Shopora - Flutter E-Commerce App + Laravel Filament Admin
Key Features
- Flutter 3.x mobile app — home, products, cart, checkout, profile, orders, reviews
- Laravel 13 + Filament 4 admin panel with dashboard, charts, and bulk actions
- PostaLynk transactional mail — custom Symfony Mailer transport, no SMTP
- Supoora live chat on web (script tag) and mobile (SupooraChatWidget)
- Zauthy auth: email + password, MFA (TOTP), magic link, OTP, OAuth (Google + Apple) with PKCE
- Zauthy KYC: document OCR, face match, liveness, sanctions screening, location verification
- 14 migrations, 7 seeders — realistic catalog with images, variants, customers, orders, reviews
- Hardened by 3 rounds of paranoid review (order recalc, replay protection, case-insensitive uniqueness, cycle prevention, leak-safe 502s)
- Throttle middleware on every unauthenticated API endpoint (10/min for auth, 30/min for KYC, 60/min for token ops)
- Webhook replay protection with 24h dedupe window
- Signed mail-handoff webhook — Zauthy renders auth emails, we deliver them via PostaLynk so they come from your verified domain
- Beautiful live-status setup docs at `/setup` — reads your .env and tells you what's wired
- SQLite-by-default, MySQL/Postgres-ready
- Soft deletes on Product / Customer / Order; address + image invariants enforced at the model layer
Customization Available
Need this product tailored to your brand or requirements? We offer custom modifications — reach out and let us know what you need.
Shopora
A complete, production-ready e-commerce starter built as a Flutter mobile app paired with a Laravel 13 + Filament 4 admin backend. Ships day one with PostaLynk (transactional mail), Supoora (live chat), and Zauthy (auth + KYC) wired and documented — no SMTP, no auth boilerplate, no support widget to build.
What you get
- Flutter storefront — home, search, categories, product detail, cart, checkout, profile, orders, reviews.
- Laravel 13 + Filament 4 admin — full CRUD for products, categories, customers, orders, coupons, reviews; relation managers; bulk actions; dashboard with revenue chart, stat overview, and latest orders.
- 14 migrations + 7 seeders — categories, products, product_images, product_variants, customers, addresses, carts, cart_items, orders, order_items, reviews, coupons, wishlists, wishlist_items.
- PostaLynk mail transport — custom Symfony Mailer transport class. Set one env var and every
Mail::send()ships via PostaLynk. - Supoora live chat — drop-in widget for the marketing site,
SupooraChatWidgetfor the Flutter app, runtime config endpoint so you can rotate embed keys without re-publishing. - Zauthy auth + KYC — full REST wrapper, customer auth API (signup, login, MFA, magic link, OAuth + PKCE, password reset), KYC session lifecycle, signed event webhook with replay protection, signed mail-handoff webhook.
- Setup docs page at
/setup— beautiful, live-status HTML guide that reads your current.envand tells you which integrations are wired and which still need keys.
Domain model
Products have categories, images, variants (size × color), tags, and stock tracking. Orders snapshot product + address state so legacy orders survive product deletion. Customers have multiple addresses with a single-default-per-type invariant. Reviews auto-update product average_rating and reviews_count on save/delete. Coupons support percent / fixed / free_shipping with min-order, max-cap, usage limits, and date windows. Wishlists support multiple lists per customer.
Hardened by paranoid review
Every release goes through three rounds of paranoid review. We've already shipped fixes for: order total recalc cascade, single-default address enforcement, primary-image enforcement, coupon case-insensitive uniqueness, category cycle prevention, PostaLynk body-rewind on consumed streams, Zauthy webhook replay protection, sanitized 502 errors that won't leak internal hostnames, throttle middleware on all unauthenticated API entry points, and UTF-8-safe name splitting on customer provisioning.
What's NOT in the box
- No SMTP fallback. By design — PostaLynk is the mail path. If PostaLynk is down, your transactional mail is queued (Laravel queue) and retried, not rerouted to SMTP.
- No social-network features (follow/like/feed). This is a shop, not a feed.
- No multi-vendor / marketplace mode. Single-vendor only.
Stack
- Frontend (mobile): Flutter 3.x, Material 3.
- Backend: PHP 8.3+, Laravel 13, Filament 4.
- DB: SQLite out of the box; MySQL / Postgres supported.
- Mail: PostaLynk HTTP API (custom transport class).
- Chat: Supoora (
widget.json web,supoora_sdk: ^1.0.2on Flutter). - Auth/KYC: Zauthy (server proxy + Flutter SDK).
License
Regular license: install on one production domain + unlimited staging. Extended license: install on one production domain for an end product you sell to one client (per FoundrCode standard terms).