Why Tijara - Supermarket Management System
What makes it better
than the alternatives
- 01
Single-tenant architecture
One database per company, no multi-tenant SaaS layer, customer's branding throughout
- 02
Full source with hand-written SQL
No ORM, ADO.NET repositories with parameterised queries, numbered schema migration scripts
- 03
BCrypt password hashing with configurable work factor, brute-force protection (lockout after 5 failures), antiforgery tokens on every form
BCrypt password hashing with configurable work factor, brute-force protection (lockout after 5 failures), antiforgery tokens on every form
- 04
Pre-aggregated reporting tables
Analytics dashboards read from rollup tables built by Hangfire jobs, not live transactional queries
- 05
Offline-capable driver PWA
Delivery orders sync through an outbox when connectivity returns, cash-on-delivery settlement tracked per shift
Head Office
- Product master: 3-level category tree
- brands
- multiple barcodes per product
- weighed items
- member prices
- Arabic names
- Bulk price changes with history
- shelf-label and barcode printing (PDF via QuestPDF)
- Suppliers
- purchase orders
- goods-received notes
- supplier deals and claims
- Stock transfer requests (warehouse → branch) with dispatch and receipt tracking
- Promotions: % off
- fixed amount
- buy-X-get-Y
- combos; by product or category; member-only and tier-gated
- User management: 17 roles (Administrator
- HeadOfficeManager
- BranchManager
- Cashier
- WarehouseManager
- DeliveryManager
- DeliveryBoy
- SupplierPortalUser
- Customer
- plus 8 more)
- permission matrix
- approval routes
- Analytics dashboards: daily takings
- hourly sales
- cash variance
- fast movers
- monthly P&L
- demand forecasting
- seasonality (Ramadan flagged from rpt.DimDate)
Branch Operations
- Branch dashboard: today's sales
- transactions
- low stock count
- expiring items (7-day window)
- pending STRs
- Inventory: stock counts
- wastage recording (with mandatory reason codes)
- expiry batch management
- Cashier handover: cash drops
- denomination declarations
- card settlement
- Z-number generation
- Day close: expenses entry
- daily sales report submission (requires approval before next day opens)
- Customer returns: refund processing with stock adjustment
- return reason tracking
- Online order picking: branch staff mark items picked
- ready for delivery handover
- Delivery handover: orders assigned to drivers
- cash-on-delivery tracking
- vehicle management
Point of Sale
- Keyboard-and-scanner-first till: barcode scanning (EAN-13/8
- UPC-A/E)
- weighed item entry
- Held bills: park incomplete transactions
- recall by cashier or bill number
- Split tender: cash
- card
- loyalty points in one transaction
- Loyalty earn and redeem at counter: points applied automatically
- promotions calculated in real-time
- Printable receipts: tax invoice generation (QuestPDF)
- QR code with transaction details
- Shift open/close: cashier sign-on
- denomination count at close
- variance reporting
- manager sign-off
Warehouse
- Goods receiving: GRN creation from purchase orders
- batch and expiry date capture
- Warehouse stock: current quantity
- reserved quantity
- available quantity per product
- Expiry batch tracking: FEFO (first-expired-first-out) allocation
- expiry alerts
- Dispatch to branches: STR fulfilment
- vehicle assignment
- dispatch confirmation
- Stock movements: audit trail of all adjustments
- transfers
- receipts (append-only log)
Loyalty & Marketing
- Points system: earn on purchase
- redeem at checkout
- FIFO lot expiry (oldest points used first)
- Tiers: unlock thresholds
- tier-gated promotions
- member-only pricing
- Audiences: customer segmentation by spend
- frequency
- last visit
- tier
- Campaigns: SMS/email message scheduling
- audience targeting
- redemption tracking
- Wishlists: customer-saved products
- abandoned-cart tracking for remarketing
Online Store (PWA)
- Installable PWA: add to home screen
- offline catalogue browsing
- push notifications
- Branch picker: customer selects collection/delivery branch
- sees live stock for that branch only
- Catalogue: category navigation
- search
- product images
