A modern, microservices-based movie streaming platform built with .NET 9, Angular, and Docker. Cinemax provides movie catalog browsing, user authentication, payment processing, private streaming sessions, and more.
This project follows Clean Architecture and Microservices patterns with the following services:
| Service | Port | Description | Technology |
|---|---|---|---|
| Identity.API | 4000 | User authentication & authorization | ASP.NET Identity, JWT, MS SQL Server |
| MovieCatalog.API | 8000 | Movie catalog management | MongoDB |
| Basket.API | 8001 | Shopping cart management | Redis, gRPC Client |
| Payment.API | 8004 | Payment processing & PayPal integration | PostgreSQL, gRPC Server, RabbitMQ |
| PrivateSession.API | 8005 | Private movie streaming sessions | Google Drive API, SignalR |
| Email.API | 8006 | Email notification service | RabbitMQ Consumer, SMTP |
- CinemaxSPA - Modern Angular single-page application with responsive design
| Service | Port | Description |
|---|---|---|
| RabbitMQ | 5672, 15672 | Message broker for async communication |
| Redis | 6379 | Distributed cache for baskets |
| PostgreSQL | 5432 | Payment database |
| MongoDB | 27017 | Movie catalog database |
| MS SQL Server | 1433 | Identity database |
| pgAdmin | 5050 | PostgreSQL management UI |
-
Docker & Docker Compose (required)
- Docker Desktop 4.0+ recommended
- Download Docker
-
For Frontend Development (optional)
- Node.js 18+ and npm
- Angular CLI:
npm install -g @angular/cli
-
For Backend Development (optional)
- .NET 9 SDK
- IDE: Visual Studio 2022, Rider, or VS Code
The .env.example file contains working development credentials ready to use!
Simply copy the template and you're ready to go:
cd Cinemax
cp .env.example .env
docker-compose up -dWhat's included in .env.example:
- β PayPal sandbox credentials (test mode - no real money)
- β Shared team email for development testing
- β Development-safe JWT secret
- β Test database passwords
- β Google Drive development folder
Google Drive Service Account (for Private Sessions):
- β
Full credentials documented in:
docs/GOOGLE_SERVICE_ACCOUNT.md - β One-command setup available in the doc
- β Restricted to development folder only
- β Safe to use for development
- βΉοΈ See:
Cinemax/Services/PrivateSessions/GET_CREDENTIALS.mdfor setup instructions
PayPal Sandbox Test Account (for testing payments):
Email: sb-2qjuu34887226@personal.example.com
Password: 4)grxJ35
Use these credentials to log in to PayPal during checkout testing. This is a PayPal sandbox account - no real money will be charged.
These credentials are:
- β Safe to share within your development team
- β Safe to commit for development use
- β Ready to use immediately - no setup required
β οΈ NOT for production use - see production setup guide
-
Generate new secure credentials:
# JWT Secret (use this in production!) openssl rand -base64 64 -
Get your own API credentials:
- PayPal: Create production app at https://developer.paypal.com
- Gmail: Generate app password at https://myaccount.google.com/apppasswords
- Databases: Use strong random passwords (20+ chars)
-
Update
.envwith production values -
Never commit
.envto git (already in.gitignoreβ )
See docs/SECURITY_GUIDE.md for detailed production security practices.
git clone <repository-url>
cd Cinemaxcd Cinemax
cp .env.example .envNote: The .env.example contains working development credentials - no editing needed for testing!
cd Cinemax
docker-compose up -dThis will start all microservices and databases. First run may take 5-10 minutes to download images and build.
docker-compose psAll services should show status "Up".
