Full Stack & AICompletedFeatured SystemJan 2025 – Jun 2025

Bazaarify — AI-Powered Campus & Student Marketplace

Secure peer-to-peer university student marketplace engineered with Spring Boot 3, React 18, Python Scikit-Learn price valuation, and delivery OTP escrow.

Demo Accounts & Test Credentials

2 Test Roles

Use these pre-configured accounts to test live features across different user roles without registering.

Open App to Login
Select Role to Test:Active: Platform Administrator
User ID / Email (Platform Administrator)
Password
••••••••••••
Role Note:Access administrative dashboard (/admin), view platform Gross Merchandise Value (GMV), resolve community-flagged listings, and manage user suspensions.
Bazaarify — AI-Powered Campus & Student Marketplace

Technologies & Architecture Stack

Java 21Spring Boot 3.2Spring Security 6Stateless JWT (JJWT)MongoDBSpring Data MongoDBReact 18ViteTailwind CSSPython 3.10+FlaskScikit-LearnFirebase FirestoreCloudinary CDNDocker ComposeNginx

Project Overview

Bazaarify is a full-stack, AI-integrated peer-to-peer marketplace engineered specifically for university campuses and student communities across India. Built to eliminate campus trading scams and informal WhatsApp/Telegram marketplace friction, Bazaarify connects verified student buyers and sellers through a secure microservice architecture. The platform integrates a Spring Boot 3 REST API secured by Spring Security 6 and stateless JWTs, a responsive React 18 single-page application built with Vite and Tailwind CSS, a Python Scikit-Learn regression microservice providing instantaneous fair-value price estimates, and Firebase Firestore for low-latency peer-to-peer negotiation. Student transactions are safeguarded through an automated UPI-compatible escrow protocol featuring confidential 4-digit handover OTP verification.

The Engineering Problem

University student trading in India faces persistent trust, safety, and operational challenges: 1. Rampant Campus Scams: Informal trade across WhatsApp and Telegram groups leads to payment defaults, fake item handovers, and no transaction accountability. 2. Arbitrary Pricing: Students lack benchmark pricing knowledge for used textbooks, electronics, and dorm appliances, causing prolonged listing stagnation. 3. Unsafe Payment Handovers: Cash transactions or instant UPI payments before physical inspection expose student buyers to defective or misrepresented goods. 4. Scalability & Moderation Void: Campus marketplaces lack centralized moderation to handle harassment, counterfeit products, and fraudulent listings.

The Solution

Architected Bazaarify as an end-to-end trusted student exchange with hardware-grade verification: 1. Delivery OTP Escrow Mechanism: Buyer funds are held in platform escrow; sellers only receive payout once the buyer inspects the goods in-person and delivers a single-use 4-digit verification OTP. 2. Scikit-Learn Valuation Engine: A standalone Python/Flask microservice computes fair market depreciation based on original invoice price, item age, condition, and category curves, auto-filling suggested listing prices. 3. Real-Time Negotiation & Offer Matrix: Integrated Firebase Firestore for instant peer-to-peer messaging paired with an in-app formal counter-offer approval system. 4. Security & ReDoS Hardened API: Built Spring Security 6 token authentication, BCrypt credential salting, and sanitized search queries via Pattern.quote to eliminate regular expression denial-of-service vulnerabilities. 5. Granular Admin Moderation: Real-time GMV calculation, listing reports review queue, and user account lifecycle controls.

System Architecture & Data Flow

Decoupled Microservice & Event-Driven Architecture: - Frontend Client (Port 3000 / 5173): React 18 SPA bundled with Vite and styled via Tailwind CSS. Utilizes Axios request/response interceptors for automatic JWT injection and handles direct client-to-Cloudinary unsigned multipart media streaming. - Core API Gateway & Business Service (Port 8080): Java 21 / Spring Boot 3.2 application managing user lifecycles, listing state machines, order escrow transitions, and administrative aggregations. Configured with Spring Security 6 and stateless JJWT filters. - Persistence Layer: MongoDB 6.0+ document store running indexing on category, college campus, price boundaries, and user status. - AI Valuation Engine (Port 5000): Python / Flask microservice exposing Scikit-Learn regression pipelines to calculate algorithmic depreciation curves. - Real-Time Messaging Layer: Firebase Firestore handling low-latency chat sessions, typing indicators, and message timestamps between buyer and seller. - Orchestration: Docker Compose coordinates multi-container networking across frontend, backend, MongoDB, and AI service containers.

