01Overview & vision 02Technology stack 03Architecture 04Data model 05Modules & functionality 06Complete feature list 07Access control 08Security 09REST API 10Animated UI demo 11Quality & delivery 12What needs adding 13Appendix
Standalone document · everything in one file · v1.3

One file.
The whole project.
Nothing left to look up.

A single self-contained reference for MageTech Jewellery Smart — the vision and scope, the stack, the architecture decisions, the data model, all thirteen modules, every feature, the access rules, security controls, REST API, a working interface demo, the test evidence and the roadmap. No links to follow, no external requests, no build step.

13 sections 13 modules 203 endpoints 52 spec sections 732 tests 46 tables 33 permissions Zero external requests
0
Sections
0
Database tables
0
Tests passing
0
Endpoints
Contents

Thirteen sections, one document

Everything below is drawn from the repository as it stands today — the requirements specification, the schema, the route table and the test suite — not from intent. Read it top to bottom or jump to a section.

01 — Overview

What the system is

A jewellery-store management system for Indian jewellers running one or more counters, built around RFID-tagged stock and metal-rate-aware billing — and deployable on ordinary shared hosting, with no long-running processes.

★Vision & tagline

Smart Billing. Smarter Inventory. RFID-Powered Jewellery Management.

POS/counter billing · inventory and stock control · RFID tagging · product and catalogue management · metal rates · purchases and supplier settlement · customer management · reporting · analytics · multi-branch multi-tenant operation · role-based access · audit trail · backups.

✓Success criteria

  • Counter bill latency under 300 ms (warm DB, cached assets)
  • 10+ concurrent users per branch
  • No long-running processes — shared-hosting uptime
  • Reload-safe counter: the cart is server-held
  • 100% of statutory GST fields on every invoice
  • RFID scan → verify under 500 ms

+In scope

Everything in the two cards above, plus multi-tenant operation so a group can run several shops from one install, and a read-only REST API for devices and integrations.

−Explicitly out of scope

Redis · Docker/containerisation · JVM services · PostgreSQL · WebSockets/SSR · Spatie packages · a Node front-end. Each was excluded because the deployment target is cPanel/shared hosting. Repairs & karigar tracking were dropped from scope (no section owned them) rather than left as an open promise.

How this document is built. Every number here — 13 modules, 52 spec sections, 203 endpoints, 46 tables, 732 tests — is counted from the repository, not estimated. The document itself follows the product's own rules: self-hosted fonts, the supplied logo and favicon from this folder, and no CDN, tracker or external request of any kind.
02 — Technology stack

Every dependency, chosen against a constraint

The deployment target is shared hosting with no long-running processes. That one rule eliminated Redis, Docker, JVM services, PostgreSQL, WebSockets and a Node front-end before a line was written — and shaped everything that remained.

LayerChoiceWhy, and what it rules out
RuntimePHP 8.3 · Laravel 13Runs on any cPanel host. Rules out JVM services and container-only tooling.
DatabaseMariaDB / MySQL · utf8mb4The shared-hosting standard; money stored as integer paise. Rules out PostgreSQL.
Front-endBlade · Livewire 3.8 · Alpine · Tailwind 4Server-rendered with local interactivity. Rules out an SSR/Node front-end.
Real-timePolling + LivewireNo persistent connection. Rules out WebSockets and SSE.
Queue & cachedatabase queue · file cache & sessionNo daemons to supervise. Rules out Redis as a requirement.
SchedulingCron → schedule:runOne entry in crontab; no schedule:work process in production.
API authLaravel SanctumPersonal access tokens carrying the owner's own permissions.
PDFDompdfStatutory invoices, GSTR sheets and reports rendered server-side.
ChartingChart.js 4Bundled locally — no chart CDN at runtime.
FontsFigtree · Playfair DisplaySelf-hosted woff2; a test fails the build on any external font request.
Auth scaffoldLaravel Breeze, fully re-skinnedStandard flows, brand-new face.
Domain logicHand-written tenancy, permissions, audit, backupNo Spatie packages — smaller, auditable, on purpose.

