|
2 | 2 |
|
3 | 3 | ## Overview |
4 | 4 |
|
5 | | -The Flowlet Backend is a robust, modular platform designed to support financial technology operations. It is built using **Python and Flask**, following a microservices-like architecture to emphasize security, compliance, and advanced financial intelligence. |
| 5 | +The Flowlet Backend is a robust, modular platform designed to support financial technology operations. It is built using Python and Flask, following a microservices-like architecture to emphasize security, compliance, and advanced financial intelligence. |
6 | 6 |
|
7 | 7 | ## 1. Core Directory Structure |
8 | 8 |
|
9 | 9 | The backend is organized to separate the application entry point, configuration, and core business logic. |
10 | 10 |
|
11 | | -| Directory | Primary Function | Key Components | |
12 | | -| :-------------- | :--------------------------- | :-------------------------------------------------------------------------------------------------------------------------- | |
13 | | -| **app.py** | **Application Entry Point** | Contains the `create_app()` factory function, initializes extensions (DB, Migrations, Limiter), and registers blueprints. | |
14 | | -| **src/** | **Core Business Logic** | Houses all specialized modules: `ai/`, `analytics/`, `compliance/`, `integrations/`, `security/`, `routes/`, and `models/`. | |
15 | | -| **src/config/** | **Configuration Management** | Centralized application settings (`settings.py`) and security policies (`security.py`). | |
16 | | -| **src/models/** | **Database Models** | SQLAlchemy models for core entities: `user.py`, `account.py`, `transaction.py`, `card.py`, etc. | |
17 | | -| **src/routes/** | **API Endpoints** | Flask Blueprints defining all API routes (e.g., `/auth`, `/payment`, `/analytics`). | |
18 | | -| **instance/** | **Runtime Data** | Directory for environment-specific data (e.g., SQLite DB files, if used). Currently empty after cleanup. | |
19 | | -| **logs/** | **Application Logging** | Stores application logs (`flowlet.log`). | |
20 | | -| **tests/** | **Comprehensive Testing** | Structured suite for Unit, Integration, Functional, Performance, and Security testing. | |
| 11 | +| Directory | Primary Function | Key Components | |
| 12 | +| ------------- | ------------------------ | --------------------------------------------------------------------------------------------------------------------------- | |
| 13 | +| `app.py` | Application Entry Point | Contains the `create_app()` factory function, initializes extensions (DB, Migrations, Limiter), and registers blueprints. | |
| 14 | +| `src/` | Core Business Logic | Houses all specialized modules: `ai/`, `analytics/`, `compliance/`, `integrations/`, `security/`, `routes/`, and `models/`. | |
| 15 | +| `src/config/` | Configuration Management | Centralized application settings (`settings.py`) and security policies (`security.py`). | |
| 16 | +| `src/models/` | Database Models | SQLAlchemy models for core entities: `user.py`, `account.py`, `transaction.py`, `card.py`, etc. | |
| 17 | +| `src/routes/` | API Endpoints | Flask Blueprints defining all API routes (e.g., `/auth`, `/payment`, `/analytics`). | |
| 18 | +| `instance/` | Runtime Data | Directory for environment-specific data (e.g., SQLite DB files, if used). Currently empty after cleanup. | |
| 19 | +| `logs/` | Application Logging | Stores application logs (`flowlet.log`). | |
| 20 | +| `tests/` | Comprehensive Testing | Structured suite for Unit, Integration, Functional, Performance, and Security testing. | |
21 | 21 |
|
22 | 22 | ## 2. Specialized Services in `src/` |
23 | 23 |
|
24 | 24 | The `src/` directory is the heart of the Flowlet backend, containing highly specialized, domain-specific modules. |
25 | 25 |
|
26 | | -| Module | Primary Function | Key Sub-Components/Files | |
27 | | -| :---------------- | :------------------------------------- | :--------------------------------------------------------------------------------------------------------------- | |
28 | | -| **ai/** | **Financial AI/ML** | `fraud_detection.py`, `risk_assessment.py`, `transaction_intelligence.py`, `support_chatbot.py`. | |
29 | | -| **analytics/** | **Data Processing & Reporting** | `dashboard_service.py`, `reporting_engine.py`, `real_time_analytics.py`, `metrics_calculator.py`. | |
30 | | -| **compliance/** | **Regulatory Adherence** | `aml_engine.py`, `kyc_service.py`, `regulatory_framework.py`, `compliance_engine.py`. | |
