# Offer Hat — Build Roadmap

Mapping the feature list from the brief to delivery phases. ✅ done · 🟡 partial/foundation · ⬜ planned

## Phase 1 — Core platform ✅ (DELIVERED)

| Feature | Status |
|---|---|
| Dynamic homepage (slider, featured, new arrivals) | ✅ |
| Multi-level product categories | ✅ |
| Product variations (Color/Size/Attributes) | ✅ |
| Advanced filters (price, category, sort) | ✅ |
| Cart & full order management | ✅ |
| SEO structure (meta, slugs, GA hook) | ✅ |
| Coupons & discounts | ✅ |
| Banner + slider management | ✅ |
| Multi-image product gallery | ✅ |
| Product stock (in/low/out tracking + alerts) | ✅ |
| Delivery setup (shipping zones) + per-product shipping | ✅ |
| Manual payment (bKash / Nagad / Rocket) + COD | ✅ |
| Suggested / related products | ✅ |
| Customer accounts | ✅ |
| Wishlist | ✅ |
| Blog module (admin CRUD pending — model + storefront ready) | 🟡 |
| Bilingual UI (বাংলা + English) | ✅ |
| Theme customizer (dynamic color) | ✅ |
| Responsive design | ✅ |
| Admin dashboard (sales charts, stats) | ✅ |
| Auto profit/loss calculation | ✅ |
| Auto invoice generation (printable) | ✅ |
| Low-stock alerts | ✅ |
| Security: CSRF, SQL-injection safe, XSS escaping, IP blocking | ✅ |
| Fraud risk scoring (basic heuristics) | 🟡 |
| Duplicate-order block (basic) | 🟡 |
| 2-Step authentication (DB columns ready) | 🟡 |

## Phase 2 — Automation & integrations ⬜ (NEXT)

| Feature | Notes |
|---|---|
| Quick View modal | JSON endpoint already built (`product.quickview`) — wire the modal |
| Blog admin CRUD | Model + storefront done; add admin screens |
| Product return / RMA module | `product_return` requests + admin approval |
| Auto courier booking — **Steadfast** & **Pathao** | API clients, one-click consignment from order |
| Auto delivery status update (courier webhooks/polling) | scheduled job |
| SMS & Email notifier (order placed/shipped/delivered) | queued jobs; BD SMS gateway |
| Incomplete-order follow-up | capture abandoned checkouts + reminders |
| 2FA enforcement for admin | TOTP (Google Authenticator) |
| Advanced fraud checker (phone history across couriers) | Steadfast fraud API |
| Online payment gateway (SSLCommerz / bKash PGW) | hosted checkout |

## Phase 3 — Scale & polish ⬜

| Feature | Notes |
|---|---|
| Redis cache/queue/session | swap drivers in `.env` |
| Asset build pipeline (Vite) for production CSS/JS | optional; currently CDN |
| Product reviews & ratings | |
| Multi-staff roles & permissions | `role` column already present |
| Sales / inventory / profit reports (exportable) | CSV/Excel export |
| Image optimization + CDN | |
| PWA / performance pass | |

---

### Environment already wired for Phase 2
`.env.production.example` contains placeholders for `STEADFAST_*`, `PATHAO_*`, `SMS_*`,
and `SSLCZ_*`, and the DB schema has the courier/fraud/2FA columns — so Phase 2 is additive,
not a rewrite.