▣Backend shape

  • 48 migrations · 39 models · 47 controllers
  • 92 support classes (enums, services, value objects)
  • 143 Blade views · 184 web routes
  • Middleware: SecurityHeaders, ResolveTenant, EnsurePermission

◈Front-end shape

  • Vite 8 build, assets committed — nothing to build at deploy
  • Tailwind 4 with brand/navy/gold/cyan namespaces
  • Alpine for small client behaviours
  • Zero external CDN requests, enforced by test

⚒Engineering tooling

  • PHPUnit 12 · Collision · Laravel Pint
  • 732 tests / 3,103 assertions, all green
  • Middleware order pinned by a dedicated test
  • laravel/pao for agent-readable test output
03 — Architecture

Decisions that shape everything

Six confirmed architecture decisions govern the whole codebase. They are recorded in docs/REQUIREMENTS.md §3 and asserted by tests, so a refactor that breaks one fails the suite rather than silently changing the product.

MageTech Jewellery Smart architecture diagram: client interfaces, application platform modules and external integrations.
ArchitectureThe platform from client interfaces to external integrations.MageTech-Jewellery-Smart-Architecture.png
DecisionDetailConsequence
Tenancy resolutionPath → domain → session → signed-in user's tenant → defaultThe URL segment wins, but a deliberate default never outranks a known owner. No public signup path creates a tenant.
Tenant storageSingle MariaDB database, tenant_id global scopeOne backup, one migration path. User carries the scope too, so provider lookup is confined by construction.
BranchesA tenant owns many branches; branch_id on stock and salesBranch is a separate axis from tenant — group reporting falls out of the schema.
RBACNamed roles, fixed permission lists in codeNo UI can grant a capability the repository does not contain. No privilege-escalation surface to guard.
First adminphp artisan magetech:install-adminNo default credentials ship anywhere; no route can mint an owner.
Audit & backupsCustom append-only table; custom zip archiveAudit rows throw on update/delete. Archives land in storage/app/private/backups, outside the web root.
Request pipeline

Middleware order is a security property

The tenant resolver must run after the session starts and before route-model binding. Global middleware fires too early (no session store); resolving after SubstituteBindings is worse and quieter — the scope would be inert while another business's row bound successfully.

RequestHTTP
→
SecurityHeadersCSP · nosniff · HSTS
→
StartSessionfile driver
→
ResolveTenantpath · domain · session · user
→
auth + tenant scopeglobal tenant_id
→
EnsurePermissionenum-backed
→
SubstituteBindingslast in group
→
Controllerview or redirect
Asserted, not assumed. tests/Feature/MiddlewareOrderTest.php pins this ordering directly, because it is a security property rather than a style preference. A reordering that looks harmless would otherwise bind another tenant's row instead of 404ing.
04 — Data model

Forty-six tables, two invariants

48 migrations create 46 business tables plus the framework's own cache, jobs and sessions. Two rules hold across all of them: every tenant-owned row carries a non-null tenant_id filtered by a global scope, and a balance is only ever written by the one writer the module names for it.

TTenancy & identity

  • tenants — slug, name, domains, locale, timezone
  • users — tenant-scoped, role enum
  • branches, counters — prefixes per branch
  • business_settings — one row per tenant
  • audit_logs — append-only, immutable
  • personal_access_tokens — Sanctum API keys

PCatalogue & rates

  • products — SKU, HSN, two GST rates, pricing mode
  • product_variants — weight, fineness, barcode, price
  • product_images — credited photography
  • product_categories — hierarchical, cycle-safe
  • metal_rates — append-only, effective-dated

SStock

  • stock_movements — append-only, reference-linked
  • stock_levels — cached balance, one writer
  • stock_counts + lines — post whole or not at all
  • Transfers write a row pair: out at source, in at destination

RRFID

  • rfid_tag_batches — sequential MT- codes, closes for good
  • rfid_tags — active / lost / retired / reissued
  • rfid_tag_bindings — one tag per variant, history kept
  • rfid_scan_sessions + results — every read kept verbatim

BBilling & sales

  • counter_sessions — open/close, counted cash, variance
  • sales_invoices + lines + payments
  • held_bills — stored as items, re-priced on resume
  • credit_notes + lines — reversed out of stock
  • loyalty_point_entries — append-only

LParties, purchases & system

  • customers / suppliers + ledger entries
  • purchase_orders → goods_receipts → purchase_invoices
  • metal_bookings — rate-lock, settle once
  • jobs, sessions, cache
Write disciplineSingle writerWhat it prevents
Stock balanceSupport\Inventory movement writerA controller incrementing a quantity the ledger doesn't know about
Metal rate historyMetalRateController / importerRetroactive price changes rewriting old bills
Audit rowsInsert-only; update/delete throwTampering with the record of who did what
Invoice numbersPer-branch, per-FY allocatorGapless numbering; duplicate documents
Loyalty balanceloyalty_point_entries sumTwo screens disagreeing about a customer's points
05 — Modules & functionality

Thirteen modules, 52 sections, all delivered

The system is specified section by section and every section is built. Each module below lists what it does at the counter and in the back office — this is the functionality a jewellery business gets on day one.

