Published on: October 2026
ARKA: DESIGN, IMPLEMENTATION AND SECURITY EVALUATION OF A SECURE E-COMMERCE WEB PLATFORM WITH SERVER-AUTHORITATIVE PRICING AND REAL-TIME COLLABORATIVE SHOPPING
Diksha Subhash Kumbhare Nirjala Subhash Kumbhare
Article Status
Available Documents
Abstract
This paper presents the design, implementation
and security evaluation of ARKA (अक´ ), a full-stack e-commerce web platform built with Next.js 16 (App Router), React 19, TypeScript, Prisma ORM and PostgreSQL. ARKA places four controls in sequence: (i) a
sliding-window rate limiter and (ii) JSON Web Token (JWT) verification with role-based access control (RBAC), both executed in Edge Middleware before any route handler; (iii) Zod schema validation of every request body; and (iv) a server-authoritative Canonical Pricing Engine that accepts only product identifiers and quantities from the client and recomputes the subtotal, promotional discount, shipping charge and 18% GST from database prices. A Real-Time Collaborative Shopping Room lets several authenticated users share one server-held cart over WebSocket. In a 14-day controlled evaluation, none of 50 price-tampering attempts altered a persisted order total, none of 75 authorization-bypass attempts reached a protected handler, all 85 requests above the login rate limit were rejected with HTTP 429, and 200 collaborative cart operations across three concurrent users produced no state divergence, with median update latencies of 31–34 ms.
How to Cite this Paper
Kumbhare, D. S. & Kumbhare, N. S. (2026). ARKA: Design, Implementation and Security Evaluation of a Secure E-Commerce Web Platform with Server-Authoritative Pricing and Real-Time Collaborative Shopping. International Journal of Creative and Open Research in Engineering and Management, <i>02</i>(10), 1-9. https://doi.org/10.55041/ijcope.v2i10.017
Kumbhare, Diksha, and Nirjala Kumbhare. "ARKA: Design, Implementation and Security Evaluation of a Secure E-Commerce Web Platform with Server-Authoritative Pricing and Real-Time Collaborative Shopping." International Journal of Creative and Open Research in Engineering and Management, vol. 02, no. 10, 2026, pp. 1-9. doi:https://doi.org/10.55041/ijcope.v2i10.017.
Kumbhare, Diksha, and Nirjala Kumbhare. "ARKA: Design, Implementation and Security Evaluation of a Secure E-Commerce Web Platform with Server-Authoritative Pricing and Real-Time Collaborative Shopping." International Journal of Creative and Open Research in Engineering and Management 02, no. 10 (2026): 1-9. https://doi.org/https://doi.org/10.55041/ijcope.v2i10.017.
References
- Wang, S. Chen, X. Wang, and S. Qadeer, “How to Shop for Free Online — Security Analysis of Cashier-as-a-Service Based Web Stores,” in Proc. IEEE Symposium on Security and Privacy, Oakland, CA, USA, 2011, pp. 465–480, doi: 10.1109/SP.2011.26.
- Sun, L. Xu, and Z. Su, “Detecting Logic Vulnerabilities in E-Commerce Applications,” in Proc. Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2014.
- Pagey, M. Mannan, and A. Youssef, “All Your Shops Are Belong to Us: Security Weaknesses in E-commerce Platforms,” in Proc. ACM Web Conference (WWW ’23), Austin, TX, USA, 2023, doi: 10.1145/3543507.3583319.
- OWASP Foundation, “OWASP Top 10:2021,”
- [Online]. Available: https://owasp.org/Top10/
- OWASP Foundation, “OWASP API Security Top 10 – 2023,” 2023. [Online]. Available: https://owas org/API-Security/editions/2023/en/0x11-t10/
- Zhu, I. Benbasat, and Z. Jiang, “Let’s Shop Online Together: An Empirical Investigation of Collaborative Online Shopping Support,” Information Systems Research, vol. 21, no. 4, pp. 872–891, Dec. 2010.
- Pellegrino and D. Balzarotti, “Toward Black-Box Detection of Logic Flaws in Web Applications,” in Proc. Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2014.
- F. Ferraiolo, R. Sandhu, S. Gavrila, D. R. Kuhn, and R. Chandramouli, “Proposed NIST Standard for Role-Based Access Control,” ACM Transactions on Information and System Security, vol. 4, no. 3, pp. 224–274, 2001, doi: 10.1145/501978.501980.
- Jones, J. Bradley, and N. Sakimura, “JSON Web Token (JWT),” IETF RFC 7519, May 2015.
- Nottingham and R. Fielding, “Additional HTTP Status Codes,” IETF RFC 6585, Apr. 2012.
Ethical Compliance & Review Process
- •All submissions are screened under plagiarism detection.
- •Review follows editorial policy.
- •Authors retain copyright.
- •Peer Review Type: Double-Blind Peer Review
- •Published on: Oct 03 2026
This article is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License. You are free to share and adapt this work for non-commercial purposes with proper attribution.

