eBay-Style Marketplace Backend

Service Design Specification

ebaycclone-adminmoderation-service documentation -Version:1.0.0

Scope

This document provides a structured architectural overview of the adminModeration microservice, detailing its configuration, data model, authorization logic, business rules, and API design. It has been automatically generated based on the service definition within Mindbricks, ensuring that the information reflects the source of truth used during code generation and deployment.

The document is intended to serve multiple audiences:

  • Service architects can use it to validate design decisions and ensure alignment with broader architectural goals.
  • Developers and maintainers will find it useful for understanding the structure and behavior of the service, facilitating easier debugging, feature extension, and integration with other systems.
  • Stakeholders and reviewers can use it to gain a clear understanding of the service's capabilities and domain logic.

Note for Frontend Developers: While this document is valuable for understanding business logic and data interactions, please refer to the Service API Documentation for endpoint-level specifications and integration details.

Note for Backend Developers: Since the code for this service is automatically generated by Mindbricks, you typically won't need to implement or modify it manually. However, this document is especially valuable when you're building other services—whether within Mindbricks or externally—that need to interact with or depend on this service. It provides a clear reference to the service's data contracts, business rules, and API structure, helping ensure compatibility and correct integration.

AdminModeration Service Settings Edit

Administrative backend service for moderation and manual override actions. Responsible for logging all admin interventions (user/product/feedback/media/category/order/notification/searchindex moderation), triggering corrections via interservice calls, and providing comprehensive audit trails for compliance.

Service Overview

This service is configured to listen for HTTP requests on port 3006, serving both the main API interface and default administrative endpoints.

The following routes are available by default:

  • API Test Interface (API Face): /
  • Swagger Documentation: /swagger
  • Postman Collection Download: /getPostmanCollection
  • Health Checks: /health and /admin/health
  • Current Session Info: /currentuser
  • Favicon: /favicon.ico

The service uses a PostgreSQL database for data storage, with the database name set to ebaycclone-adminmoderation-service.

This service is accessible via the following environment-specific URLs:

  • Preview: https://ebaycclone.prw.mindbricks.com/adminmoderation-api
  • Staging: https://ebaycclone-stage.mindbricks.co/adminmoderation-api
  • Production: https://ebaycclone.mindbricks.co/adminmoderation-api

Authentication & Security

  • Login Required: Yes

This service requires user authentication for access. It supports both JWT and RSA-based authentication mechanisms, ensuring secure user sessions and data integrity. If a crud route also is configured to require login, it will check a valid JWT token in the request query/header/bearer/cookie. If the token is valid, it will extract the user information from the token and make the fetched session data available in the request context.

Service Data Objects

The service uses a PostgreSQL database for data storage, with the database name set to ebaycclone-adminmoderation-service.

Data deletion is managed using a soft delete strategy. Instead of removing records from the database, they are flagged as inactive by setting the isActive field to false.

Object Name Description Public Access
moderationAction Audit record for all admin moderation/override actions affecting core business entities. Links to admin, timestamp, entity type/ID, action performed, and reason. accessProtected

moderationAction Data Object

Object Overview

Description: Audit record for all admin moderation/override actions affecting core business entities. Links to admin, timestamp, entity type/ID, action performed, and reason.

This object represents a core data structure within the service and acts as the blueprint for database interaction, API generation, and business logic enforcement. It is defined using the ObjectSettings pattern, which governs its behavior, access control, caching strategy, and integration points with other systems such as Stripe and Redis.

Core Configuration

  • Soft Delete: Enabled — Determines whether records are marked inactive (isActive = false) instead of being physically deleted.
  • Public Access: accessProtected — If enabled, anonymous users may access this object’s data depending on API-level rules.

Composite Indexes

  • moderation_admin_entity: [adminId, entityType, entityId] This composite index is defined to optimize query performance for complex queries involving multiple fields.

The index also defines a conflict resolution strategy for duplicate key violations.

When a new record would violate this composite index, the following action will be taken:

On Duplicate: doInsert

The new record will be inserted without checking for duplicates. This means that the composite index is designed for search purposes only.