1 · Dashboard

§1.1–1.3

A role-aware home screen: what each user sees depends on their job, and every figure reads live from the tables the rest of the system writes — no stale summaries.

  • Today's sales, stock on hand, bound tags, party dues
  • Five alert types incl. low stock & flagged scans
  • Shortcuts that check permission before showing

2 · Products & Catalogue

§2.1–2.5

Product master with variants and images, hierarchical categories that refuse to become cyclic, metal and purity as closed enums with fineness as data, and two pricing modes.

  • Multi-image upload, per-variant SKU/barcode/price
  • HSN codes, making %, wastage, purity (22K/18K…)
  • Category reorder & drag-order maintenance

3 · Inventory & Stock

§3.1–3.5

An append-only stock ledger — nothing is ever overwritten — plus per-location transfers, physical counts with variance reason codes and purity-adjusted valuation.

  • Stock register by branch/location/cut
  • Manual adjust with reason codes
  • Count sheets: create → add lines → post/cancel

4 · RFID Tagging

§4.1–4.5

The module other jewellery software doesn't have: tag batches, EPC binding, scan sessions with manifests, printable label sheets and a full tag lifecycle.

  • Batch create/close/print, bind & unbind
  • Scan session: reads → complete/abort
  • Found / lost / retire / reissue with history

5 · Billing / POS

§5.1–5.6

The counter. Open a shift with a float, build a cart on the server, hold and resume bills, split payments, run exchanges, then print statutory or thermal output.

  • Counter open/close with counted-cash variance
  • Hold/resume, quick customer, barcode & RFID search
  • Exchange & return against the original bill

6 · Sales & Invoices

§6.1–6.4

Every invoice numbered gaplessly per financial year per branch, rendered to PDF, with registers cut by day, counter and shift — and credit notes for returns.

  • GST PDF, 80 mm thermal and A5 print
  • Day book / counter / shift registers
  • Credit note with reason codes & withdrawal

7 · Customers

§7.1–7.4

Customer profiles with GSTIN-derived party type, purchase history read from actual bills, advances and dues, printable statements and a loyalty scheme.

  • Ledger entries & closing-balance statement
  • Earn / redeem loyalty points at the till
  • Party past 30 days surfaces on the dashboard

8 · Suppliers

§8.1–8.3

Supplier profiles and a payable ledger where advances are kept as their own entry type — so ageing can never count the same rupee twice.

  • Payable ageing without double-counting
  • Period-based printable statements
  • Manual entries with audit attribution

9 · Purchases

§9.1–9.4

Procurement as a state machine: draft → approved → placed → received. Goods receipts are the only place inbound stock moves, and metal bookings lock a rate for a period.

  • PO line editing, approval and placement
  • GRN with over/short variance explanation
  • Metal bookings create/settle/cancel

10 · Metal Rates

§10.1–10.3

Effective-dated, append-only rates — no retroactive overwrite ever. Live screen, history, audited manual override and an all-or-nothing CSV import.

  • Per metal / purity, effective from a date
  • History with no retroactive edits
  • CSV import: template, validate, all-or-nothing

11 · Reports

§11.1–11.3

Sales, stock, purchases and party ageing as CSV, plus GSTR-1 and GSTR-3B working sheets bucketed by HSN and rate — exportable and printable.

  • 4 report families, CSV export each
  • GSTR-1 & GSTR-3B as CSV and PDF
  • HSN + rate bucketing for filing

12 · Analytics

§12.1–12.2

Period-over-period comparison with a least-squares seven-day projection labelled as a projection, plus fast/slow/dead stock and margin against lifetime cost.

  • Sales trend vs previous window
  • Fast / slow / dead stock classification
  • Margin on lifetime weighted-average cost

13 · Settings & Admin

§13.1–13.5

Business profile and GST, branches and counters, users with a read-only role matrix, tenancy scoping, a filterable audit log and tenant backups with restore.

  • Branch CRUD with own invoice prefixes
  • Users: create/edit/disable, last-owner guard
  • Backup create / download / restore
Delivered, not planned. Milestones M0–M9 are complete: the full suite — 732 tests, 3,103 assertions — passes, Pint style checks are clean, and the production build compiles. Section arithmetic: 3+5+5+5+6+4+4+3+4+3+3+2+5 = 52.
06 — Complete feature list

Every feature, plainly listed

203 endpoints in total — 184 web across 13 modules, 13 authentication endpoints and 6 REST API endpoints. Below is what a user actually meets on screen, grouped the way they experience it.