Frontend:
- Angular SPA:
http://localhost:4200(if running separately)
Backend APIs:
- Identity API:
http://localhost:4000/swagger - Movie Catalog API:
http://localhost:8000/swagger - Basket API:
http://localhost:8001/swagger - Payment API:
http://localhost:8004/swagger - Private Session API:
http://localhost:8005/swagger - Email API:
http://localhost:8006/swagger
Infrastructure:
- RabbitMQ Management:
http://localhost:15672(guest/guest) - pgAdmin:
http://localhost:5050(dev@gmail.com/admin1234)
docker-compose downTo remove volumes (databases) as well:
docker-compose down -v-
Start Required Infrastructure
cd Cinemax docker-compose up -d identitydb paymentdb moviecatalogdb basketdb rabbitmq pgadmin -
Run Individual Services
# Identity API cd Cinemax/Security/IdentityServer dotnet run # Payment API cd Cinemax/Services/Payment/Payment.API dotnet run # Other services follow the same pattern
-
Install Dependencies
cd CinemaxSPA npm install -
Run Development Server
npm start # or ng serve -
Access Frontend
- Navigate to
http://localhost:4200
- Navigate to
-
Synchronous (gRPC)
- Basket.API β Payment.API
- Used for real-time payment processing during checkout
-
Asynchronous (RabbitMQ)
- Payment.API β Email.API
- Basket.API β Email.API (via events)
- Used for non-blocking email notifications
-
HTTP REST
- Frontend β All Backend APIs
- Used for standard CRUD operations
- Database per Service pattern
- Each microservice has its own database
- No direct database sharing between services
Cinemax/
βββ Cinemax/ # Backend microservices
β βββ Services/
β β βββ Basket.API/ # Shopping cart service
β β βββ Email.API/ # Email notification service
β β βββ MovieCatalog.API/ # Movie catalog service
β β βββ Payment/ # Payment service (Clean Architecture)
β β β βββ Payment.API/ # API layer
β β β βββ Payment.Application/# Business logic layer
β β β βββ Payment.Domain/ # Domain models
β β β βββ Payment.Infrastructure/ # Data access & external services
β β βββ PrivateSessions/ # Private streaming sessions
β βββ Security/
β β βββ IdentityServer/ # Authentication & authorization
β βββ Common/
β β βββ EventBus.Messages/ # Shared event definitions
β βββ docker-compose.yml # Docker services definition
β βββ docker-compose.override.yml # Development configuration
β
βββ CinemaxSPA/ # Angular frontend
βββ src/app/ # Application components
βββ src/assets/ # Static assets
βββ package.json # npm dependencies
- RabbitMQ Management: guest/guest
- pgAdmin: dev@gmail.com/admin1234
- Database SA Password: MATF12345
Option 1: Using Swagger UI (Recommended)
- Navigate to Identity API Swagger:
http://localhost:4000/swagger - Find the
POST /api/v1/Authentication/RegisterAdministratorendpoint - Click "Try it out"
- Enter the following JSON:
{ "firstName": "Admin", "lastName": "User", "username": "admin", "password": "Admin123!", "email": "admin@cinemax.com" } - Click "Execute"
- Use these credentials to login at
POST /api/v1/Authentication/Login
Option 2: Using cURL
curl -X POST "http://localhost:4000/api/v1/Authentication/RegisterAdministrator" \
-H "Content-Type: application/json" \
-d '{
"firstName": "Admin",
"lastName": "User",
"username": "admin",
"password": "Admin123!",
"email": "admin@cinemax.com"
}'Option 3: Using HTTP File (Easiest)
Use the included test-admin.http file in the root directory:
- Open
test-admin.httpin VS Code (with REST Client extension) or JetBrains IDE - Click "Send Request" above
### Register Admin User - Then click "Send Request" above
### Login as Admin - Copy the returned JWT token for authenticated requests
The file includes examples for:
- β Registering Admin users
- β Registering Buyer users
- β Logging in
- β Getting user lists (with auth)
Use the same methods but with the RegisterBuyer endpoint:
POST /api/v1/Authentication/RegisterBuyer
Note: Password requirements:
- Minimum 5 characters
- At least 1 digit
- Must include uppercase, lowercase, and special characters recommended
- .NET 9 - Web APIs
- ASP.NET Core Identity - Authentication
- Entity Framework Core 9 - ORM
- MassTransit - RabbitMQ abstraction
- Grpc.AspNetCore - gRPC server/client
- MediatR - CQRS pattern
- AutoMapper - Object mapping
- PayPal SDK - Payment processing
- Google Drive API - Video streaming
- Angular 18 - SPA framework
- TypeScript - Type-safe JavaScript
- RxJS - Reactive programming
- SignalR - Real-time communication
- PostgreSQL 15 - Payment data
- MongoDB - Movie catalog
- MS SQL Server 2019 - Identity data
- Redis - Distributed cache
- RabbitMQ 3 - Asynchronous messaging
Each service has Swagger documentation:
http://localhost:4000/swagger # Identity API
http://localhost:8000/swagger # Movie Catalog API
http://localhost:8001/swagger # Basket API
http://localhost:8004/swagger # Payment API
http://localhost:8005/swagger # Private Session API
http://localhost:8006/swagger # Email API
Each service includes .http files for testing:
Cinemax/Services/Basket.API/Basket.API.http
Cinemax/Services/Payment/Payment.API/Payment.API.http
Cinemax/Services/Email.API/Email.API.http
Open these in Visual Studio, Rider, or VS Code with REST Client extension.
