Module: vendor
Version: v0.01
Ownership default: If unclear, vendor owns until reassigned.
Provides: Vendor onboarding, profiles, and analytics.
Includes: CRUD endpoints for managing vendor entities, access restricted to authenticated or admin users.
Excludes: payment processing, billing administration, customer-facing vendor directories.
¶ 1. Roles and Views
- [MOBILE] KMM Android/iOS app dev
- [FE] Web frontend (React/Tailwind) dev
- [BE-RUST] Axum service dev
- [BE-DB] PostgreSQL/Redis ops
Vendor Management
- Provides CRUD endpoints for managing vendor entities
- Access restricted to authenticated or admin users as applicable
- Integrated with token-based authentication
- Get Vendor: Retrieve vendor entity data
- Update Vendor: Update or create vendor entity record
- Web Interface: Render HTML interface
- Vendor Authentication: Token-based access for vendor operations
- CRUD Interface: Forms for vendor data management
- Data Validation: Client-side validation for vendor inputs
- Responsive Design: Mobile-friendly vendor interface
| Method |
Path |
Purpose |
Auth |
| GET |
/api/vendor/get |
Retrieve entity data |
JWT |
| POST |
/api/vendor/update |
Update or create entity record |
JWT |
| GET |
/api/vendor |
Render HTML interface (web) |
JWT |
{
"error": {
"code": "VENDOR_NOT_FOUND",
"http": 404,
"message": "Vendor entity not found",
"trace_id": "uuid-v4"
}
}
| Key |
Required |
Example |
Notes |
| VENDOR_RATE_LIMIT_PER_MINUTE |
yes |
60 |
Vendor API rate limit |
| VENDOR_DATA_MAX_SIZE_KB |
yes |
512 |
Max size for vendor data |
| VENDOR_ANALYTICS_RETENTION_DAYS |
yes |
90 |
Vendor analytics data retention |
- Vendor app interface with secure authentication
- Offline capability for viewing cached vendor data
- Push notifications for vendor-related updates
- Secure storage for vendor session data
Acceptance:
- Vendor login < 3s
- Data updates complete < 2s
- Offline data access functional
- Vendor dashboard with authenticated access
- CRUD interface for vendor data management
- Analytics visualization for vendor metrics
- Responsive design for mobile and desktop
Acceptance:
- Dashboard loads < 3s
- Form validation provides real-time feedback
- CSRF protection enabled for all forms
- Axum route handlers for all vendor endpoints
- SeaORM integration for database operations
- Token validation for authenticated access
- Rate limiting for vendor endpoints
Rate limiting:
/api/vendor/update: Recommended for write endpoints
vendor_records
| Field |
Type |
Description |
| id |
UUID |
Primary key |
| user_id |
UUID |
Foreign key to users table |
| data |
JSONB |
Module-specific data |
| updated_at |
DateTimeUTC |
Last update timestamp |
| created_at |
DateTimeUTC |
Creation timestamp |
- Rate limiting:
vendor_rate:{user_id}:{endpoint} with sliding window
- Protected routes via AuthenticatedUser middleware
- CSRF protection for HTML routes
- Token validation for all API requests
- Sensitive data encryption where applicable
- Latency: Vendor operations p95 < 1s
- Availability: 99.9% uptime for vendor endpoints
- Scalability: Support concurrent vendor operations
- Data Integrity: Consistent vendor data management
- Vendor CRUD operations
- Data validation logic
- Rate limiting enforcement
- Vendor authentication flows
- Database operations
- API endpoint functionality
- Vendor app login and data access
- Offline capability
- Push notification handling
- Complete vendor management workflows
- Dashboard functionality
- Form validation and submission
[MOBILE]
- Vendor mobile interface with secure authentication
- Offline data access capability
- Push notification system
[FE]
- Vendor dashboard and management interface
- CRUD forms for vendor data
- Analytics visualization components
[BE-RUST]
- All vendor API endpoints with authentication
- Rate limiting implementation
- Database integration layer
[BE-DB]
- Database migrations for vendor tables
- Indexes for efficient vendor queries
- Redis schema for rate limiting
- All vendor endpoints functional with proper authentication
- CRUD operations work for vendor data
- Rate limiting prevents abuse
- Web interface renders properly
- Mobile interface provides offline access
- Analytics data properly stored and retrievable
- Breaking changes to vendor API require
/api/vendor/v2
- Database schema changes need migration plan
- Client interface changes require compatibility testing
/core - For shared utilities and middleware
/auth - For user authentication and JWT validation
/profile - For user profile integration