E-commerce

Festline

A server-rendered camping and outdoor store: price, coupons and stock are computed only on the server, with 13 attack scenarios tested. A 1,605-product catalogue migration, 18 tables.

Festline festline.com.tr
1.605ürünlük katalog
13/13saldırı engellendi
SSRsunucuda render
Open the site
Technical profile

What it is built with

StackTanStack Start (server-side rendering) + React 19, Tailwind 4, TypeScript
BackendPostgreSQL with server-computed price/coupon/shipping and locked stock decrement
Codebase~16,000 lines · 133 files
Interface58 components across server-rendered routes
Database18 tables · 23 versioned migrations
Catalogue1,605 products · 28 category headings (reduced from a 526-node tree)
Security13 attack scenarios tested, all blocked
EmailTransactional emails and in-site notifications
What makes it different

Not a standard website

  • Pages are rendered on the server. Content arrives ready, with no empty shell for a crawler or a slow phone to wait on — the core difference from a typical browser-rendered store.
  • The client does not set the price. Price, discount, shipping and coupons are computed only on the server, and direct writes to order tables were revoked. A request that dictates its own total gets a 403.
  • Stock survives a race. Stock is decremented under a row lock, so two simultaneous orders cannot split the last item.
  • The catalogue came by migration, not by hand. 1,722 products transferred, a 526-node tree reduced to 28 headings, 68 duplicates merged and 49 out-of-scope products removed.
  • Security is tested, not claimed. Thirteen scenarios covering price manipulation, coupon bypass, stock races and unauthorised writes were written — all blocked.
  • Independent infrastructure. Database, authentication and file storage moved out of an external development environment into our own account across 14 ordered migrations.
What we did

The solution in five parts

01

Move to independent infrastructure

Database, authentication and file storage were migrated to our own account; 14 migrations were applied in order, social sign-in was wired directly to the identity provider and hard-coded addresses moved into configuration.

02

Catalogue migration and cleanup

1,722 products were transferred and a 526-node category tree was reduced to 28 headings. 68 duplicate records were merged and 49 out-of-scope products removed, settling the catalogue at 1,605 products.

03

Server-side price and stock

Price, discount percentage, shipping and coupons are now computed only on the server. Stock is decremented under a lock, coupon limits are enforced server-side, and direct write access to order tables was revoked.

04

Verified by attack tests

Thirteen scenarios — price manipulation, coupon limit bypass, stock race conditions and unauthorised writes — were tested; all were blocked.

05

Server rendering and deployment

Pages are rendered on the server so content arrives ready on first load. Environment-variable and dependency failures in the deployment pipeline were fixed for good.

Components

What was built

  • Server-side rendering with content ready at first paint
  • Locked stock decrement and an order state machine
  • Server-verified coupons, shipping and size validation
  • Direct write access to order tables revoked
  • 14 versioned database migrations and private file buckets
  • Transactional emails and in-site notifications
  • Bulk product import, category mapping and discount calculation
  • Administrator role and permission table

Want a similar system?

Most of the problems we solved on Festline repeat across sectors. Tell us about yours and we will scope it together.