Properties Schema

Property Type Required Description
adminId ID Yes ID of admin performing moderation action.
entityId ID Yes ID of target entity affected by moderation (user/product/etc).
actionTimestamp Date Yes Timestamp moderation action was performed/logged.
entityType Enum Yes Type of entity affected (USER, PRODUCT, FEEDBACK, MEDIA, CATEGORY, NOTIFICATION, ORDER, SEARCHINDEX).
reason String Yes Explanation or justification for the moderation action performed.
actionType Enum Yes Type of moderation action (e.g., SOFT_DELETE, RESTORE, UPDATE_ROLE, MANUAL_CORRECTION, MEDIA_FLAG, INDEX_REBUILD, PAYMENT_FIX, FEEDBACK_OVERRIDE, ADMIN_NOTE).
  • Required properties are mandatory for creating objects and must be provided in the request body if no default value is set.

Default Values

Default values are automatically assigned to properties when a new object is created, if no value is provided in the request body. Since default values are applied on db level, they should be literal values, not expressions.If you want to use expressions, you can use transposed parameters in any business API to set default values dynamically.

  • adminId: '00000000-0000-0000-0000-000000000000'
  • entityId: '00000000-0000-0000-0000-000000000000'
  • actionTimestamp: new Date()
  • entityType: "USER"
  • reason: 'default'
  • actionType: "SOFT_DELETE"

Constant Properties

adminId entityId actionTimestamp entityType actionType

Constant properties are defined to be immutable after creation, meaning they cannot be updated or changed once set. They are typically used for properties that should remain constant throughout the object's lifecycle. A property is set to be constant if the Allow Update option is set to false.

Auto Update Properties

reason

An update crud API created with the option Auto Params enabled will automatically update these properties with the provided values in the request body. If you want to update any property in your own business logic not by user input, you can set the Allow Auto Update option to false. These properties will be added to the update API's body parameters and can be updated by the user if any value is provided in the request body.

Enum Properties

Enum properties are defined with a set of allowed values, ensuring that only valid options can be assigned to them. The enum options value will be stored as strings in the database, but when a data object is created an addtional property with the same name plus an idx suffix will be created, which will hold the index of the selected enum option. You can use the index property to sort by the enum value or when your enum options represent a sequence of values.

  • entityType: [USER, PRODUCT, FEEDBACK, MEDIA, CATEGORY, NOTIFICATION, ORDER, SEARCHINDEX]

  • actionType: [SOFT_DELETE, RESTORE, UPDATE_ROLE, MANUAL_CORRECTION, MEDIA_FLAG, INDEX_REBUILD, PAYMENT_FIX, FEEDBACK_OVERRIDE, ADMIN_NOTE]

Elastic Search Indexing

adminId entityId actionTimestamp entityType reason actionType

Properties that are indexed in Elastic Search will be searchable via the Elastic Search API. While all properties are stored in the elastic search index of the data object, only those marked for Elastic Search indexing will be available for search queries.

Database Indexing

adminId entityId entityType actionType

Properties that are indexed in the database will be optimized for query performance, allowing for faster data retrieval. Make a property indexed in the database if you want to use it frequently in query filters or sorting.

Relation Properties

adminId

Mindbricks supports relations between data objects, allowing you to define how objects are linked together. You can define relations in the data object properties, which will be used to create foreign key constraints in the database. For complex joins operations, Mindbricks supportsa BFF pattern, where you can view dynamic and static views based on Elastic Search Indexes. Use db level relations for simple one-to-one or one-to-many relationships, and use BFF views for complex joins that require multiple data objects to be joined together.

  • adminId: ID Relation to user.id

The target object is a parent object, meaning that the relation is a one-to-many relationship from target to this object.

On Delete: Set Null Required: Yes

Session Data Properties

adminId

Session data properties are used to store data that is specific to the user session, allowing for personalized experiences and temporary data storage. If a property is configured as session data, it will be automatically mapped to the related field in the user session during CRUD operations. Note that session data properties can not be mutated by the user, but only by the system.

