npm run dev:admin |
Run admin panel only |
npm run db:migrate |
Run Prisma migrations |
npm run db:seed |
Seed database with sample data |
- JWT authentication with register/login
- Product management (CRUD + image upload)
- Hierarchical categories
- Shopping cart & checkout
- Full admin panel (dashboard, orders, users, discounts)
- Vendor panel
- Zarinpal payment gateway
- Shipping methods (post, TIPAX, MAHEX, SnappBox)
- Jalali date & full RTL support
- Docker + docker-compose
- CI/CD with GitHub Actions + Dependabot + CodeQL
- SQLite → PostgreSQL migration
- Email delivery with Nodemailer
- Security hardening (Helmet, rate limiting, trust proxy, CORS)
- Code quality (ConfigModule, exception filter, logging)
- Rate limiting (4 layers: Nginx → NestJS → Edge → Client)
- PWA (installable with service worker + offline fallback)
- Blog with hybrid Server/Client pattern
- SEO (JSON-LD, OG, Twitter cards, sitemap, robots.txt)
- SMS (Kavenegar + console fallback)
- Invoice PDF generation
- Real-time notifications (WebSockets)
- Advanced discount system (smart coupons)
- Inventory & warehouse management
- Returns & refunds system
- Multi-vendor marketplace
- Affiliate system
- Wishlist sharing
- PWA push notifications
- i18n / multi-language support
- Fork it 🍴
- Create a feature branch (
git checkout -b feature/amazing) - Commit (
git commit -m 'feat: add amazing feature') - Push (
git push origin feature/amazing) - Open a Pull Request 🎉
See CONTRIBUTING.md for more details.
This project is licensed under the MIT License. See the LICENSE file for details.
Made with ❤️






























