Ownify is a modern web application that enables users to register, log in, add and list products, manage wishlists, and communicate via messaging. The backend is built with Spring Boot, while the frontend uses static HTML, CSS, and JavaScript files for a responsive and user-friendly experience.
- User Authentication: Register, log in, and log out securely.
- Product Management: Add, view, and list products with category filtering.
- Wishlist: Add products to a personal wishlist for easy access later.
- Messaging: Communicate with other users via a built-in messaging system.
- Dashboard: Personalized dashboard for managing your products and settings.
- Static Pages: About Us, FAQs, Customer Support, and more.
- Responsive Design: Modern UI with static resources.
Ownify/
├── README.md
├── .gitignore
└── ownify/ # Spring Boot application (Maven project)
├── src/
│ ├── main/
│ │ ├── java/com/ownify/
│ │ │ ├── Controller/ # Controllers for web/API endpoints
│ │ │ ├── Entity/ # JPA Entities
│ │ │ ├── Model/ # Data models (e.g., for messaging)
│ │ │ ├── Repository/ # Spring Data JPA repositories
│ │ │ ├── Service/ # Business logic services
│ │ │ └── config/ # Configuration classes (security, CORS, etc.)
│ │ └── resources/
│ │ ├── static/ # Static files (index.html, CSS, JS, images)
│ │ └── application.properties # App configuration
│ └── test/ # Test files
├── pom.xml # Maven dependencies
└── mvnw, mvnw.cmd # Maven wrapper
- Java 17 or higher
- Maven 3.6+
- (Optional) An IDE such as IntelliJ IDEA, Eclipse, or VS Code
- Clone the Repository
git clone https://github.com/melikeisil/Ownify.git
cd Ownify/ownify
-
Set environment variables (see Environment Variables)
export DB_PASSWORD='<choose-a-database-password>' export ADMIN_PASSWORD='<choose-an-admin-password>'On Windows (PowerShell):
$env:DB_PASSWORD='...'. You can also keep them in a local.envfile for your IDE/run configuration;.envis ignored by git and must never be committed. -
Build the Project
mvn clean install(or
./mvnw clean installwithout a local Maven installation) -
Run the Application
mvn spring-boot:runOr run
Application.javafrom your IDE with the same environment variables. -
Access the Application
- Homepage: http://localhost:8080/
- Login/Register:
/signin,/signup - Dashboard:
/dashboard - Wishlist:
/wishlist - Shop:
/shop - About:
/about - FAQs:
/faqs - Customer Support:
/customer-support
- Register a new user or log in with existing credentials.
- Add products from the dashboard and view them in the shop.
- Add products to your wishlist for quick access.
- Send and receive messages with other users.
- Navigate through static pages for more information.
- Backend: Spring Boot, Spring MVC, Spring Security, H2 Database
- Frontend: HTML, CSS, JavaScript (static files)
- Build Tool: Maven
- Database:
- The application uses a file-based H2 database (
jdbc:h2:file:./ownifydb), not an in-memory one. Data persists between restarts inownifydb.mv.dbin the working directory you start the app from (for exampleownify/when usingmvn spring-boot:run). - Database files (
*.mv.db,*.trace.db) are local only and ignored by git. - If you already have a local
ownifydb.mv.dbcreated with a different password, either setDB_PASSWORDto that password or delete the file so a fresh database is created. - The H2 web console is disabled by default. For local debugging only, start with
H2_CONSOLE_ENABLED=true(it is served at/h2-console). - You can change database settings in
ownify/src/main/resources/application.properties.
- The application uses a file-based H2 database (
- Static Files:
- All static resources (HTML, CSS, JS) are located in
src/main/resources/static/.
- All static resources (HTML, CSS, JS) are located in
- Port:
- The default port is
8080. You can change it inapplication.properties.
- The default port is
No passwords are stored in application.properties; they are read from the environment.
| Variable | Required | Default | Description |
|---|---|---|---|
DB_USERNAME |
No | sa |
H2 datasource username |
DB_PASSWORD |
Yes* | (empty) | H2 datasource password |
ADMIN_USERNAME |
No | admin |
Spring Security built-in user name |
ADMIN_PASSWORD |
Yes* | (empty) | Spring Security built-in user password; if unset, Spring Boot generates a random one at startup |
H2_CONSOLE_ENABLED |
No | false |
Enables the H2 console at /h2-console (local debugging only) |
* The application starts without them, but you should always set them outside of throwaway local runs.
GET /api/products— List all productsGET /api/categories— List all categoriesPOST /api/products— Add a new productGET /api/products/{id}— Get product detailsPOST /api/users— User registration (JSON:firstName,lastName,email,password)POST /api/login— User login (JSON:email,password; starts a session)GET /api/users/{id}— Get your own user record (requires login; only your ownid)PUT /api/users/{id}— Update your own user record (requires login; only your ownid)GET /api/users/check-email?email=...— Check whether an email is already registered
Password hashes are never included in API responses.
For more, see the controller classes in
ownify/src/main/java/com/ownify/Controller/.
Ownify is under active development. This is not a final release and has not yet been hardened for production use.
What is in place today
- Passwords are hashed with BCrypt and are never returned in API responses.
GET/PUT /api/users/{id}only allow access to your own record.- The session id is rotated on login.
- Public product responses only include the seller's id and name.
- Chat messages take the sender from the logged-in session and are rejected without one.
- Secrets are read from environment variables, and the H2 console is off by default.
Known limitations
SecurityConfigcurrently ends withanyRequest().permitAll(). Access control is done manually in controllers by checking theuserattribute in the HTTP session, and only where that check has been added.- CSRF protection is disabled on most paths, including
/api/**,/dashboard/**,/wishlist/**,/messaging/**,/loginand the WebSocket endpoints. - Session cookies are not marked secure (
server.servlet.session.cookie.secure=false) so the app works over plain HTTP locally.
Planned improvements
- Proper Spring Security authentication and authorization rules
- CSRF protection
- HTTPS with secure cookies
- A production-ready database
Contributions are welcome! To contribute:
- Fork the repository
- Create a new branch (
git checkout -b feature/your-feature) - Commit your changes (
git commit -am 'Add new feature') - Push to the branch (
git push origin feature/your-feature) - Open a pull request
No license has been chosen for this project yet, so all rights are reserved by the author.
If you want to allow reuse, add a LICENSE file (for example MIT or Apache-2.0) and update this section.
For questions, suggestions, or support, please open an issue or contact the maintainer.