AreaRoutesWhat you can do
Dashboard2Role-aware cards (today's sales, stock on hand, bound tags, party dues); alerts for low stock, flagged RFID scans, bindable tags, parties not seen in 30 days and bookings expiring within a week; shortcuts that check both permission and route existence.
Catalogue21Create/edit/delete products; multi-image upload; variant rows each with own SKU, barcode and price; category create, edit, delete and reorder; metal rate create, CSV import with template download, and effective-dated history.
Inventory13Stock screen with location cut; movement register; manual adjustment and branch-transfer forms; full count workflow — create sheet, add lines, post or cancel — with independent piece and weight tallies.
RFID22Tag batches: create, close, print, label sheet; per-tag bind, unbind, mark found, mark lost, reissue; scan sessions: start, add reads, complete, abort, view reads; bindable-tag picker for the counter.
Billing / POS18Counter open with opening float and close with counted cash and variance; till with line add/remove; barcode & RFID search; quick customer create; hold, resume and clear; exchange panel; post bill and reprint.
Sales & returns13Invoice register with day/counter/shift cuts; invoice detail; PDF download; 80 mm thermal and A5 print; return creation against a specific bill; credit note detail, print and cancel.
Parties18Customer and supplier CRUD; manual ledger entries; printable statement with closing balance; purchase history read straight from posted bills; customer picker live on the till.
Purchases33Purchase orders draft → approve → place → cancel with line-level editing; goods receipts with over/short variance explanation; metal bookings create/settle/cancel; purchase invoices post, settle and cancel with per-line returns.
Reports15Sales, stock, purchases and parties — each with CSV export — plus GSTR-1 and GSTR-3B as CSV and PDF, bucketed by HSN and tax rate.
Analytics2Sales trend with previous-window comparison and a labelled seven-day projection; inventory fast/slow/dead classification; margin against lifetime weighted-average cost.
Settings24Business profile and GST details; branch CRUD with own invoice prefixes; user CRUD with last-owner and last-branch guards; read-only role matrix; filterable audit log; personal access API tokens; backup create, download, restore and delete.
Profile3Name, email and password change for the signed-in user.
Authentication13Login, logout, forgot password, reset password, email verification, password confirmation, registration.
REST API6Sanctum-token endpoints for products, stock, bills and rates — for integrations, handhelds and future mobile clients.

Business rules the system enforces for you

⏱State machines

  • Counter session must be open before a bill exists — one shift per till
  • Closing shows counted cash against expected and records the variance
  • Purchase order: draft → approved → placed → received
  • Goods receipt posts only with an explained variance
  • Credit note is withdrawable: stock returns, account corrected
  • RFID batch closes for good; a closed batch refuses a reprint
  • Scan session accepts no reads once closed

⚑Guards you can't bypass

  • The last active owner can't be deactivated
  • Nobody deletes or demotes their own account
  • The last branch can't be deleted
  • Super-admin status is never accepted from a form
  • Payments beyond a supplier's payable are refused
  • Advances are a separate entry type, never mixed into ageing
  • Rate history cannot be edited retroactively

⇩Outputs you get

  • GST invoice PDF with every statutory field
  • 80 mm thermal receipt via the browser print dialog
  • A5 invoice print
  • GSTR-1 and GSTR-3B CSV + PDF
  • Sales / stock / purchase / party CSV exports
  • Customer & supplier statements with balance
  • RFID label sheets and count sheets
  • Nightly zipped backup: database + files

Feature checklist

A flat, scannable list of what is in the box today.

