SakkolDev
All projects
2026 · Backend Architect

VET Car Rental API

Delivered a centralized backend service handling the complete lifecycle of car rental transactions, from discovery to ABA PayWay-integrated payment processing.

JavaSpring BootSpring SecurityMySQLjOOQFlyway

Business Context

The rental operations required a robust, scalable backend to unify customer-facing vehicle booking, automated payment callbacks, and fine-grained administrative controls over fleet inventory.

The Solution

A Spring Boot REST API featuring a dual datasource architecture, Spring Security with custom AOP permission enforcement, and Resilience4j circuit breakers.

  • Full sale order lifecycle management (Draft → Completed)
  • Fine-grained AOP-driven permission system
  • ABA PayWay webhook integration for asynchronous payment confirmation
  • Automated daily background schedulers for order auto-expiry

Architecture Overview

The architecture separates concerns into a Public API layer, an Admin API layer, and a core Service layer. An AOP Permission Aspect intercepts requests to enforce fine-grained access control before reaching the controllers.

Spring Boot 3.3.3 & Spring Security
jOOQ (Type-safe SQL)
Flyway (Schema Migrations)
Resilience4j Circuit Breaker
Dual MySQL DataSources

Tech Stack & Reasoning

TechnologyWhy it was used
Spring Boot & Spring SecurityProvides a robust, enterprise-grade framework for REST APIs with built-in JWT authentication capabilities.
jOOQEnsures type-safe SQL query building, offering superior performance and developer experience over traditional ORMs for complex queries.
Resilience4jWraps external calls to the ABA PayWay API with a circuit breaker, preventing gateway outages from cascading into order failures.
FlywayAutomates database schema versioning and migrations for reliable multi-environment deployments.

Key Features

  • Real-time KPI dashboard and comprehensive reporting
  • Fine-grained permissions with module/action scoping
  • ABA PayWay integration with Resilience4j circuit breaker
  • Global unhandled exception alerting via Telegram Bot API

Engineering Highlights

Engineered an AOP Permission Aspect (`@RequirePermission`) that intercepts administrative endpoints to enforce fine-grained access control without polluting controller logic.

Implemented a Dual DataSource Architecture to seamlessly integrate primary application data with external partner logistics data.

Built a Global Exception Handler that automatically fires alerts to a Telegram Bot on unhandled 500 errors, enabling instant incident awareness.

Challenges & Solutions

Challenge

Payment gateway outages could cascade and cause failures in the core order management system.

Solution

Wrapped external ABA PayWay API calls with a Resilience4j circuit breaker configured with a 50% failure rate threshold.

Impact: Prevented external API failures from impacting the performance and stability of the primary rental platform.

Performance Metrics

MySQL 8.0Primary Database
17 LTSJava Version

What I Learned

  • •Designing fine-grained AOP-driven authorization systems
  • •Implementing circuit breaker patterns for resilient third-party integrations
  • •Configuring dual MySQL datasources in a single Spring Boot application

System Interface

VET Car Rental API — feature view