Run on Windows:
- Install Node.js LTS.
- Extract this folder.
- Open Terminal in the folder.
- Run
npm install - Copy
.env.exampleto.envand change the secret/password. - Run
npm start - Open http://localhost:3000
Includes Node/Express, SQLite database, bcrypt password hashing, JWT httpOnly login cookies, customer registration/login, product database, stock control, real order records, COD checkout and admin dashboard.
Real bKash/Nagad/card payment is intentionally not activated: it requires merchant credentials, server-side verification and webhooks. Production also needs HTTPS, secure cookies, rate limiting, CSRF protection, validation, backups and a production database.
- Seller registration and seller dashboard
- Sellers can add/delete their own products
- Product ownership stored with seller_id
- Admin order management
- Admin can change order status: Pending, Confirmed, Shipped, Delivered, Cancelled
- Customer order records include order items
- Admin dashboard shows users, sellers, products, orders and sales
- Seller order view
After replacing an older version, run npm install and npm start again. The server automatically adds the seller_id column if it is missing in an existing database.
- Real product image upload (JPG/PNG/WEBP/GIF, max 5MB)
- Product detail pages
- Customer profile and order history
- Wishlist
- Product reviews and 1–5 star ratings
- Rating/review counts on product cards
- Seller image uploads
- Local image storage in
public/uploads
- Exact V3 homepage retained.
- Checkout flow.
- Cash on Delivery.
- bKash/Nagad manual transaction-ID capture and storage.
- Stock validation and order creation.
- Card option marked unavailable until a real gateway is configured.
Real bKash/Nagad API payments require merchant credentials, server verification, callbacks/webhooks and HTTPS.