✓Counter billing in under 300 msServer-held cart, reload-safe
✓Metal rate lock at billingEffective-dated, append-only
✓Purity & fineness pricing22K/18K and gram-based maths
✓Wastage & making chargesPer line, per product, per rule
✓RFID batch printingBind tags to SKUs in bulk
✓RFID scan sessionsManifest, reads, pass/fail
✓Tag lifecycleActive, found, lost, retired, reissued
✓Barcode search at tillScan or type, instant match
✓Hold & resume billsQueue a customer, keep theirs
✓Exchange & returnAgainst the original bill only
✓Credit notesStock back out, account corrected
✓Split paymentsCash, card, UPI, part advance
✓Counter sessionsOpening float, closing variance
✓GST invoicingAll statutory fields, HSN aware
✓GSTR-1 & GSTR-3BCSV and PDF working sheets
✓Gapless invoice numbersPer branch, per financial year
✓Thermal printing80 mm via browser, no driver
✓Stock ledgerAppend-only, every movement
✓Branch transfersMove stock with full trace
✓Stock countsPiece and weight tallies, variance
✓Reorder adviceLow stock surfaces on dashboard
✓Adjustment reasonsEvery change explained
✓Purchase ordersFour-stage approval workflow
✓Goods receiptsVariance explained, stock moves once
✓Metal bookingsRate-locked supply agreements
✓Purchase invoicesPost, settle, per-line returns
✓Supplier ageingAdvances kept separate
✓Customer statementsPrintable with closing balance
✓Loyalty earn & redeemPoints at the till
✓Party ledgersManual entries, full audit
✓Metal rate importCSV, all-or-nothing validation
✓Rate historyNever overwritten retroactively
✓Category treeCycle-safe, reorderable
✓Product variantsOwn SKU, barcode, price each
✓Multi-image galleryUpload and remove per product
✓Multi-branchOwn prefixes, own counters
✓Multi-tenantPath or domain scoped data
✓Five fixed rolesOwner, Manager, Cashier, Accountant, Stockroom
✓33 permissionsChecked in middleware, not the view
✓Append-only audit logRows throw on update/delete
✓Nightly backupsZip of DB + files, restorable
✓Sanctum API tokensCreate and revoke per user
✓6 REST endpointsFor integrations & handhelds
✓Sales analyticsTrend vs previous window
✓Stock analyticsFast, slow and dead stock
✓Margin reportingLifetime weighted-average cost
✓Day bookBy day, counter and shift
✓Dashboard alertsFive types, role aware
✓Zero external requestsSelf-hosted fonts, enforced by test
07 — Access control

Five roles, thirty-three permissions

Permissions are string cases in App\Support\Auth\Permission, not rows in a table — so an authorisation decision always traces to a literal in the repository, and no role can acquire a capability through the UI. There is deliberately no permission editor.

Permission OwnerManagerCashierAccountantStockroom
dashboard.view●●●●●
products.view · rates.view · inventory.view · rfid.view●●●●●
products.manage●●——●
rates.manage●●———
inventory.manage●●——●
rfid.manage●●——●
billing.create · billing.hold · billing.reprint●●●——
billing.discount · billing.cancel●●———
sales.view●●●●—
sales.view_all · sales.return●●—●—
customers.view●●●●—
customers.manage●●●——
suppliers.view · purchases.view●●—●●
suppliers.manage · purchases.manage●●——●
reports.view · analytics.view●●—●—
reports.financial●——●—
settings.view●●———
branches.manage · users.view · audit.view●●———
settings.manage · users.manage · backups.manage●————

OOwner

Full access, including users, settings and backups. 33 / 33 permissions.

MManager

Runs the outlet day to day, without backups or user provisioning. 29 permissions.

CCashier

Bills at the counter and handles customers. 11 permissions — no discount, no cancel, no reports.

AAccountant

Reporting, GST working sheets and party ledgers. 12 permissions — read-only across the book, no billing.

SStockroom

Stock, RFID tags, product records and purchases. 11 permissions — no billing, no sales.

⊕API tokens

A token carries its owner's permissions and nothing more — a cashier's token can no more read a report than the cashier can in a browser.

Guards the UI cannot bypass. The last active owner cannot be deactivated; nobody deletes or demotes their own account; the last branch cannot be deleted; super-admin status is never accepted from a form.
08 — Security

Hardening as middleware, not a checklist

SecurityHeaders runs on every response — error pages, downloads and the health endpoint included, because a header that only guards the screens that render often is one an attacker simply avoids.

ControlWhat it does
Content-Security-Policydefault-src 'self' with object-src 'none', base-uri 'self', frame-ancestors 'self', form-action 'self'. Scripts and styles from any other origin are refused outright.
Permissions-PolicyEight sensors named as unavailable: accelerometer, camera, geolocation, gyroscope, magnetometer, microphone, payment, USB.
Transport & framingX-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Referrer-Policy: strict-origin-when-cross-origin, HSTS where the request is already https.
Rate limitingA named api limiter at sixty requests a minute per user, applied to every API route.
Error handlingBranded 403, 404, 419, 429 and 500 pages instead of framework traces; /up for probes.
Tenant isolationGlobal tenant_id scope on every owned table, including User — reach is confined by construction.
Audit trailAppend-only: updates and deletes throw a LogicException rather than silently corrupting who did what.
BackupsJSON + manifest inside a zip under storage/app/private/backups — outside the web root. Restore refuses another business's file and refuses column drift before the first delete.
BootstrapOwners exist only through magetech:install-admin. No default credentials ship; no route can mint an admin.
Secrets.env is git-ignored; API tokens are shown once in plaintext and revocable instantly from settings.
Honest note on CSP. The policy permits inline script and style because the Blade views use inline event handlers (confirm-before-delete). What it removes is the part that matters for injection: code from anywhere but this origin, plugin objects, a foreign base tag, off-site form posts and framing by anyone else.
09 — REST API