  • adminId: ID property will be mapped to the session parameter userId.

Formula Properties

actionTimestamp

Formula properties are used to define calculated fields that derive their values from other properties or external data. These properties are automatically calculated based on the defined formula and can be used for dynamic data retrieval.

  • actionTimestamp: Date
    • Formula: Date.now()

    • Calculate After Instance: No

Business Logic

adminModeration has got 5 Business APIs to manage its internal and crud logic. For the details of each business API refer to its chapter.

Edge Controllers

rebuildSearchIndex

Configuration:

  • Function Name: rebuildSearchIndex
  • Login Required: Yes

REST Settings:

  • Path: /rebuild-search-index
  • Method:

fixPaymentRecord

Configuration:

  • Function Name: fixPaymentRecord
  • Login Required: Yes

REST Settings:

  • Path: /fix-payment-record
  • Method:

overrideFeedback

Configuration:

  • Function Name: overrideFeedback
  • Login Required: Yes

REST Settings:

  • Path: /override-feedback
  • Method:

flagMediaAsset

Configuration:

  • Function Name: flagMediaAsset
  • Login Required: Yes

REST Settings:

  • Path: /flag-media-asset
  • Method:

restoreSoftDeletedEntity

Configuration:

  • Function Name: restoreSoftDeletedEntity
  • Login Required: Yes

REST Settings:

  • Path: /restore-soft-deleted-entity
  • Method:


Service Library

Functions

No general functions defined.

Hook Functions

No hook functions defined.

Edge Functions

rebuildSearchIndex.js

module.exports = async (request, {LIB, context}) => { /* Only for admins; triggers a search index rebuild/correction via the searchIndexing microservice. Records a moderationAction. */
  const session = request.session;
  if (!session || session.roleId !== 'admin') throw {status:403,message:'Forbidden'};
  // Rebuild search index by calling searchIndexing:listSearchIndexes + create/update as needed (simulating event trigger)
  // (In practice: publish event or call BFF to orchestrate)
  // Here, just log an audit entry:
  await LIB.createModerationAction({
    adminId: session.userId,
    entityType: 'SEARCHINDEX',
    entityId: 'ALL',
    actionType: 'INDEX_REBUILD',
    reason: request.body?.reason || 'Manual search index rebuild',
    actionTimestamp: new Date().toISOString()
  });
  return {status:200,message:'Triggered search index rebuild & logged action.'};
}

fixPaymentRecord.js

module.exports = async (request, {LIB, context}) => {
  // Only admins can invoke. Fixes payment (order) record in orderManagement.
  const session = request.session;
  if (!session || session.roleId !== 'admin') throw {status:403,message:'Forbidden'};
  const {orderId, fixParams, reason} = request.body;
  // Call orderManagement:updateOrderManagementOrderStatus via interservice call (not implemented in this stub)
  // Log moderationAction:
  await LIB.createModerationAction({
    adminId: session.userId,
    entityType: 'ORDER',
    entityId: orderId,
    actionType: 'PAYMENT_FIX',
    reason: reason || 'Manual payment status correction',
    actionTimestamp: new Date().toISOString()
  });
  return {status:200,message:'Order payment correction logged. (See audit trail)'};
}

overrideFeedback.js

module.exports = async (request, {LIB, context}) => {
  // Only admins; manually override feedback for order item
  const session = request.session;
  if (!session || session.roleId !== 'admin') throw {status:403,message:'Forbidden'};
  const {feedbackId, updateParams, reason} = request.body;
  // Call feedback:updateFeedback via interservice call (not implemented in this stub)
  await LIB.createModerationAction({
    adminId: session.userId,
    entityType: 'FEEDBACK',
    entityId: feedbackId,
    actionType: 'FEEDBACK_OVERRIDE',
    reason: reason || 'Feedback manually corrected by admin',
    actionTimestamp: new Date().toISOString()
  });
  return {status:200,message:'Feedback override performed & logged.'};
}

