ComputerStore - An e-commerce platform for computer hardware components.
Description: Users must be able to create accounts, login and manage their personal profile.
Acceptance Criteria:
- Users can register with valid email, unique username, and strong password.
- Secure login using Spring Security and BCrypt password hashing.
- Users can update their profile information (name, address, phone, email).
- Account deletion with full data cleanup (cascade deletion).
- Role-based access (USER role by default).
Description: The system must display a comprehensive catalog of computer components with detailed specifications.
Acceptance Criteria:
- Products are categorized by type (Processors, Graphics Cards, Motherboards, Cases)
- Each product displays: name, price, and technical specifications
- Users can view all products or filter by category
- Product information is stored persistently in database
Description: Users can manage a persistent shopping cart and a wishlist for future purchases.
Acceptance Criteria:
- Authenticated users have a persistent cart stored in the database.
- Products can be added to the cart or wishlist.
- Cart displays product details, quantities, and real-time total price.
- Users can adjust quantities or remove items from the cart.
- Wishlist items can be moved directly to the cart.
Description: A streamlined checkout process that creates persistent orders and manages inventory state.
Acceptance Criteria:
- Secure checkout flow restricted to authenticated users.
- Order creation includes timestamp, user reference, and item snapshots.
- Cart is automatically cleared upon successful order placement.
- Total price calculation includes all items and potential discounts.
Description: Users must be able to view their past orders.
Acceptance Criteria:
- Users can view list of all their previous orders
- Each order shows: order ID, date, total price, and items purchased
- Orders are sorted by date (newest first)
Description: Users must be able to filter products by component type to find specific items quickly.
Acceptance Criteria:
- Filter buttons for: All Products, Processors, Motherboards, Graphics Cards, Cases
- Filtered results display only products of selected type
- Filter selection persists when adding items to cart
- System returns appropriate products based on filter
Description: Comprehensive security measures and strict input validation to protect user data and system integrity.
Acceptance Criteria:
- CSRF (Cross-Site Request Forgery) protection on all state-changing forms.
- Password requirements: Minimum 8 characters with hashing via BCrypt.
- Email format validation using Jakarta Validation API.
- Role-Based Access Control (RBAC) ensuring users only access their own data.
- Protection against unauthorized access to administrative endpoints.
Description: The system must maintain user session state for authenticated users.
Acceptance Criteria:
- User login creates a session
- Session maintains user identity across pages
- Shopping cart is tied to user session
- Users can logout to end session
- Unauthenticated users are redirected to login
Description: The system must implement automated logging to track application behavior and troubleshoot issues.
Acceptance Criteria:
- Aspect-Oriented Programming (AOP) used to log service method executions.
- Request/Response logging for critical business flows (login, checkout).
- Performance tracking (execution time) for database queries.
- Error and Exception logging with stack traces for debugging.
Description: The system must maintain accurate product information including pricing and specifications.
Acceptance Criteria:
- Products have unique identifiers
- Product specifications vary by type (cores for CPU, memory for GPU, etc.)
- Products can be added, updated, or removed from catalog
- All product changes are persisted in database
Description: A secure authentication system using Spring Security with Role-Based Access Control (RBAC).
Technical Implementation:
- Security: BCrypt password encoding and CSRF protection.
- Roles:
ROLE_USERfor customers andROLE_ADMINfor system management. - Persistence: User details stored in the
userstable with Jakarta Validation. - Session: Secure session management with "Remember Me" functionality.
User Story: As a user, I want a secure way to access my personal data and orders so that my information remains private.
Priority: Critical (P0)
Description: A dynamic product catalog with category-based filtering and high-performance pagination.
Technical Implementation:
- Filtering: Category-specific views for Processors, GPUs, Motherboards, and Cases.
- Pagination: Server-side pagination (Spring Data JPA) to handle large datasets efficiently.
- Inheritance:
JOINEDinheritance strategy for specialized product specifications. - UI: Responsive grid layout with real-time specification display.
User Story: As a user, I want to filter and paginate through components so that I can quickly find parts that fit my specific build requirements.
Priority: Critical (P0)
Description: Persistent storage for user shopping carts and wishlists, enabling cross-device shopping.
Technical Implementation:
- Service:
CartServiceandWishlistServicemanaging database persistence. - Operations: Real-time quantity adjustments, price calculations, and "Move to Cart" logic.
- Integration: Automated cart cleanup upon successful order placement.
User Story: As a user, I want my cart to be saved across sessions so that I can place my order later.
Priority: High (P1)
Description: A checkout system that validates payment details and ensures transactional integrity.
Technical Implementation:
- Transaction: Atomic order creation and cart clearing using
@Transactional. - Validation: Server-side validation of payment information (Luhn check simulation).
- History: Immutable order snapshots capturing price-at-purchase to prevent history drift.
User Story: As a user, I want a secure checkout process so that I can finalize my purchase.
Priority: Critical (P0)
Description: A dedicated administrative dashboard for managing system users and monitoring activity.
Technical Implementation:
- Authorization: Restrictive access via
hasRole('ADMIN'). - Management: Paginated view of all registered users with administrative controls.
- Auditing: AOP-based logging of administrative actions for security audits.
User Story: As an administrator, I want to manage user accounts so that I can ensure the platform remains secure and well-moderated.
Priority: High (P1)
- AOP Logging: Automated logging of all service layer methods for better observability.
- Exception Handling: Centralized
@ControllerAdvicefor consistent error responses and user feedback. - Testing Coverage: Target >80% coverage using Jacoco, JUnit 5, and Mockito.
- Documentation: Full OpenAPI/Swagger integration for API exploration.
- Performance: Product pages load in under 500ms even with pagination.
- Security: 100% of sensitive data is encrypted; no unauthorized access to admin panels.
- Reliability: Successful order persistence and transactional integrity across all flows.
- Quality: All 50+ unit and integration tests passing in the CI/CD pipeline.