Six read-only endpoints, same permissions

A Sanctum-authenticated, read-only surface for till displays, stock devices and reporting hooks. It answers in one shape, prices in integer paise, and carries the caller's own permissions — the token grants nothing its owner does not already hold.

auth:sanctumbearer token
→
ResolveTenantsame resolver
→
tenant scopeglobal
→
throttle:api60 / min / user
→
ReadControllerdata + meta

⇄Response contract

Every response is a single JSON object: data for the payload, meta for pagination and timing. Money is integer paise, dates are ISO-8601, errors use the same envelope with a stable machine-readable code.

  • GET /api/products — list & filter
  • GET /api/products/{id} — detail with variants
  • GET /api/stock — levels by location
  • GET /api/rates — effective metal rates
  • GET /api/invoices — recent documents
  • GET /api/invoices/{id} — one document

⛨What it deliberately isn't

  • No writes — billing and stock stay in the application where the guards live
  • No public registration; tokens are minted per user from settings
  • No separate permission model to drift from the UI's
  • No unauthenticated endpoint of any kind
  • Rate-limited at 60 requests/minute/user

Integration points for handhelds, kiosks and BI tools — with the same tenancy and role rules as a browser session.

10 — Animated UI demo

The interface, demonstrated

Four working demonstrations of the real screen layouts — the dashboard a manager opens, the till a cashier lives in, the RFID scan a stockroom runs and the report an accountant files. Switch tabs; the animations replay.

magetech.local/dashboard

Good morning, Priya

Owner · Jaipur — Bapu Bazaar · 02 Oct 2026

Shift open · Till 1
Today's sales
₹0
▲ 12.4% vs yesterday
Stock on hand
0 pcs
▲ 34 received today
Bound RFID tags
0
93% of stock tagged
Party dues
₹0
6 parties past 30 days
Sales — last 7 days today highlighted
SAT
SUN
MON
TUE
WED
THU
TODAY
Alerts
▲Low stock — 14 itemsReorder level hit in Gold Chains and Jhumka categories.
⌁3 RFID scans need reviewTag reads that didn't match the batch manifest.
✓Nightly backup completed02:00 · 412 MB zip · database + files.
magetech.local/billing/pos
🔒 Gold rate locked at bill start — ₹7,245/g · 22K · effective 02 Oct 2026
Temple Necklace Set
SKU GLD-NEC-0242 · RFID E280…4A1
42.350 g
₹3,42,180
Daily Wear Chain 22K
SKU GLD-CHN-118 · RFID E280…9C7
8.120 g
₹65,740
Diamond Stud Earrings
SKU DIA-EAR-071 · 0.50 ct · I1
1 pcs
₹48,900
Silver Payal Pair
SKU SLV-ANK-009
2 pcs
₹4,180

Bill · Till 1

Customer: Meera Sharma · 98290… · Loyalty 2,140 pts

Gold 42.350 g × ₹7,245₹3,06,825
Making 8% + wastage 2%₹35,355
Diamond & silver items₹53,080
CGST 3% + SGST 3%₹21,617
Loyalty redeemed (400 pts)− ₹1,200
Payable₹4,15,677
CASHCARDUPI
magetech.local/rfid/sessions/18
UHF Reader connected · Session #18 · Aisle 2
Manifest: 8 expected 0 / 8 verified
E280-1170-B1C4-0000-0242
Temple Necklace
FOUND
E280-1170-B1C4-0000-0118
Daily Wear Chain
FOUND
E280-1170-B1C4-0000-0071
Diamond Studs
SCANNING
E280-1170-B1C4-0000-0305
Kundan Ring
SCANNING
E280-1170-B1C4-0000-0412
Jhumka Pair
SCANNING
E280-1170-B1C4-0000-0556
Mangalsutra
SCANNING
E280-1170-B1C4-0000-0663
Bangle Set
MISSING
E280-1170-B1C4-0000-0701
Payal Pair
SCANNING

