Skip to content
SHIVSASTRA
QE-AI2025Product Engineering · Application SecurityOct 20, 2025

QuickEats

AI-assisted product engineering and application security system. Highlights include server-side price recalculation, ownership validation, JWT refresh-token rotation, real-time STOMP order updates, and conversational AI assistance. Verified with 71 executable @Test methods across 23 backend test classes.

QuickEats
Technologies
Product EngineeringApplication SecuritySpring Boot 3WebSocketsGroq Llama 3PostgreSQL
Engineering Deep Dive & Architecture

Overview

QuickEats is an ordering and delivery system engineered to solve critical application security and real-time state synchronization challenges in food delivery.

Key Engineering Lessons & Security Mechanisms

  • Server-Side Price Recalculation: The order service strictly ignores client-supplied item prices. Total amounts are calculated exclusively on the server by looking up authoritative database prices, preventing cart tampering attacks.
  • Ownership & IDOR Validation: Strict entity-level ownership validation guarantees that customers can only view, modify, or track orders tied to their authenticated account.
  • JWT Authentication & Refresh Token Rotation: Implements stateless short-lived JWT access tokens paired with database-backed refresh token rotation and revocation.
  • Real-Time Order Updates: Bi-directional STOMP WebSockets over SockJS broadcast order lifecycle progression (PENDING ➔ PREPARING ➔ OUT_FOR_DELIVERY ➔ DELIVERED) and live simulated delivery coordinates.
  • Conversational AI Assistance: Groq API (Llama 3) powers conversational food recommendations and customer support grounded in verified order context.
  • Verified Automated Test Suite: Backed by 71 executable @Test methods across 23 backend test classes covering security controls, price recalculation logic, IDOR protections, and database transactions.

Architecture

  • Backend: Spring Boot 3.2.3, Java 17, Spring Security 6, JJWT
  • Persistence: PostgreSQL, MySQL 8, and Hibernate ORM
  • Real-Time: Spring WebSocket with STOMP and SockJS
  • AI Integration: Groq API (Llama 3) for contextual menu assistance

Questions about this project?

Feel free to reach out if you'd like to talk about the tech stack, implementation, or a similar project.

Get in Touch →