IJCOPE Journal

UGC Logo DOI / ISO Logo

International Journal of Creative and Open Research in Engineering and Management

A Peer-Reviewed, Open-Access International Journal Supporting Multidisciplinary Research, Digital Publishing Standards, DOI Registration, and Academic Indexing.
Journal Information
ISSN: 3108-1754 (Online)
Crossref DOI: Available
ISO Certification: 9001:2015
Publication Fee: 599/- INR
Compliance: UGC Journal Norms
License: CC BY 4.0
Peer Review: Double Blind
Volume 02, Issue 10

Published on: October 2026

ARKA: DESIGN, IMPLEMENTATION AND SECURITY EVALUATION OF A SECURE E-COMMERCE WEB PLATFORM WITH SERVER-AUTHORITATIVE PRICING AND REAL-TIME COLLABORATIVE SHOPPING

Diksha Subhash Kumbhare Nirjala Subhash Kumbhare

Dept. of Computer Science (MCA), Sardar Patel College, Balaghat, India

Article Status

Plagiarism Passed Peer Reviewed Open Access

Available Documents

Abstract

Business-logic flaws in checkout flows, where a server trusts prices, totals or roles asserted by the client, remain a leading cause of financial loss in web commerce, and security studies continue to find them in widely deployed platforms. At the same time, mainstream storefronts treat shopping as a single-user activity and offer no synchronous way for several people to build one cart together.

This paper presents the design, implementation

and security evaluation of ARKA (अक´ ), a full-stack e-commerce web platform built with Next.js 16 (App Router), React 19, TypeScript, Prisma ORM and PostgreSQL. ARKA places four controls in sequence: (i) a

sliding-window rate limiter and (ii) JSON Web Token (JWT) verification with role-based access control (RBAC), both executed in Edge Middleware before any route handler; (iii) Zod schema validation of every request body; and (iv) a server-authoritative Canonical Pricing Engine that accepts only product identifiers and quantities from the client and recomputes the subtotal, promotional discount, shipping charge and 18% GST from database prices. A Real-Time Collaborative Shopping Room lets several authenticated users share one server-held cart over WebSocket. In a 14-day controlled evaluation, none of 50 price-tampering attempts altered a persisted order total, none of 75 authorization-bypass attempts reached a protected handler, all 85 requests above the login rate limit were rejected with HTTP 429, and 200 collaborative cart operations across three concurrent users produced no state divergence, with median update latencies of 31–34 ms.

How to Cite this Paper

Kumbhare, D. S. & Kumbhare, N. S. (2026). ARKA: Design, Implementation and Security Evaluation of a Secure E-Commerce Web Platform with Server-Authoritative Pricing and Real-Time Collaborative Shopping. International Journal of Creative and Open Research in Engineering and Management, <i>02</i>(10), 1-9. https://doi.org/10.55041/ijcope.v2i10.017

Kumbhare, Diksha, and Nirjala Kumbhare. "ARKA: Design, Implementation and Security Evaluation of a Secure E-Commerce Web Platform with Server-Authoritative Pricing and Real-Time Collaborative Shopping." International Journal of Creative and Open Research in Engineering and Management, vol. 02, no. 10, 2026, pp. 1-9. doi:https://doi.org/10.55041/ijcope.v2i10.017.

Kumbhare, Diksha, and Nirjala Kumbhare. "ARKA: Design, Implementation and Security Evaluation of a Secure E-Commerce Web Platform with Server-Authoritative Pricing and Real-Time Collaborative Shopping." International Journal of Creative and Open Research in Engineering and Management 02, no. 10 (2026): 1-9. https://doi.org/https://doi.org/10.55041/ijcope.v2i10.017.

Search & Index

References


  • Wang, S. Chen, X. Wang, and S. Qadeer, “How to Shop for Free Online — Security Analysis of Cashier-as-a-Service Based Web Stores,” in Proc. IEEE Symposium on Security and Privacy, Oakland, CA, USA, 2011, pp. 465–480, doi: 10.1109/SP.2011.26.

  • Sun, L. Xu, and Z. Su, “Detecting Logic Vulnerabilities in E-Commerce Applications,” in Proc. Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2014.

  • Pagey, M. Mannan, and A. Youssef, “All Your Shops Are Belong to Us: Security Weaknesses in E-commerce Platforms,” in Proc. ACM Web Conference (WWW ’23), Austin, TX, USA, 2023, doi: 10.1145/3543507.3583319.


  • OWASP Foundation, “OWASP Top 10:2021,”

  • [Online]. Available: https://owasp.org/Top10/

  • OWASP Foundation, “OWASP API Security Top 10 – 2023,” 2023. [Online]. Available: https://owas org/API-Security/editions/2023/en/0x11-t10/

  • Zhu, I. Benbasat, and Z. Jiang, “Let’s Shop Online Together: An Empirical Investigation of Collaborative Online Shopping Support,” Information Systems Research, vol. 21, no. 4, pp. 872–891, Dec. 2010.

  • Pellegrino and D. Balzarotti, “Toward Black-Box Detection of Logic Flaws in Web Applications,” in Proc. Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2014.

  • F. Ferraiolo, R. Sandhu, S. Gavrila, D. R. Kuhn, and R. Chandramouli, “Proposed NIST Standard for Role-Based Access Control,” ACM Transactions on Information and System Security, vol. 4, no. 3, pp. 224–274, 2001, doi: 10.1145/501978.501980.

  • Jones, J. Bradley, and N. Sakimura, “JSON Web Token (JWT),” IETF RFC 7519, May 2015.

  • Nottingham and R. Fielding, “Additional HTTP Status Codes,” IETF RFC 6585, Apr. 2012.

Ethical Compliance & Review Process

  • •All submissions are screened under plagiarism detection.
  • •Review follows editorial policy.
  • •Authors retain copyright.
  • •Peer Review Type: Double-Blind Peer Review
  • •Published on: Oct 03 2026
CCBYNC

This article is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License. You are free to share and adapt this work for non-commercial purposes with proper attribution.

View License
Scroll to Top