Scan-to-verify target: < 500 ms per tag. Each read is matched against the batch manifest; anything not expected is flagged for review rather than silently accepted.

magetech.local/reports/gst/gstr1

GSTR-1 · September 2026

B2B + B2C summary · HSN bucketed · GSTIN 08ABCDE1234F1Z5

Ready to file
⬇ Export CSV⎙ Print PDF✓ Validate
HSNDescriptionTaxable valueRateCGSTSGSTTotal
7113Gold jewellery, 22K₹18,42,5003%₹55,275₹55,275₹19,53,050
7113Silver articles₹1,86,4003%₹5,592₹5,592₹1,97,584
7114Gold jewellery, 18K₹4,12,9003%₹12,387₹12,387₹4,37,674
7102Diamonds, unstudded₹6,75,0000.1%+0.1%₹675₹675₹6,76,350
9988Making charges (labour)₹2,41,6005%₹12,080₹12,080₹2,65,760
Reconciliation
Invoicesgapless FY numbering418
Total taxCGST + SGST₹1,62,686
Credit notes3 returns, stock restored− ₹48,200
These are live HTML demonstrations built from the real screen structure — the same layout, fields, guards and numbers the application renders. No screenshots, so they scale to any screen and replay on every switch.
11 — Quality & delivery

Proven by tests, not promises

Every milestone from M0 to M9 is built and runnable. The evidence sits in the repository: a PHPUnit suite that covers the state machines, guards and permissions, style checks that stay clean, and a production build that compiles.

0
Tests
0
Assertions
0
Migrations
0
Blade views

M0 Foundation done

Laravel 13 scaffold, toolchain, brand design system, self-hosted fonts, test harness.

M1 Auth & tenancy done

Breeze re-skinned, tenant resolution chain, global scope, role permissions in code.

M2 Catalogue done

Products, variants, images, categories, metal & purity enums, HSN, pricing modes.

M3 Inventory done

Append-only ledger, transfers, adjustments with reasons, count sheets and valuation.

M4 Parties done

Customers and suppliers, ledgers, statements, advances, purchase history, loyalty.

M5 Purchases done

Orders, goods receipts with variance, metal bookings, purchase invoices and settlement.

M6 Rates done

Effective-dated append-only rates, live/history screens, audited overrides, CSV import.

M7 Billing done

Counter sessions, server-held cart, holds, exchange, split payment, thermal & statutory output.

M8 Sales & reports done

Registers, PDF invoices, credit notes, CSV reports, GSTR-1 and GSTR-3B.

M9 Dashboard, backups, hardening done

Role-aware dashboard, five alert types, nightly backups with restore, middleware ordering pinned by tests.

⛨Security posture

  • Sanctum API auth; hashed passwords; session hardening
  • Content-Security-Policy, HSTS, nosniff on every response
  • Permission checked in middleware — before the controller
  • Tenant scope is a global query scope, not a request filter
  • Backups stored where the web root cannot serve them
  • No default credentials: first owner via artisan command

⚙Runs anywhere cheap

  • PHP 8.3 + Laravel 13 + MariaDB — nothing exotic
  • Blade + Livewire + Alpine + Tailwind, compiled at deploy
  • No Redis / queue worker / Node SSR / Docker / WebSockets
  • Cron only — no schedule:work process
  • File cache & session drivers, database queue
  • Self-hosted fonts: zero third-party requests

✓Definition of done

  • Full suite green — 732 tests, 3,103 assertions
  • Laravel Pint style check clean
  • npm run build succeeds, assets committed
  • No external network request in devtools
  • Statutory GST fields verified present
  • Middleware order asserted by an automated test
12 — What needs adding

What's next, honestly listed

Nothing below is broken — it is scope that has not been opened yet. These are the capabilities a live jewellery shop will ask for next, ranked by how soon it will be asked for.

High value Loyalty configuration screen

Loyalty is built and working — earn and redeem already run at the till — but the four settings that control it have no screen yet, so switching it on for a shop needs a developer today.

High value Barcode label printing

Products carry barcodes and the till searches on them, but only RFID label sheets can be printed. A jeweller not using RFID still needs adhesive barcode labels at the counter.

High value Offline billing

Billing is refresh-safe — the cart lives on the server — but a dead connection stops sales. A queue that replays transactions when the line returns is the largest remaining engineering item.

Medium Notifications & reminders

Low stock, flagged scans and overdue parties appear as dashboard alerts only. Email/SMS/WhatsApp delivery, birthday and anniversary reminders and due-payment nudges are not wired up yet.

