BrewBite Admin Backend is the server-side engine powering the admin panel of the BrewBite Android App — a full-featured ordering application for cafés and bakeries.
While the Android app handles the customer-facing experience (browsing menu, placing orders, and payment), this backend gives the admin complete control over the entire business operation through a clean, secure RESTful API.
The system is built around 8 independent business modules, each handling a specific domain of the business — from authentication and product management to revenue analytics and complaint resolution.
Built with a security-first mindset, the API uses JWT stateless authentication and role-based access control to ensure every endpoint is protected.
The backend follows a strict layered architecture that separates concerns at every level:
Android App (Customer) Admin Panel
│ │
└───────────┬───────────────┘
▼ HTTPS + JSON
┌─────────────────────┐
│ API Gateway │
│ Spring Security │
│ JWT Filter │
└─────────┬───────────┘
▼
┌─────────────────────┐
│ Controllers │ ← Handle HTTP Requests & Responses
│ Services │ ← Business Logic / Use Cases
│ Repositories │ ← Spring Data JPA (Data Access)
│ Entities / Models │ ← JPA Entities
└──────┬──────┬───────┘
│ │ │
┌──────▼─┐ ┌──▼────┐ ┌▼─────┐
│Postgres│ │Cloud │ │Other │
│ SQL │ │inary │ │Apps │
└────────┘ └───────┘ └──────┘
Common Modules shared across all layers:
- Exception Handling · Validation · Logging
- Response Wrapper · Global Config · CORS Config
flowchart TD
A([🔓 Admin opens login page]) --> B[Submit Email & Password]
B --> C[(Database\nAdmins Table)]
C --> D{Credentials\nValid?}
D -- ❌ No --> E([Show Error Message\nAuthentication Failed])
D -- ✅ Yes --> F[Generate JWT Token\nAccess Token + Refresh Token]
F --> G[Return Token to Client\nSecure Storage]
G --> H([✅ Access Granted\nProtected Resources Available])
style A fill:#f0f4ff
style E fill:#ffe0e0
style H fill:#e0ffe0
Security features implemented:
| Feature | Implementation |
|---|---|
| Password Hashing | BCrypt |
| Token Type | JWT — HS256 (Stateless) |
| Access Control | Role-Based (Admin Roles) |
| Request Security | Spring Security Filter Chain |
flowchart TD
A([📱 Customer places order\nfrom Android App]) --> B[Order sent to Backend API]
B --> C[Validate: items · stock · address · payment]
C --> D{Order\nValid?}
D -- ❌ No --> E([Return error message to user])
D -- ✅ Yes --> F[(Save Order\nin Database)]
F --> G([✅ Order Confirmed\nSuccess response to user])
G --> H[🔔 Notify Admin Panel]
H --> I[Admin views new order\nin dashboard]
I --> J[Update Order Status]
J --> K[Pending → Confirmed\nPreparing → On Delivery → Completed]
K --> L[Business Updates\nRevenue · Analytics · Stock]
L --> M([📨 Status notification\nsent to user])
style A fill:#f0f4ff
style E fill:#ffe0e0
style G fill:#e0ffe0
style M fill:#e0ffe0
- Admin registration and secure login
- JWT access token + refresh token generation
- Role-based access control (admin-only endpoints)
- Token validation via Spring Security filter
- Create, update, and delete menu items
- Manage item categories (drinks / bakery)
- Upload and manage item images via Cloudinary
- Maintain item details and availability
- View all incoming customer orders in real time
- Retrieve detailed order information and line items
- Update order status across the full lifecycle
- Track complete order history
- Calculate daily and monthly income automatically
- Track cumulative total revenue
- Review transaction history in detail
- Generate structured revenue reports
- Collect ratings submitted by customers
- Calculate and expose average rating per item
- Maintain a reviewable list of ratings
- Provide rating analytics for business insight
- View all customer comments and posts
- Allow admin to reply to customer feedback
- Comment rating and management
- Moderate and manage engagement data
- Receive and log customer complaints
- Track complaint status (open / in progress / resolved)
- Handle and resolve reported issues
- Maintain full complaint history for reference
- Overview dashboard with business KPIs
- Sales analytics broken down by period
- User activity and behavior insights
- Combined reports and statistics across all modules
| Layer | Technology |
|---|---|
| Language | Java 17 |
| Framework | Spring Boot 3.x |
| Security | Spring Security + JWT (HS256) |
| ORM | Spring Data JPA / Hibernate |
| Primary Database | PostgreSQL |
| Image Storage | Cloudinary |
| API Documentation | Swagger / OpenAPI |
| API Testing | Postman |
BrewBite-Admin/
├── src/
│ └── main/
│ ├── java/com/brewbite/admin/
│ │ ├── auth/ # JWT, login, register, security config
│ │ ├── item/ # Product CRUD & image management
│ │ ├── order/ # Order lifecycle management
│ │ ├── revenue/ # Income calculation & reports
│ │ ├── rating/ # Ratings & review analytics
│ │ ├── comment/ # Comments & admin replies
│ │ ├── complaint/ # Complaint handling & resolution
│ │ ├── analytics/ # Dashboard & statistics
│ │ └── common/ # Exception, Validation, Logging, CORS
│ └── resources/
│ └── application.properties
└── pom.xml
- Java 17+
- PostgreSQL running locally or remotely
- Cloudinary account (free tier works)
git clone https://github.com/Melikash98/BrewBite-Admin.git
cd BrewBite-Admin# PostgreSQL
spring.datasource.url=jdbc:postgresql://localhost:5432/brewbite_admin
spring.datasource.username=YOUR_DB_USERNAME
spring.datasource.password=YOUR_DB_PASSWORD
spring.jpa.hibernate.ddl-auto=update
# JWT
jwt.secret=YOUR_JWT_SECRET_KEY
jwt.expiration=86400000
# Cloudinary
cloudinary.cloud-name=YOUR_CLOUD_NAME
cloudinary.api-key=YOUR_API_KEY
cloudinary.api-secret=YOUR_API_SECRET./mvnw spring-boot:run- API base URL:
http://localhost:8080 - Swagger UI:
http://localhost:8080/swagger-ui.html
- Clean Architecture — strict separation between layers
- RESTful API Design — consistent, predictable endpoints
- Security-First — every endpoint protected by default
- Modular Development — 8 independent, self-contained modules
- Reusable Components — shared validation, logging, and response wrappers
- Scalability — stateless JWT ready for horizontal scaling
Developing this project gave me hands-on experience with:
- Designing enterprise-grade REST APIs from scratch
- Implementing JWT authentication with access & refresh token strategy
- Building clean, layered Spring Boot applications with proper separation of concerns
- Database modeling with JPA entities and PostgreSQL
- Media management with Cloudinary integration
- Structured exception handling and validation patterns
- Building business analytics and reporting workflows
- Securing APIs with Spring Security filter chains and role-based access
| Project | Description | Link |
|---|---|---|
| 📱 BrewBite Android App | Customer-facing Android app — Java, Firebase, PayPal, Google Pay | BrewBiteApp |
Melika Shooryabi
Java Backend Developer · Android Developer
This project is licensed under the MIT License.
Made with ❤️ — the backend layer of the BrewBite ecosystem
.png)
