1. legacy
Itinera API
  • ✈ Itinera API Documentation
  • Docs
    • legacy
      • Itinera — System Overview
      • Technology Stack & Architecture
      • Getting Started Guide
      • Infrastructure
      • Frontend Application
      • Architecture Overview
      • API Reference
      • Backend Services
      • Development Guidelines
    • phases
      • 01. Architecture Overview & Checkout Idempotency
      • Phase 2: Commerce & Checkout Engine
      • Phase 3: Webhooks & Asynchronous Fulfillment
      • Phase 4: Security Perimeter & Authentication
      • Phase 5: Database Schema & Entity Relationships
      • Phase 6: AI Quota & Telemetry Subsystems
      • Phase 7: API Route Matrix & FormRequests
      • Phase 8: Global Exception & Error Handling
      • Phase 9: Frontend Ecosystem & State Management
      • Phase 10: Design System & Component Library
      • Phase 11: Interactive GSAP Animations
      • Phase 12: Deployment & CI/CD Pipeline
      • Phase 13: Testing Strategies
      • Phase 14: Performance & Optimization
      • Phase 15: Developer Onboarding & Runbooks
      • 15-Phase Comprehensive Wiki & Documentation Plan
  • APIs
    • Auth
      • Register a new user
      • Log in a user
      • Log out user
      • Refresh JWT token
      • Forgot password request
      • Reset password verification
      • Get current user profile
      • Update user profile
      • Redirect to Google OAuth
      • Google OAuth Callback
      • Verify email via signed URL
    • Catalog
      • List all countries
      • Get country details
      • List all cities
      • List all regions
      • List all destinations
      • Get destination details
      • Get hotels by destination
      • List all hotels
      • Get hotel details
      • Get reviews for a hotel
      • List all flights
      • Get flight details
      • List all restaurants
      • Get restaurant details
      • List all attractions
      • Get current weather
      • Submit review for an entity
      • Delete review
      • Toggle favourite status for entity
      • List my submitted reviews
    • Bookings
      • Book a tour destination
    • V1 Aliases
      • V1 List all countries
      • V1 Get country details
      • V1 List all cities
      • V1 List all destinations
      • V1 Get destination details
      • V1 Get hotels by destination
      • V1 List all hotels
      • V1 Get hotel details
      • V1 Get reviews for a hotel
      • V1 List all flights
      • V1 Get flight details
      • V1 List all restaurants
      • V1 Get restaurant details
      • V1 List all attractions
      • V1 Get attraction details
      • V1 List all regions
      • V1 Get weather details
    • Trips
      • List user trips
      • Create a new trip
      • Get trip details
      • Update trip details
      • Delete a trip
      • Get creation metadata
      • Attach items to a trip
      • Update trip item
      • Detach items from a trip
      • Fork a trip
    • Conversations
      • List user conversations
      • Start a new conversation
      • Get conversation details
      • List messages in conversation
      • Send message to conversation
      • Mark conversation as read
    • Commerce Plans
      • List public plans
      • Get public plan details
    • Commerce Subscriptions
      • Subscribe to a plan
      • Upgrade active plan
      • Get active subscription info
      • Cancel active subscription
    • Commerce Checkout
      • Initiate Paymob payment checkout
    • Integrations
      • Paymob status webhook callback
      • Paymob redirect return callback
    • System Settings & Support
      • Submit public contact message
      • Subscribe to system newsletter
      • Get list of my reports
      • List all notifications
      • Mark single notification as read
      • List available surveys
      • Submit answers for survey
      • Get survey details
      • Update survey details
      • Delete survey response
    • AI Tools
      • Enhance itinerary details using AI
      • Request AI review of itinerary
      • Plan route using AI assistance
      • Get AI quota remaining details
      • Chat with AI Concierge assistant
      • Get AI Review progress by ID
    • Agency Integration
      • Request agency assignment
      • List agency active tasks
      • List agency managed trips
      • Get agency total earnings
      • Get agency profile details
      • Update agency profile details
    • Admin User Management
      • List users inside admin dashboard
      • Get user profile
      • Set user active status
      • Block user profile
    • Admin Catalog Moderation
      • Create new catalog category
      • Create new catalog destination
      • Create new hotel catalog record
      • Create new flight catalog record
      • Create new restaurant catalog record
      • Create new attraction catalog record
  • Schemas
    • User
    • ErrorResponse
    • Trip
    • Destination
    • Hotel
    • Flight
    • Restaurant
    • Attraction
    • Booking
    • Review
    • Agency
    • Survey
  1. legacy