Medium Estimates & quotations

A per-branch estimate prefix is already stored in the schema, but no screen writes it. Quotation-to-bill conversion, expiry and customer acceptance are unimplemented.

Medium GSTR filing integration

GSTR-1 and GSTR-3B are working sheets — CSV and PDF a human files in the portal. Direct IRN e-invoicing and e-way bills are an external integration, not an app feature.

Medium Custom roles

Roles are deliberately fixed in code so no screen can grant a privilege the code doesn't have. A shop wanting "senior cashier — discounts but no reports" would need a permissions editor and a security decision.

Medium Custom tenant domains UI

The resolver reads tenants.domains as step two of five, but no screen sets it — multi-shop groups running one custom domain per outlet need database access today.

Low Languages (Hindi/regional)

Every string in the UI is already wrapped for translation — 2,094 call sites — but no language files exist yet, so everything falls back to English. Adding copy is a content job, not a code job.

Low PWA offline shell

A web manifest and install shortcuts ship, but there is no service worker — opening the app with no signal shows the browser's error page rather than a cached shell.

Low Queue-backed work

app/Jobs does not exist. Backups, rate imports and PDF generation run inside the request. The database queue driver is already configured, so adding jobs is cheap when something becomes slow.

Low Repairs & karigar tracking

Present in the original outline, then dropped because no section owned it. Reopening it is a genuine module with its own lifecycle — it needs a spec revision, not a finishing touch.

How to read this list. The three high value items are what a live shop hits first: loyalty can't be switched on without a developer, barcode labels can't be printed, and billing stops when the internet does. The rest are either a decision with a trade-off (custom roles, e-invoicing, repairs) or plumbing that is already half-laid (queue, translations, service worker).
13 — Appendix

Where everything lives

The repository layout behind this document, the counting rules for the numbers used throughout, and a glossary of the domain terms that jewellery retail uses differently from generic e-commerce.

📂Repository layout

app/
  Console/Commands/     install-admin, backup
  Http/Controllers/     47
  Http/Middleware/       SecurityHeaders, ResolveTenant, …
  Models/               39
  Support/
    Auth/               Permission, Role
    Billing/ Inventory/ Rfid/ Parties/
    Reports/ Tenancy/ Backup/ Audit/ Dashboard/
database/migrations/   48
resources/views/       143 Blade views
routes/                web, auth, api, console
tests/Feature/         732 tests · 3,103 assertions
docs/                  REQUIREMENTS.md (52 sections)

∑Counting rules

  • 52 sections — 3+5+5+5+6+4+4+3+4+3+3+2+5 across 13 modules
  • 203 endpoints — 184 web + 13 auth + 6 API
  • 46 tables — business tables only; framework cache/jobs/sessions excluded
  • 33 permissions — enum cases in Permission.php
  • 732 tests / 3,103 assertions — full suite, green at time of writing
  • 2,094 __() call sites — translation-ready, no lang/ files yet

Source of truth: docs/REQUIREMENTS.md v1.3, reviewed 2026-09-30.

TermWhat it means in this system
TenantOne business (a shop or group). Every owned row carries tenant_id; the resolver picks it from path, domain, session or signed-in user.
BranchAn outlet inside a tenant, with its own invoice prefixes and counters. A separate axis from tenant, so group reporting falls out of the schema.
Counter sessionA shift: opened with a float, closed against counted cash. A bill cannot exist outside one.
Metal rateEffective-dated price per metal and purity. Locked into a bill at creation; history is append-only.
Purity / fineness22K, 18K… as an enum with numeric fineness as data, so valuation adjusts for purity rather than assuming pure metal.
Making & wastageLabour percentage and wastage percentage applied to gold value — the two numbers that make a jewellery bill different from a retail bill.
RFID tagA UHF EPC bound to one product variant, with a lifecycle: active → lost / retired → reissued. History is kept across every rebind.
Scan sessionA timed read against a manifest: every read stored verbatim, unmatched reads flagged for review rather than accepted.
Credit noteA return written against the bill it reverses — stock comes back out and the account is corrected.
Metal bookingA rate-lock commitment with a supplier: create → settle → cancel, settling once.
Held billA paused cart stored as items; re-priced against the current rate on resume.
GSTIN / HSNState-coded tax identity and classification code; drives GSTR-1 and GSTR-3B bucketing by rate.
The document obeys the product's rules. Self-hosted fonts from public/fonts/, the supplied logo and favicon from this folder, and no CDN, tracker or external request of any kind. Open the network tab — it stays empty apart from this file and its own assets.