Commit Graph

4 Commits

Author SHA1 Message Date
Kazem Alghasi
a5fd01dde1 chore(api): implement rate limiting for sensitive endpoints
Introduce granular rate limiting across various API categories to
improve security and prevent abuse. This includes protection against
brute-force attacks on authentication and SMS endpoints, as well as
resource management for public, customer, wallet, and staff APIs.

- Add `auth` rate limiter (5 requests/min per IP)
- Add `sms` rate limiter (1 request/min per phone/IP)
- Add `public` rate limiter (30 requests/min per IP)
- Add `customer` rate limiter (60 requests/min per user)
- Add `wallet` rate limiter (30 requests/min per user)
- Add `staff` rate limiter (60 requests/min per user)
- Apply middleware to corresponding routes in `api.php`
- Remove obsolete `test_pdf_generation.php` script
2026-10-04 01:35:22 +03:30
Kazem Alghasi
91984dbde3 feat(ui): redesign admin dashboard with layered grid and custom branding
Implement a comprehensive overhaul of the Filament admin dashboard,
introducing a structured 12-column responsive grid layout and enhanced
visual identity.

Key changes include:
- Redesigned Dashboard layout with a 4-layer progressive disclosure
  architecture (KPIs, Exchange Rates, Data Tables, and Trends).
- Introduced custom IFNEX design tokens via CSS, including branded
  stat cards, status badges, and improved sidebar typography.
- Enhanced FinanceOverviewWidget with real-time trend analysis and
  sparkline-ready data structures.
- Refactored RecentShipments and RecentTransactions widgets to use
  custom Blade templates for a more polished, consistent UI.
- Integrated brand assets including the company logo and custom
  authentication pages.
- Added global number formatting helpers and integrated them into
  financial widgets.
- Updated AdminPanelProvider to support custom login pages and
  brand-specific header/footer hooks.
2026-10-03 11:08:50 +03:30
Kazem Alghasi
d6e04d53fa feat(core): integrate Kavenegar SMS notifications and audit logging
Implement a comprehensive notification system using Kavenegar SMS
gateway and enhance system traceability through audit logging and
detailed shipment status history.

- SMS Integration:
  - Add Kavenegar SMS service with configurable API keys and sender
    numbers via system settings.
  - Implement automated SMS notifications for shipment approval,
    rejection, successful payments, and tracking updates.
  - Add administrative UI in Filament to manage SMS gateway settings
    and toggle specific notification types.
- Audit & Tracking:
  - Apply `Auditable` trait to core models (User, Shipment, Wallet,
    etc.) to track changes.
  - Refactor `ShipmentStatusHistory` to include status transitions
    (`from_status` to `to_status`) and specific reasons for changes.
  - Implement `ShipmentObserver` to automate notification triggers
    on status changes.
- Database & Config:
  - Add migrations for enhanced shipment status history tracking.
  - Update `.env.example` and `config/ifnex.php` with Kavenegar
    configuration parameters.
2026-09-10 00:52:18 +03:30
Kazem Alghasi
c95e992dbb feat: Complete Phase 1 core logic and WP bridge setup 2026-08-01 04:01:22 +03:30