Introduce granular rate limiting across various API categories to
improve security and prevent abuse. This includes protection against
brute-force attacks on authentication and SMS endpoints, as well as
resource management for public, customer, wallet, and staff APIs.
- Add `auth` rate limiter (5 requests/min per IP)
- Add `sms` rate limiter (1 request/min per phone/IP)
- Add `public` rate limiter (30 requests/min per IP)
- Add `customer` rate limiter (60 requests/min per user)
- Add `wallet` rate limiter (30 requests/min per user)
- Add `staff` rate limiter (60 requests/min per user)
- Apply middleware to corresponding routes in `api.php`
- Remove obsolete `test_pdf_generation.php` script
Add comprehensive Architecture Decision Records (ADRs) detailing the
new shipment review state machine, review history domain, and customer
resubmission logic. This documentation establishes the separation
between operational shipment status and the review lifecycle.
Additionally, perform repository cleanup by removing obsolete Postman
collections, environment files, test scripts, and unused migrations.
- Add ADR-001 through ADR-005 regarding review workflow and state.
- Add shipment review handoff documentation.
- Remove redundant Postman resources and local environment configs.
- Remove `test_pdf_generation.php` and `resubmit-test.json`.
- Remove unused `shipment_packages` migration.
- Rename and reorganize one-off maintenance scripts.
- Redesign AWB PDF with barcode, From/To, Value, Service, Type
- Redesign Invoice PDF with 9-row table, legal declaration, barcode
- Redesign Label PDF to A5 landscape with large barcode
- Add DOC/PARCEL condition for Invoice (only PARCEL has invoice)
- Fix ShipmentType enum names (DocNormal/DocEconomy)
- Add migration for shipment_items (row_number, unit_price)
- Add migration to make name nullable
- Update PdfService with base64 barcode embedding
- Update ShipmentPdfController with DOC type handling
- Add test_pdf_generation.php script
Phase 3.5 — PDF redesign complete"