NexBank is a full-stack, enterprise-grade Core Banking application engineered with Domain-Driven Design (DDD) principles and Event-Driven Architecture. It simulates a real-world digital banking environment, focusing heavily on Data Integrity, Concurrency Management, and High Security.
This project isn't just a simple CRUD application; it addresses complex financial engineering problems such as Double Spending prevention, Idempotent transactions, and Distributed Locking.
- Distributed Locking with Redis: Prevents "Double Spending" and race conditions. If two rapid requests try to transfer money from the same account at the exact same millisecond, Redis
SETNX(Set if Not Exists) atomically locks the account, rejecting the second request instantly. - Idempotency (Eşetkisellik): Network glitched and the user clicked "Send" twice? No problem. Every transfer requires a unique UUID
idempotencyKey. The backend ensures the same transaction is never executed twice, even if the request is duplicated. - ACID Transactions (
@Transactional): If money is deducted from Account A, but an error occurs before adding it to Account B (e.g., database failure), the entire transaction is rolled back. No money is ever lost in the void.
- Event-Driven Modularity: Modules are completely decoupled using Spring's
ApplicationEventPublisher. For example, theAtmControllerdoesn't know theNotificationServiceexists. It simply shouts"ATM_DEPOSIT_EVENT", and the Notification system listens asynchronously. (Open/Closed Principle). - Redis In-Memory Caching: Account balances—the most frequently accessed data in banking—are cached in Redis to dramatically reduce PostgreSQL database load and improve response times to sub-milliseconds.
- MongoDB NoSQL Document Storage: Financial transaction histories and high-volume logs are offloaded to MongoDB. This ensures the primary PostgreSQL database remains highly optimized and focused strictly on core relational operations.
- Stateless JWT Architecture: No sessions are stored on the server. Every request is verified via a cryptographically signed JSON Web Token (JWT), intercepted by a custom
JwtAuthenticationFilter. - Rate Limiting (Anti-Brute-Force): Implemented using
Bucket4j. Prevents automated password guessing or API spamming by limiting requests (e.g., max 5 login attempts per minute per IP). - BCrypt Hashing: Passwords are never stored in plain text. A strength-12 BCrypt algorithm ensures mathematically unbreakable password hashes.
- Glassmorphism & Micro-animations: A highly premium, TailwindCSS-powered user interface that feels alive.
- Real-time Analytics: Integrated
Chart.jsfor dynamic pie charts and bar charts on the Dashboard, giving administrators and users instant insights into their finances. - RxJS Reactive Programming: Advanced state management and HTTP request handling using
BehaviorSubjectandObservablesfor a seamless, SPA (Single Page Application) experience.
Backend:
- Java 21, Spring Boot 3 (Web, Data JPA, Security)
- PostgreSQL (Primary Relational Database)
- MongoDB (NoSQL Storage for Transaction History & Logs)
- Redis (Caching & Distributed Locking)
- Bucket4j (Rate Limiting)
- JWT (io.jsonwebtoken)
Frontend:
- Angular 18 (Standalone Components, RxJS)
- Tailwind CSS (Styling & Animations)
- Chart.js (Data Visualization)
DevOps & Infrastructure:
- Docker & Docker Compose (Containerization of DBs and Backend)
- Maven & NPM
Running the entire banking infrastructure is incredibly simple thanks to Docker.
- Docker & Docker Compose installed.
- Node.js (v18+) and Angular CLI installed.
Navigate to the root directory and start the databases (PostgreSQL, Redis, MongoDB) and the Spring Boot backend container.
docker-compose up --build -dThe backend will be available at http://localhost:8080.
Open a new terminal, navigate to the frontend folder, install dependencies, and run the development server.
cd Front
npm install
npm startThe web application will be available at http://localhost:4200.
- Admin Account (Auto-seeded):
- Username:
admin - Password:
admin
- Username:
- Or simply register a new customer account from the login screen!
@RestController,@RequestMapping: Exposes our domain endpoints to the internet.@Transactional: The guardian of our financial logic. Ensures operations either fully complete or fully rollback.@RequiredArgsConstructor: Clean Dependency Injection via constructors (Lombok).@EventListener: Powers our loosely coupled, event-driven architecture.@RestControllerAdvice: Intercepts unhandledRuntimeExceptionsglobally and formats them into clean JSON400 Bad Requestresponses for the frontend.
Developed with an emphasis on Enterprise Software Engineering best practices.