- member prices shown when signed in
- Cart & checkout: guest checkout (no registration required)
- saved addresses
- card payment or cash-on-delivery
- Order tracking: status history (Pending → Confirmed → Picked → OutForDelivery → Delivered)
- estimated delivery time
- Returns: customer initiates return request
- branch approves
- refund processed to original payment method
Delivery
- Delivery manager queue: orders awaiting assignment
- branch picker
- driver assignment
- Driver PWA: offline-capable
- outbox syncs when connectivity returns
- route optimisation (manual)
- Cash-on-delivery: driver collects payment
- records amount
- settles at shift close
- Delivery boy shift: sign-on
- order handover
- cash settlement
- card slip reconciliation
- sign-off
- Card slips: driver records card payments
- manager reconciles against bank settlement
Supplier Portal
- Supplier login: separate authentication (dbo.AdminUsers)
- BCrypt password hashing
- brute-force protection
- Purchase orders: view assigned POs
- line items
- delivery dates
- branch destinations
- Goods receipt notes: view GRNs created from supplier's POs
- quantities received
- batch numbers
- Deals and claims: supplier submits promotional deals
- head office approves
- claim tracking
Accounting
- General ledger: chart of accounts (Asset
- Liability
- Equity
- Revenue
- Expense)
- account hierarchy
- Journal entries: manual posting
- auto-posting from sales/purchases
- approval workflow
- Accounts payable: supplier invoices
- payment tracking
- aging report
- Accounts receivable: customer invoices (credit sales)
- payment tracking
- aging report
- VAT reporting: sales VAT
- purchase VAT
- net VAT payable
- period-end reconciliation
Platform Console
- Administrator dashboard: branch summaries (today's sales
- transactions)
- audit log (last 200 actions)
- user activity
- Hangfire dashboard: background job monitoring (requires Administrator role)
- job re-queue/trigger/delete
- Licence context: module enablement (OnlineStore
- Delivery
- Loyalty
- Accounting)
- branch/user limits
- Company profile: name
- logo
- VAT number
- address (used on receipts and invoices)
- Notification centre: system alerts
- low-stock warnings
- expiry alerts
- approval requests
| Language | Version | Framework | Used for | Share of code |
|---|---|---|---|---|
| C# | — | — | Web, API, admin | 50.4% |
| C# (Razor) | — | — | Web pages | 24.2% |
| SQL | — | — | Database | 17% |
| CSS | — | — | Styling | 3.6% |
| HTML | — | — | Front-end | 2.5% |
| JavaScript | — | — | Front-end | 2.1% |
| Python | — | — | Web, API | 0.2% |
- Primary language
- C# 12 (.NET 9.0)
- Framework
- ASP.NET Core 9 MVC
- Database
- SQL Server 2019+
- Authentication
- Cookie authentication with BCrypt password hashing
- Licence
- Single-site
- Screens
- 87
- Database tables
- 89
- Supported languages
- English, Arabic (RTL supported via lx_lang cookie)
- Browser support
- Modern browsers (Chrome, Firefox, Safari, Edge); PWA installable on mobile
| Minimum | Recommended | |
|---|---|---|
| CPU | 2 vCPU | 4 vCPU |
| RAM | 4 GB RAM / 20 GB SSD | 8 GB RAM / 50 GB SSD |
| OS | Linux/Windows Server with .NET 9.0.100+ SDK, SQL Server 2019+ | Linux/Windows Server with .NET 9.0.100+ SDK, SQL Server 2019+ |
| Est. monthly hosting | $35 | $35 |
```bash cp .env.example .env # Edit .env: set SA_PASSWORD, DEMO_PASSWORD_HASH, PLATFORM_PASSWORD_HASH # Generate hashes: cd "NET Project/tools/HashPassword" dotnet run -- "your-demo-password" dotnet run -- "your-platform-password" # Paste hashes into .env, then: docker compose up -d --build # App at http://localhost:8080, SQL at localhost:14333 ```
```bash # Install .NET 9 SDK wget https://dot.net/v1/dotnet-install.sh chmod +x dotnet-install.sh ./dotnet-install.sh --channel 9.0 # Install SQL Server 2019+ curl https://packages.microsoft.com/keys/microsoft.asc | sudo apt-key add - sudo add-apt-repository "$(curl https://packages.microsoft.com/config/ubuntu/22.04/mssql-server-2019.list)" sudo apt-get update sudo apt-get install -y mssql-server sudo /opt/mssql/bin/mssql-conf setup # Clone and build git clone <repo-url> tijara cd tijara/"NET Project" dotnet restore dotnet build SupermarketMS.sln # Set connection string cd SupermarketMS.Web dotnet user-secrets set "ConnectionStrings:DefaultConnection" "Server=localhost;Database=Tijara;User Id=sa;Password=<your-sa-password>;TrustServerCertificate=True;Encrypt=True;" # Run dotnet run --urls "http://0.0.0.0:8080" ```
