Technical overviewFull-stack application architecture

Car Sale Application

An authenticated marketplace connecting a React interface to a layered Java API.

Source code

Inspect the implementation, commit history, and project documentation.

Role
Solo developer: React, Spring Boot, security, relational data, containers, cloud
Evidence status
Live at carsale.pesanth.com; self-hosted and verified end to end on 2026-08-09
Verified
2026-08-09

01

Purpose and scope

A peer-to-peer car marketplace where users list, buy, and manage vehicles. React drives the workflow while a Spring Boot API applies JWT auth, business rules, and MySQL persistence. It is live at carsale.pesanth.com.

What it is used for

  • Create an account and authenticate before any marketplace action.
  • Add, list, buy, and remove vehicles tied to ownership.
  • Give admins visibility into users and listings.
  • React
  • Spring Boot
  • Java
  • MySQL
  • JWT
  • Docker

02

Architecture

User interface

Frontend

React SPA

Login, marketplace, inventory, admin

HTTP client

Axios client

Attaches bearer tokens to API calls

HTTPS · JWT

API and security

Security boundary

Spring Security

RSA JWT, BCrypt, roles, CORS

API

REST controllers

Accounts, cars, listings, purchases

Delegates

Domain and persistence

Business logic

Domain services

Ownership, listing, purchase rules

Data access

JPA repositories

Entity mapping and queries

Database

MySQL

Users, roles, balances, vehicles

Packaged in

Deployment boundary

Orchestration

Docker Compose

nginx, API, and MySQL on one network

Public ingress

Cloudflare Tunnel

Outbound-only ingress, no open ports

Text equivalent: The React app sends authenticated requests to a stateless Spring Boot API; Spring Security validates JWTs, controllers delegate to services and JPA repositories, and MySQL stores users and vehicles, all wired by Docker Compose.

03

Engineering decisions

Stateless token boundary

Spring Security validates RSA JWTs and BCrypt hashes passwords, so authorization needs no server session.

Layered domain logic

Controllers delegate to services and JPA repositories instead of coupling HTTP handlers to the database.

One reproducible stack

Docker Compose wires the React client, Java API, and MySQL on one network for local and VM deployment.

04

Verification evidence

  • Source inspection confirmed React calls for auth, vehicle CRUD, listing, purchase, and admin.
  • The backend contains controller, service, repository, entity, security, and persistence layers.
  • The live site was exercised end to end on 2026-08-09: signup, JWT login, listing, and purchase returned expected responses, and auth endpoints returned 429 under rapid retries.
verified-2026-08-09
$ React client -> authenticated API request
Spring Security -> JWT validation
Controller -> service -> JPA repository
Docker Compose: nginx + API + MySQL
Cloudflare Tunnel -> carsale.pesanth.com
live at carsale.pesanth.com

05

Demonstrated workflow

06

Limitations