31 | | -| **integrations/** | **External System Connectivity** | Sub-modules for `banking/` (Plaid, FDX), `payments/` (Stripe), and `currency/` (Exchange Rates). | |
32 | | -| **nocode/** | **Business Logic Configuration** | `rule_engine.py`, `workflow_builder.py`, `config_engine.py` for dynamic business rules. | |
33 | | -| **security/** | **Authentication & Threat Prevention** | `authentication.py`, `encryption_service.py`, `rate_limiter.py`, `threat_prevention.py`, `password_security.py`. | |
34 | | -| **services/** | **Core Business Services** | `payment_service.py`, `card_service.py`, `wallet_service.py` implementing core financial logic. | |
35 | | -| **gateway/** | **API Gateway Logic** | `optimized_gateway.py` for handling and routing external API requests. | |
| 26 | +| Module | Primary Function | Key Sub-Components/Files | |
| 27 | +| --------------- | ---------------------------------- | ---------------------------------------------------------------------------------------------------------------- | |
| 28 | +| `ai/` | Financial AI/ML | `fraud_detection.py`, `risk_assessment.py`, `transaction_intelligence.py`, `support_chatbot.py`. | |
| 29 | +| `analytics/` | Data Processing & Reporting | `dashboard_service.py`, `reporting_engine.py`, `real_time_analytics.py`, `metrics_calculator.py`. | |
| 30 | +| `compliance/` | Regulatory Adherence | `aml_engine.py`, `kyc_service.py`, `regulatory_framework.py`, `compliance_engine.py`. | |
| 31 | +| `integrations/` | External System Connectivity | Sub-modules for `banking/` (Plaid, FDX), `payments/` (Stripe), and `currency/` (Exchange Rates). | |
| 32 | +| `nocode/` | Business Logic Configuration | `rule_engine.py`, `workflow_builder.py`, `config_engine.py` for dynamic business rules. | |
| 33 | +| `security/` | Authentication & Threat Prevention | `authentication.py`, `encryption_service.py`, `rate_limiter.py`, `threat_prevention.py`, `password_security.py`. | |
| 34 | +| `services/` | Core Business Services | `payment_service.py`, `card_service.py`, `wallet_service.py` implementing core financial logic. | |
| 35 | +| `gateway/` | API Gateway Logic | `optimized_gateway.py` for handling and routing external API requests. | |
36 | 36 |
|
37 | 37 | ## 3. Configuration and Security |
38 | 38 |
|
39 | 39 | Configuration is split into two primary files for clarity and separation of concerns. |
40 | 40 |
|
41 | | -| File | Description | Key Responsibilities | |
42 | | -| :------------------------- | :----------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------- | |
43 | | -| **src/config/settings.py** | **Application Settings** | Defines environment-specific settings (e.g., `SQLALCHEMY_DATABASE_URI`, `REDIS_URL`), API metadata, and feature flags (e.g., `FRAUD_DETECTION_ENABLED`). | |
44 | | -| **src/config/security.py** | **Security Policies** | Defines strict security parameters, including JWT configuration, password policy, rate limiting rules, and encryption key requirements. | |
| 41 | +| File | Description | Key Responsibilities | |
| 42 | +| ------------------------ | -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | |
| 43 | +| `src/config/settings.py` | Application Settings | Defines environment-specific settings (e.g., `SQLALCHEMY_DATABASE_URI`, `REDIS_URL`), API metadata, and feature flags (e.g., `FRAUD_DETECTION_ENABLED`). | |
| 44 | +| `src/config/security.py` | Security Policies | Defines strict security parameters, including JWT configuration, password policy, rate limiting rules, and encryption key requirements. | |
45 | 45 |
|
46 | 46 | ## 4. API Routes Overview |
47 | 47 |
|
48 | 48 | The `src/routes/` directory contains Flask Blueprints, each managing a set of related API endpoints. |
49 | 49 |
|
50 | | -| Blueprint File | Domain | Key Functionality | |
51 | | -| :----------------- | :-------------- | :----------------------------------------------------------------------------- | |
52 | | -| **auth.py** | Authentication | User registration, login, token refresh, and password management. | |
53 | | -| **user.py** | User Management | Profile retrieval, updates, and administrative user operations. | |
54 | | -| **payment.py** | Payments | Processing transactions, managing payment methods, and payment status checks. | |
55 | | -| **wallet.py** | Wallet | Managing user wallets, balances, and internal transfers. | |
56 | | -| **analytics.py** | Analytics | Access to dashboard data, metrics, and reporting endpoints. | |