```bash # Create resources az group create --name tijara-rg --location eastus az sql server create --name tijara-sql --resource-group tijara-rg --location eastus --admin-user sqladmin --admin-password <strong-password> az sql db create --resource-group tijara-rg --server tijara-sql --name Tijara --service-objective S1 az appservice plan create --name tijara-plan --resource-group tijara-rg --sku B1 --is-linux az webapp create --resource-group tijara-rg --plan tijara-plan --name tijara-app --runtime "DOTNETCORE:9.0" # Set connection string az webapp config connection-string set --resource-group tijara-rg --name tijara-app --settings DefaultConnection="Server=tcp:tijara-sql.database.windows.net,1433;Database=Tijara;User ID=sqladmin;Password=<password>;Encrypt=True;" --connection-string-type SQLAzure # Deploy cd "NET Project/SupermarketMS.Web" dotnet publish -c Release -o ./publish cd publish zip -r ../deploy.zip . az webapp deployment source config-zip --resource-group tijara-rg --name tijara-app --src ../deploy.zip ```
```bash # Start SQL Server container docker run -d --name tijara-sql -e ACCEPT_EULA=Y -e MSSQL_SA_PASSWORD='YourStrong!Pass123' -p 1433:1433 mcr.microsoft.com/mssql/server:2019-latest # Build and run cd "NET Project" dotnet restore cd SupermarketMS.Web dotnet user-secrets set "ConnectionStrings:DefaultConnection" "Server=localhost;Database=Tijara;User Id=sa;Password=YourStrong!Pass123;TrustServerCertificate=True;Encrypt=True;" dotnet run # App at http://localhost:5000 ```
Quality report
Manually reviewedHow to read the quality report
What this is. Every project on Vibe96 goes through an automated audit of its source code before a reviewer in Dubai checks it by hand. The score is out of 100; 75 is the minimum to be listed, and any single failing check blocks a listing regardless of the score.
- Security
- No real credentials in the code, every data-changing route protected, admin areas role-gated, no SQL built from user input.
- Code structure
- A developer can navigate and extend it: clear module boundaries, no giant files, little copy-paste.
- Docs & completeness
- The setup guide, example config, schema and required files the builder committed to are actually in the archive.
- Dependency health
- Packages pinned, no known critical vulnerabilities, no abandoned libraries in production paths.
- Build & deploy
- A clean machine can restore, build and start it by following the shipped instructions.
Warnings are problems that didn't block the listing; they stay visible here until a later version clears them. The audit reads the code — it does not run it — so always try the live demo before you buy. Lines of code are counted from the same audited archive.
What to know before you buy
2 non-blocking findings shown publicly: moderate duplication and some oversized files; module boundaries mostly sound but view logic could be tightened; strong authentication and role guards; minor ownership gaps on read endpoints. The seller has been notified; fixes ship in the next version.
Versions & updates
Release historyCurrent version
Updates in the last 90 days
Buyers
Updates included
-
1.1.0 Version Current7 Oct 2026 ✓ Reviewed & audited
- Updated security fixes
-
1.0.0 First release 7 Oct 2026 ✓ Reviewed & audited
How updates work: versions add features and go through the full AI audit and human review. Patches are small fixes, audited and checked by a reviewer before release. Buyers get every update free for 1 year and are emailed the how-to-apply steps.
What you get
- </>Full source codeThe complete audited source, delivered as a download from your account. No obfuscation.
- ▤DocumentationSetup guide, architecture notes, CLAUDE.md and AGENTS.md.
- ↻One year of updatesEvery new version the builder publishes, free for 12 months.
- ♧30 days of supportInstallation and defect support through Vibe96 tickets.