VET Car Rental API
Delivered a centralized backend service handling the complete lifecycle of car rental transactions, from discovery to ABA PayWay-integrated payment processing.
Business Context
The rental operations required a robust, scalable backend to unify customer-facing vehicle booking, automated payment callbacks, and fine-grained administrative controls over fleet inventory.
The Solution
A Spring Boot REST API featuring a dual datasource architecture, Spring Security with custom AOP permission enforcement, and Resilience4j circuit breakers.
- Full sale order lifecycle management (Draft → Completed)
- Fine-grained AOP-driven permission system
- ABA PayWay webhook integration for asynchronous payment confirmation
- Automated daily background schedulers for order auto-expiry
Architecture Overview
The architecture separates concerns into a Public API layer, an Admin API layer, and a core Service layer. An AOP Permission Aspect intercepts requests to enforce fine-grained access control before reaching the controllers.
Tech Stack & Reasoning
| Technology | Why it was used |
|---|---|
| Spring Boot & Spring Security | Provides a robust, enterprise-grade framework for REST APIs with built-in JWT authentication capabilities. |
| jOOQ | Ensures type-safe SQL query building, offering superior performance and developer experience over traditional ORMs for complex queries. |
| Resilience4j | Wraps external calls to the ABA PayWay API with a circuit breaker, preventing gateway outages from cascading into order failures. |
| Flyway | Automates database schema versioning and migrations for reliable multi-environment deployments. |
Key Features
- Real-time KPI dashboard and comprehensive reporting
- Fine-grained permissions with module/action scoping
- ABA PayWay integration with Resilience4j circuit breaker
- Global unhandled exception alerting via Telegram Bot API
Engineering Highlights
Engineered an AOP Permission Aspect (`@RequirePermission`) that intercepts administrative endpoints to enforce fine-grained access control without polluting controller logic.
Implemented a Dual DataSource Architecture to seamlessly integrate primary application data with external partner logistics data.
Built a Global Exception Handler that automatically fires alerts to a Telegram Bot on unhandled 500 errors, enabling instant incident awareness.
Challenges & Solutions
Payment gateway outages could cascade and cause failures in the core order management system.
Wrapped external ABA PayWay API calls with a Resilience4j circuit breaker configured with a 50% failure rate threshold.
Impact: Prevented external API failures from impacting the performance and stability of the primary rental platform.
Performance Metrics
What I Learned
- •Designing fine-grained AOP-driven authorization systems
- •Implementing circuit breaker patterns for resilient third-party integrations
- •Configuring dual MySQL datasources in a single Spring Boot application
System Interface

Want to see more projects?
Explore my other recent work to see a broader range of system architectures and full-stack solutions.