57 | | -| **kyc_aml.py** | Compliance | Endpoints for Know Your Customer (KYC) and Anti-Money Laundering (AML) checks. | |
58 | | -| **security.py** | Security | Audit log access, security status checks, and threat monitoring data. | |
59 | | -| **api_gateway.py** | Gateway | External API routing and centralized request handling. | |
| 50 | +| Blueprint File | Domain | Key Functionality | |
| 51 | +| ---------------- | --------------- | ------------------------------------------------------------------------------ | |
| 52 | +| `auth.py` | Authentication | User registration, login, token refresh, and password management. | |
| 53 | +| `user.py` | User Management | Profile retrieval, updates, and administrative user operations. | |
| 54 | +| `payment.py` | Payments | Processing transactions, managing payment methods, and payment status checks. | |
| 55 | +| `wallet.py` | Wallet | Managing user wallets, balances, and internal transfers. | |
| 56 | +| `analytics.py` | Analytics | Access to dashboard data, metrics, and reporting endpoints. | |
| 57 | +| `kyc_aml.py` | Compliance | Endpoints for Know Your Customer (KYC) and Anti-Money Laundering (AML) checks. | |
| 58 | +| `security.py` | Security | Audit log access, security status checks, and threat monitoring data. | |
| 59 | +| `api_gateway.py` | Gateway | External API routing and centralized request handling. | |
60 | 60 |
|
61 | 61 | ## 5. Testing Suite Overview |
62 | 62 |
|
63 | 63 | The `tests/` directory is structured to ensure comprehensive quality assurance across all layers of the application. |
64 | 64 |
|
65 | | -| Test Category | Location | Purpose | |
66 | | -| :-------------- | :------------------- | :------------------------------------------------------------------------------------------------------------ | |
67 | | -| **Unit** | `tests/unit/` | Verifies individual functions, classes, and service methods in isolation (e.g., `test_payment_service.py`). | |
68 | | -| **Functional** | `tests/functional/` | Tests end-to-end user flows and core business logic (e.g., `test_fraud_detection.py`). | |
69 | | -| **Integration** | `tests/integration/` | Verifies interactions between different services and external systems (e.g., `test_banking_integrations.py`). | |
70 | | -| **API** | `tests/api/` | Validates API endpoint responses, data contracts, and status codes (e.g., `test_api_integration.py`). | |
71 | | -| **Performance** | `tests/performance/` | Measures latency and throughput of critical paths (e.g., `test_gateway_performance.py`). | |
72 | | -| **Security** | `tests/security/` | Validates security controls like rate limiting, authentication, and input validation. | |
| 65 | +| Test Category | Location | Purpose | |
| 66 | +| ------------- | -------------------- | ------------------------------------------------------------------------------------------------------------- | |
| 67 | +| Unit | `tests/unit/` | Verifies individual functions, classes, and service methods in isolation (e.g., `test_payment_service.py`). | |
| 68 | +| Functional | `tests/functional/` | Tests end-to-end user flows and core business logic (e.g., `test_fraud_detection.py`). | |
| 69 | +| Integration | `tests/integration/` | Verifies interactions between different services and external systems (e.g., `test_banking_integrations.py`). | |
| 70 | +| API | `tests/api/` | Validates API endpoint responses, data contracts, and status codes (e.g., `test_api_integration.py`). | |
| 71 | +| Performance | `tests/performance/` | Measures latency and throughput of critical paths (e.g., `test_gateway_performance.py`). | |
| 72 | +| Security | `tests/security/` | Validates security controls like rate limiting, authentication, and input validation. | |
| 73 | + |
| 74 | +## Running the Backend |
| 75 | + |
| 76 | +Development server: |
| 77 | + |
| 78 | +```bash |
| 79 | +python run_server.py |
| 80 | +``` |
| 81 | + |
| 82 | +With Docker: |
| 83 | + |
| 84 | +```bash |
| 85 | +docker-compose up |
| 86 | +``` |
| 87 | + |
| 88 | +Running tests: |
| 89 | + |
| 90 | +```bash |
| 91 | +./run_tests.sh |
| 92 | +``` |
| 93 | + |
| 94 | +## Environment Setup |
| 95 | + |
| 96 | +Copy the example environment file and configure your local settings: |
| 97 | + |
| 98 | +```bash |
| 99 | +cp .env.example .env |
| 100 | +``` |
| 101 | + |
| 102 | +Required environment variables include database URIs, Redis connection strings, JWT secrets, and API keys for external integrations. |
0 commit comments