SUPER LUXURY CAR
Secure Web Software
Development
Super Luxury Car
Rental System
Academic presentation of the project stack, backend
implementation, and frontend experience.
Amir Hossein Asem Yousefi Özge Olgaç
2593631 2505882
Jarifa Zakaria Wajdi Ladhari
2106268 2502388 Built with .NET 8, MongoDB, React, Vite,
cookie-aware Swagger, and role-based
portals.
SLC Academic Presentation Presenter 1 | 01/15
SUPER LUXURY CAR
Project Technology Stack
The project combines a secure .NET backend, MongoDB persistence, and a modern React frontend.
Backend Frontend Database
.NET 8 Web API, controllers, services, repositories, JWT React, Vite, Router, Query, Zustand, Tailwind, form validation. MongoDB collections for users, cars, bookings, wallets, returns,
authentication. notifications.
Security API Tools Development
BCrypt passwords, role authorization, rate limits, secure headers, Swagger with cookie login for authenticated API testing. Rider for backend, Vite dev server for frontend, seeded test
audit logs. accounts.
SLC Academic Presentation Presenter 1 | 02/15
SUPER LUXURY CAR
System Architecture Overview
The architecture separates presentation, API boundaries, business rules, and persistent data.
React Client Web API Application Services MongoDB Swagger
Primary users Core resources Security boundary
Guests browse cars, clients rent and return cars, and admins Cars, clients, reservations, wallets, return requests, The backend enforces identity, roles, booking integrity, wallet
manage operations. notifications, and audit records. payment, and admin decisions.
SLC Academic Presentation Presenter 1 | 03/15
SUPER LUXURY CAR
Backend Layered Design
The backend uses clear layers to keep data, business logic, and HTTP endpoints maintainable.
Core Infrastructure Application Web API
Entities MongoDB Services Controllers
Implementation style Data access style
Controllers stay thin. Services handle rental rules, wallet updates, Generic repositories and UnitOfWork centralize MongoDB collection
return requests, notifications, and user management. access and keep persistence consistent.
SLC Academic Presentation Presenter 2 | 04/15
SUPER LUXURY CAR
Database Domain Model
MongoDB stores the entities required for clients, cars, reservations, payments, returns, and notifications.
Entity Purpose Important fields
User Authentication and roles Email, password hash, role, active state, wallet
Car Fleet inventory Brand, model, category, price, images, availability
Booking Rental reservation Client, car, dates, total, status, payment state
ReturnRequest Return review Photos, client note, admin note, decision status
Notification Client updates User, message, event type, read state
SLC Academic Presentation Presenter 2 | 05/15
SUPER LUXURY CAR
Authentication and Authorization
The backend authenticates users, protects roles, and supports cookie-based Swagger testing.
Login BCrypt Verify JWT Issued Cookie Stored Role Checked
Admin APIs require the admin role before sensitive data or management actions are available.
Swagger login writes the authentication cookie, so API testing does not require manual token authorization.
Security middleware applies protective headers, CORS rules, rate limits, and audit logging.
SLC Academic Presentation Presenter 2 | 06/15
SUPER LUXURY CAR
REST API Organization
API endpoints use resource-based names and Swagger orders operations by GET, POST, PUT, and DELETE.
Method Resources Purpose
GET cars, bookings, clients, wallet, returns, notifications Read public, client, and admin data
POST auth, bookings, cars, wallet top-up, return requests Create sessions and business records
PUT bookings, cars, users, settings, return decisions Update state and profile information
DELETE cars, bookings, notifications Remove or cancel eligible records
Naming rule Routes are grouped by business resources instead of reusing one vague action name across different methods.
SLC Academic Presentation Presenter 3 | 07/15
SUPER LUXURY CAR
Rental and Wallet Workflow
Renting a car validates availability, prevents overlap, charges the wallet, and notifies the client.
Select Car Validate Dates Block Overlap Check Wallet Create Booking Debit Wallet Notify Client
Rule Backend behavior
No double rental Active bookings and return-requested bookings block overlapping reservations.
Wallet payment Confirmed booking requires enough balance and records a wallet debit.
Status accuracy Booking status changes drive return eligibility and visible client updates.
SLC Academic Presentation Presenter 3 | 08/15
SUPER LUXURY CAR
Admin Backend Management
Admin services manage fleet data, client wallets, reservation state, and return review decisions.
Fleet Clients Reservations Returns
Create, update, delete View users, change Inspect bookings and Approve or reject photo-
cars and store multiple active state, and increase update status through backed return requests
images per car. wallet balances. controlled admin APIs. with admin notes.
SLC Academic Presentation Presenter 3 | 09/15
SUPER LUXURY CAR
Frontend Application Stack
The frontend uses React tools for routing, server state, authentication state, forms, validation, and polished UI.
React and Vite React Router TanStack Query
Component UI with fast development and production build. Public pages, protected client routes, and nested admin routes.
API caching and refresh after mutations.
Zustand Hook Form and Zod Tailwind and Motion
Persistent authentication state and user updates. Controlled forms with schema validation. Responsive luxury interface with smooth interactions.
SLC Academic Presentation Presenter 4 | 10/15
SUPER LUXURY CAR
Public Catalog and Availability
Guest and client pages show the fleet while preventing rented cars from entering the booking flow.
Home Fleet Car Details
Hero, featured cars, brand presentation, Search, filter, category, brand, price, Photos, specifications, price, availability
and authentication-aware navigation. sort, and available-only browsing. badge, and booking action.
API availability Availability badge Book button state Booking page
SLC Academic Presentation Presenter 4 | 11/15
SUPER LUXURY CAR
Client Booking Experience
Booking is presented as a guided flow from vehicle selection to wallet-confirmed reservation.
Vehicle Dates Client Info Wallet Payment
Frontend guardrails Backend confirmation
The UI checks selected vehicle, date range, personal fields, The API still performs final validation, creates the booking,
wallet balance, and loading state before submission. charges the wallet, and sends a notification.
SLC Academic Presentation Presenter 4 | 12/15
SUPER LUXURY CAR
Admin Portal Experience
The admin interface exposes business controls for cars, clients, wallets, reservations, and returns.
Cars Clients
Add, edit, remove, feature, price, and upload multiple car images. View clients, booking counts, active state, roles, and wallet balances.
Wallets Reservations
Increase client wallet amounts from the admin user screen. View bookings, filter status, and change reservation state.
SLC Academic Presentation Presenter 5 | 13/15
SUPER LUXURY CAR
Client Portal and Returns
Clients can review wallet balance, reservation history, notifications, settings, and car return requests.
Reservation Return Photos Admin Review Decision Notification
Client portal Return review
Wallet amount, reservations, payment status, rental status, return The client uploads multiple photos and a note. The admin
action, notifications, and user settings are available in one view. accepts or rejects the request with a review note.
SLC Academic Presentation Presenter 5 | 14/15
THANK YOU
Testing accounts
Admin: admin@[Link] / Admin@12345
Client: client@[Link] / Client@12345