Project Case Study
Lucky Bongky Store
A live Growtopia account marketplace, built and operated end-to-end — from the Next.js storefront and admin tooling down to the hardened VPS it runs on.
01 · Tech Stack
Built with
Next.js 16 (App Router)
Framework — SSG product pages, prerendered storefront
React 19 + TypeScript 5
UI runtime and type safety across the codebase
Tailwind CSS v4
CSS-first styling, no config file
Drizzle ORM + MariaDB
Typed schema & queries; products, orders, FAQs, audit logs
jose (JWT) + bcryptjs
Admin sessions and password hashing
zod
Form and API request validation
nginx + systemd + Cloudflare
Reverse proxy, process supervision, Full SSL + edge protection
02 · Features
What's inside
Storefront
- Account catalog with search and load-more pagination
- Product detail pages with an Instagram-style image carousel and lightbox
- Automatic trust badges on every listing
- FAQ, privacy policy, and WhatsApp contact hand-off
- Dynamic sitemap and per-page SEO metadata (Open Graph, canonical URLs)
Admin panel (separate subdomain)
- JWT-protected sessions with login rate-limiting and full audit logging
- Product CRUD with direct image upload — MIME type and magic-byte verified
- FAQ editor with ordering and visibility toggles
- Chat analytics dashboard: 14-day trends, source breakdown, geography
Cost-optimized chatbot
- Answers from local FAQ and product matching first — zero AI cost for most queries
- Falls back to an AI model only for out-of-scope questions
- Rate-limited per IP with a per-session message cap
03 · Architecture & Infra
How it runs
The app runs as a supervised Node process behind an nginx reverse proxy, with Cloudflare in front providing Full SSL and edge filtering — the origin only accepts web traffic from Cloudflare's network. MariaDB is bound to localhost only, and user uploads live outside the application directory, served through a route that re-verifies file signatures on every request.
Security is layered through the stack: bcrypt-hashed admin credentials with login rate-limiting, short-lived JWT sessions, an audit trail of every admin action, and upload validation by MIME type and magic bytes. Deploys are scripted — backup first, build, restart, then smoke-test.
See it live
The store is in production and actively maintained.