flagMediaAsset.js

module.exports = async (request, {LIB, context}) => {
  // Admin flags a media asset for review or removal
  const session = request.session;
  if (!session || session.roleId !== 'admin') throw {status:403,message:'Forbidden'};
  const {mediaAssetId, reason} = request.body;
  // Call productListing:deleteProductListingMedia (not implemented in this stub)
  await LIB.createModerationAction({
    adminId: session.userId,
    entityType: 'MEDIA',
    entityId: mediaAssetId,
    actionType: 'MEDIA_FLAG',
    reason: reason || 'Media flagged & removed by admin',
    actionTimestamp: new Date().toISOString()
  });
  return {status:200,message:'Media asset flagged/removed and moderation action logged.'};
}

restoreSoftDeletedEntity.js

module.exports = async (request, {LIB, context}) => {
  // Only admins; restores a soft-deleted entity (user/product/feedback/etc.)
  const session = request.session;
  if (!session || session.roleId !== 'admin') throw {status:403,message:'Forbidden'};
  const {entityType, entityId, reason} = request.body;
  // Would call appropriate service restore API
  await LIB.createModerationAction({
    adminId: session.userId,
    entityType,
    entityId,
    actionType: 'RESTORE',
    reason: reason || 'Entity manually restored by admin',
    actionTimestamp: new Date().toISOString()
  });
  return {status:200,message:'Entity restore triggered and audit logged.'};
}

Templates

No templates defined.

Assets

No assets defined.

Public Assets

No public assets defined.


Event Emission


Integration Patterns

Deployment Considerations

Environment Configuration

  • HTTP Port: 3006
  • Database Type: MongoDB
  • Global Soft Delete: Enabled

Implementation Guidelines

Development Workflow

  1. Data Model Implementation: Generate database schema from data object definitions
  2. CRUD Route Generation: Implement auto-generated routes with custom logic
  3. Custom Logic Integration: Implement hook functions and edge functions
  4. Authentication Integration: Configure with project-level authentication
  5. Testing: Unit and integration testing for all components

Code Generation Expectations

  • Database Schema: Auto-generated from data objects and relationships
  • API Routes: REST endpoints with customizable behavior
  • Validation Logic: Input validation from property definitions
  • Access Control: Authentication and authorization middleware

Custom Code Integration Points

  • Hook Functions: Lifecycle-specific custom logic
  • Edge Functions: Full request/response control
  • Library Functions: Reusable business logic
  • Templates: Dynamic content rendering

Testing Strategy

Unit Testing

  • Test all custom library functions
  • Test validation logic and business rules
  • Test hook function implementations

Integration Testing

  • Test API endpoints with authentication scenarios
  • Test database operations and transactions
  • Test external integrations
  • Test event emission and Kafka integration

Performance Testing

  • Load test high-traffic endpoints
  • Test caching effectiveness
  • Monitor database query performance
  • Test scalability under load

Appendices

Data Type Reference

Type Description Storage
ID Unique identifier UUID (SQL) / ObjectID (NoSQL)
String Short text (≤255 chars) VARCHAR
Text Long-form text TEXT
Integer 32-bit whole numbers INT
Boolean True/false values BOOLEAN
Double 64-bit floating point DOUBLE
Float 32-bit floating point FLOAT
Short 16-bit integers SMALLINT
Object JSON object JSONB (PostgreSQL) / Object (MongoDB)
Date ISO 8601 timestamp TIMESTAMP
Enum Fixed numeric values SMALLINT with lookup

Enum Value Mappings

Request Locations

  • 0: Bearer token in Authorization header
  • 1: Cookie value
  • 2: Custom HTTP header
  • 3: Query parameter
  • 4: Request body property
  • 5: URL path parameter
  • 6: Session data
  • 7: Root request object

HTTP Methods

  • 0: GET
  • 1: POST
  • 2: PUT
  • 3: PATCH
  • 4: DELETE

Edge Function Signature

async function edgeFunction(request) {
  // Custom request processing
  // Return response object or throw error
  return {
    data: {},
    status: 200,
    message: "Success"
  };
}

This document was generated from the service architecture definition and should be kept in sync with implementation changes.