Skip to content
Back to Projects

Lucky Bongky Store

A live Growtopia account marketplace, built and operated end-to-end — from the Next.js storefront and admin tooling down to the hardened VPS it runs on.

Visit luckybongky.com
Next.js 16Drizzle ORMMariaDBTailwind v4

Built with

Next.js 16 (App Router)

Framework — SSG product pages, prerendered storefront

React 19 + TypeScript 5

UI runtime and type safety across the codebase

Tailwind CSS v4

CSS-first styling, no config file

Drizzle ORM + MariaDB

Typed schema & queries; products, orders, FAQs, audit logs

jose (JWT) + bcryptjs

Admin sessions and password hashing

zod

Form and API request validation

nginx + systemd + Cloudflare

Reverse proxy, process supervision, Full SSL + edge protection

What's inside

Storefront

  • Account catalog with search and load-more pagination
  • Product detail pages with an Instagram-style image carousel and lightbox
  • Automatic trust badges on every listing
  • FAQ, privacy policy, and WhatsApp contact hand-off
  • Dynamic sitemap and per-page SEO metadata (Open Graph, canonical URLs)

Admin panel (separate subdomain)

  • JWT-protected sessions with login rate-limiting and full audit logging
  • Product CRUD with direct image upload — MIME type and magic-byte verified
  • FAQ editor with ordering and visibility toggles
  • Chat analytics dashboard: 14-day trends, source breakdown, geography

Cost-optimized chatbot

  • Answers from local FAQ and product matching first — zero AI cost for most queries
  • Falls back to an AI model only for out-of-scope questions
  • Rate-limited per IP with a per-session message cap

How it runs

The app runs as a supervised Node process behind an nginx reverse proxy, with Cloudflare in front providing Full SSL and edge filtering — the origin only accepts web traffic from Cloudflare's network. MariaDB is bound to localhost only, and user uploads live outside the application directory, served through a route that re-verifies file signatures on every request.

Security is layered through the stack: bcrypt-hashed admin credentials with login rate-limiting, short-lived JWT sessions, an audit trail of every admin action, and upload validation by MIME type and magic bytes. Deploys are scripted — backup first, build, restart, then smoke-test.

See it live

The store is in production and actively maintained.