docker-compose build payment.api
docker-compose up -d payment.apidocker-compose build --no-cache
docker-compose up -d# All services
docker-compose logs -f
# Specific service
docker-compose logs -f payment.api
# Last 50 lines
docker-compose logs --tail=50 payment.api-
Check if ports are already in use:
# On macOS/Linux lsof -i :8004 # On Windows netstat -ano | findstr :8004
-
Clean and restart:
docker-compose down -v docker-compose up -d
-
Reset databases:
docker-compose down -v # Removes volumes docker-compose up -d -
View database logs:
docker-compose logs paymentdb docker-compose logs identitydb docker-compose logs moviecatalogdb
-
Check RabbitMQ is running:
docker-compose ps rabbitmq
-
Access RabbitMQ Management UI:
- URL:
http://localhost:15672 - Credentials: guest/guest
- Check queues and connections
- URL:
-
Clean all build artifacts:
# From Cinemax/Cinemax directory find . -type d \( -name bin -o -name obj \) -exec rm -rf {} + 2>/dev/null
-
Remove Docker build cache:
docker-compose build --no-cache
- Payment Setup:
Cinemax/Services/Payment/Payment.API/PAYPAL_SETUP.md - Email Setup:
Cinemax/Services/Email.API/README.md - Private Sessions:
- Overview:
Cinemax/Services/PrivateSessions/README.md - Google Drive Setup:
Cinemax/Services/PrivateSessions/PrivateSession/GOOGLE_DRIVE_SETUP.md
- Overview:
- π‘οΈ Security Guide:
docs/SECURITY_GUIDE.mdβ READ THIS FIRST - π Development Credentials:
docs/DEVELOPMENT_CREDENTIALS.md- Why credentials are in the repo - π³ Testing Payments:
docs/TESTING_PAYMENTS.md- PayPal sandbox testing guide - π Google Service Account:
docs/GOOGLE_SERVICE_ACCOUNT.md- Google Drive credentials for dev - Google Drive Service Account Setup:
docs/SERVICE_ACCOUNT_SETUP.md - HLS Video Streaming Guide:
docs/HLS_STREAMING_GUIDE.md - Frontend Testing Guide:
docs/FRONTEND_TESTING_GUIDE.md - Frontend Premium Features:
docs/FRONTEND_PREMIUM_FIX.md - Admin Protection Summary:
docs/ADMIN_PROTECTION_SUMMARY.md - Purchased Movies Filter:
docs/PURCHASED_MOVIES_FILTER.md - Testing Google Drive Integration:
docs/TESTING_GOOGLE_DRIVE.md
- User Authentication - JWT-based with role management (Admin, Buyer)
- Movie Catalog - Browse movies by genre with premium content
- Shopping Cart - Add movies to basket with Redis caching
- Payment Processing - PayPal integration with gRPC communication
- Email Notifications - Asynchronous via RabbitMQ
- Private Streaming - Google Drive integration with HLS streaming
- Real-time Chat - SignalR for private session chat
- Admin Protection - Secure endpoints with role-based access
- Create a feature branch
- Make your changes
- Test with Docker Compose
- Submit a pull request
Bojan Velickovic 1070/2024 David Zivkovic 1027/2024 Dusan Trtica 1041/2023 Stefan Jevtic 1043/2024
For issues and questions:
- Check the troubleshooting section above
- Review service-specific README files
- Check Docker logs:
docker-compose logs [service-name]
-
Rotate ALL Credentials
- Generate new JWT secret with
openssl rand -base64 64 - Create new PayPal API credentials
- Generate new database passwords
- Create new email app password
- Generate new JWT secret with
-
Use Docker Secrets or Cloud Secret Management
- For production: Use Docker Swarm secrets or Kubernetes secrets
- For cloud: Use Azure Key Vault, AWS Secrets Manager, or Google Secret Manager
- See
Cinemax/Services/Payment/Payment.API/docker-secrets-setup.md
-
Never Commit to Git
.envfile (already gitignored β )- Google Drive credentials (already gitignored β )
- Any file containing passwords or API keys
-
Environment-Specific Secrets
- Use different credentials for dev/staging/production
- Never use production credentials in development
- Implement secret rotation policies
-
Additional Security Measures
- Enable HTTPS/TLS in production
- Use strong database passwords (20+ characters)
- Implement rate limiting on APIs
- Enable firewall rules to restrict database access
- Regular security audits
- Immediately rotate the compromised credentials
- Check git history if secrets were committed:
git log --all --full-history -- "*docker-compose*" - Use BFG Repo Cleaner to remove secrets from git history
- Force push to remote (only if you control all copies)
Last Updated: October 2025