Architecture Overview

Table of Contents#

1.
Layered Request Flow
2.
Domain Modules
3.
Repository & Service Pattern
4.
Checkout Strategy Pattern
5.
Event-Driven Side Effects
6.
Authorization Model

Layered Request Flow#

Every response is shaped through app/Http/Resources/* transformers and the shared Support/ApiResponse helper for consistent envelopes.
Diagram sources: routes/api.php, Resources, ApiResponse.php

Domain Modules#

The app/ tree is partitioned by bounded context instead of technical type at the top level:
ModuleModelsControllersServices
AccountUser, Role, UserPointAuth, AdminUserUserService
CatalogCountry, Region, Destination, Hotel, Flight, Restaurant, Attraction, Categorypublic + Admin CRUD pairsper-entity services + Fixtures + AiAttraction
TripsTrip, ItineraryItem, TripDestination, Review, Favourite, AiGeneration, BudgetSnapshot, TripContributionTrip, AI, Map, Interaction, admin variantsTripService, ForkService, AttachService, ReviewService, AiUsage
CommerceOrder, OrderItem, Payment, Plan, Subscription, Address, AgencyAssignmentCheckout, Paymob, Plan, Agency, AnalyticsCheckoutService, PaymobGateway/Client, WebhookService, PriceCalculator, strategies
ChatConversation, MessageConversationController— (policy-guarded)
SystemSetting, Flag, Survey, ContactMessage, NewsletterSubscriber, Notification, Report, PasswordResetTokenWeather, Report, Settings, Survey, Contact, Flags, DashboardGenerateReportService (+Excel), OpenMeteo, Newsletter, Survey, Flag
Section sources: app/Models tree, Controllers tree

Repository & Service Pattern#

Interfaces live in app/Interfaces/<Module>/ (e.g. PaymentGatewayInterface) and are bound to implementations in AppServiceProvider.
Repositories in app/Repositories/<Module>/ encapsulate Eloquent queries so services stay persistence-agnostic.
Controllers stay thin: validate via FormRequest, delegate to one service, return a Resource.
Domain exceptions (InvalidStateTransitionException) funnel through a custom ApiExceptionHandler for uniform error payloads.
Section sources: Interfaces, Repositories, AppServiceProvider.php

Checkout Strategy Pattern#

CheckoutType enum drives factory selection; each strategy builds order lines and pricing before delegating to the single payment gateway. Adding a purchasable product type = one new strategy class.
Diagram sources: CheckoutStrategyFactory.php, Strategies, Support/Enums/CheckoutType.php

Event-Driven Side Effects#

EventListener(s)Effects
PaymentSucceededFulfillOrderListenermark order paid, fire mail + notification, subscription activation
PaymentFailedHandlePaymentFailedfailure mails/notifications, state rollback
MessageSentconversation notificationschat unread counts
Commerce agency events (AgencyAssignment*)admin/user notificationsmarketplace workflow
Mail classes (TripBookedMail, WelcomeMail, SubscriptionActivatedMail, …) and database notifications (app/Notifications) keep user-facing messaging decoupled from controllers. Long-running work (report PDF/XLSX generation, destination geocoding) runs on queued jobs: GenerateReportJob, GeocodeDestinationJob.
Section sources: Events/Commerce, Listeners, Jobs, Mail

Authorization Model#

Two stacked gates on every protected route:
1.
JWT authentication (auth:api) + optional verified email gate and custom EnsureUserIsActive middleware.
2.
Spatie permissions via inline middleware: permission:manage hotels, role:admin|super_admin, etc. Permissions are seeded by RoleAndPermissionSeeder; policies exist for fine-grained cases (TripPolicy, ConversationPolicy, FlagPolicy, AgencyAssignmentPolicy).
Roles in use: super_admin, admin, user, agency (agency marketplace endpoints under /agency/*).
Section sources: routes/api.php, Policies, Middleware
Modified at 2026-08-25 22:41:45
Previous
Frontend Application
Next
API Reference
Built with