Core Engineering Features

Multi-Image Cloudinary Upload with dynamic client-side previews and direct CDN image distribution.
Python Scikit-Learn Fair-Price Valuation Engine predicting realistic depreciation curves across academic categories.
Escrow-Protected UPI Workflow withholding seller payouts until in-person physical inspection and OTP release.
Confidential Handover OTP Shielding ensuring the 4-digit code is visible strictly to the buyer and validated server-side.
Low-Latency Real-Time Student Chat powered by Firebase Firestore with integrated negotiation history.
Formal In-App Offer System allowing buyers and sellers to propose, counter, accept, or decline negotiated prices.
Listing Bump & Discovery Refresh allowing verified sellers to bump listings to the top of campus feeds once every 24 hours.
Comprehensive Admin Console featuring real-time GMV aggregation, active listing counts, and community abuse moderation queues.
ReDoS (Regular Expression Denial of Service) Protection sanitizing user-submitted search terms via Pattern.quote.
Multi-Criteria Campus Filter supporting instant searches by college affiliation, price bounds, condition, and delivery methods.

Technical Challenges & Overcoming Them

Securing Escrow Handover Integrity: Solved by strictly omitting the release OTP from the seller's API DTO responses and enforcing atomic verification in MongoDB so that funds release cannot race.
Stateless Cross-Origin Preflighting (CORS): Configured Spring Security 6 to explicitly permit CORS preflight OPTIONS requests without requiring Authorization headers, resolving preflight failures across disparate browser origins.
ReDoS Attack Mitigation in Discovery Queries: User-supplied search strings in regex queries were vulnerable to polynomial backtracking; resolved by sanitizing queries through Java's Pattern.quote() before compilation.
Media Upload Bottlenecks: Eliminated backend server memory spikes by routing multi-photo uploads directly to Cloudinary from the client using secure unsigned presets, persisting only generated CDN URLs in MongoDB.
Inter-Service AI Latency: Decoupled the Scikit-Learn valuation endpoint from listing creation so price suggestions remain an interactive seller assistant that doesn't block critical database writes.

Results & Impact

- Zero-Trust Transaction Safety: 100% of marketplace purchases guarded by OTP escrow, mitigating local campus payment fraud. - 85%+ Accurate Valuation: Scikit-learn regression model aligns student resale expectations within 10-15% of actual second-hand market clearance rates. - Sub-100ms API Response Times: Optimized Spring Data MongoDB indexing allows sub-second discovery queries across thousands of campus products. - Zero Orphaned Media: Cloudinary CDN offloading reduced backend disk I/O to near-zero, enabling lightweight containerization.

Key Takeaways

- Architecting production-grade Spring Boot 3 applications using Spring Security 6, stateless JWTs, and custom authentication filters. - Integrating heterogeneous multi-language tech stacks (Java backend + Python Flask AI + Node.js/React frontend). - Designing escrow state machines with OTP verification workflows to guarantee transactional integrity. - Hardening web applications against OWASP top vulnerabilities including ReDoS, CORS misconfigurations, and sensitive data exposure in JSON DTOs.

Future Roadmap

- Integrate Razorpay Route / Cashfree marketplace escrow APIs for automated institutional UPI disbursements. - Add edu-email domain validation (.ac.in / .edu) with automatic college verification badges. - Implement WebSockets using Spring STOMP as an on-premise alternative to Firebase Firestore. - Train an image classification CNN (PyTorch / MobileNet) to automatically detect product conditions and categories from uploaded photos.