Functional Requirement Document (FRD)
This Functional Requirement Document specifies what CarRental does from a behavioral perspective: its modules, pages, features, customer/host/admin/influencer flows, validation, and the business rules that govern them. It complements the Business Requirement Document by translating goals into concrete, testable functionality across the storefront, the customer, host and influencer portals, and the admin CMS — all served from one Next.js 16 application.
Module Overview
CarRental groups functionality into nine functional areas. Vehicle listing and booking are part of the free core; premium integration providers unlock via CreativeCape add-on licensing.
| # | Module | Purpose |
|---|---|---|
| 1 | Catalogue | Public vehicle/host browsing with search, filters, and reviews |
| 2 | Booking & Checkout | Rental period selection, unit reservation, extras, coupons/gift cards, and payment |
| 3 | Payments | PayPal online gateway + offline methods (Bank Transfer); pluggable driver registry |
| 4 | Rental Periods & Units | Scheduled availability windows with a fixed fleet of units, atomic unit claiming, availability |
| 5 | Customer Portal | The /customer area — bookings, payments, wishlist, reviews, messaging, support |
| 6 | Host | The /host portal — vehicle listings, calendar/rental periods, reservations, earnings, payouts |
| 7 | Admin / CMS | The /admin panel — listings, bookings, hosts, customers, marketing, content, settings |
| 8 | Add-ons & Licensing | 53 channel integration providers, license/purchase-code activation |
| 9 | Auth | Customer, host and admin sessions, OTP/email verification, social sign-in, RBAC |
Catalogue
Public storefront under / (the (site) route group).
| Route | Page |
|---|---|
/ |
Homepage (hero, sections, featured content) |
/listings |
Vehicle catalogue with search, body type, transmission, price, and sort filters |
/listings/[slug] |
Vehicle detail — rental periods, what's included, reviews, pricing |
/booking/checkout, /booking/confirmed |
Unit checkout and booking confirmation |
/blogs, /blogs/[slug] |
Marketing blog listing and post |
/become-a-host, /how-it-works |
Host onboarding and marketing pages |
/gallery, /about, /contact, /faq, /enquiry |
CMS / marketing pages |
Capabilities:
- Published-vehicle catalogue with faceted filtering (body type, transmission, fuel type, price, location) and sorting; results are cached for hot public pages.
- Vehicle detail renders the description, what's included (amenity groups such as GPS, child seat, insurance), scheduled rental periods with per-period unit availability, ratings (
rating_avg/rating_count), approved reviews, and nearby places. - Vehicle categorisation via
listing_master_items(body type / fuel type / transmission tags); host profiles aggregate fleet size and rating. - Paid extras (e.g. GPS navigation, child seat, additional driver) surface on the vehicle page and are selectable at checkout.
Booking & Checkout
APIs under /api/v1/bookings and /api/v1/listings.
- Availability —
GET /api/v1/listings/[slug]/availabilityreturns eachexperience_sessionsrow withunits_total/units_bookedso the client can render bookable rental periods and remaining fleet units. - Quote —
POST /api/v1/listings/[slug]/quotere-prices a proposed booking server-side (rental period, unit count,booking_modeper_unit|exclusive, extras) and returns the deposit and full amounts without creating a booking. - Coupons & gift cards — coupons support
PERCENTorAMOUNTdiscounts, a minimum total, a max-discount cap, redemption limits, a validity window, and scoping; gift cards are validated forACTIVEstatus, currency, and balance. - Payment methods —
GET /api/v1/bookings/payment-methodslists the active gateways for the method picker. - Booking creation —
POST /api/v1/bookings/checkoutre-prices server-side, re-validates the coupon, and claims units atomically (units_total - units_booked >= units), creating abookingsrow keyed to thesession_idwith the chosenunitsandbooking_mode. The customer pays deposit or full (plus a refundable security deposit where configured); online gateways return a redirect/approval, offline methods return apendingbooking. - Verification —
POST /api/v1/bookings/payand the verify/return routes confirm payment with the driver and finalise the booking (recording abooking_paymentsrow).
Payments
- Built-in online gateway: PayPal (Orders v2, redirect flow) using client-id/secret with
test/live/sandboxmodes. - Offline method: Bank Transfer — creates a
pendingbooking fulfilled by admin "Mark as Paid". - Deposit or full. The customer may choose to pay a deposit or the full amount; the split is computed server-side from the vehicle/rental-period pricing — never trusted from the client.
- Pluggable driver registry: premium gateways (e.g. Stripe, Razorpay, and more) ship as self-contained add-on drivers, configured in admin settings.
- Active gateway configuration is read from the
integration_connectionstable (channelPAYMENTS), with secrets decrypted server-side only.
Rental Periods & Units
Booking statuses: pending, confirmed, cancelled, refunded.
- Rental periods. Each vehicle (
listings) opens scheduledexperience_sessions(availability windows) with a fixedunits_total;units_bookedtracks claimed fleet units. A rental period is bookable while units remain and its pickup date/time is in the future. - Atomic unit claiming. On checkout the requested unit count is claimed in a single guarded update (
units_total - units_booked >= n) so two customers cannot oversell the same rental period. - Booking modes.
per_unitbooks individual vehicle units at the daily/weekly/monthly price;exclusivebooks the whole fleet in that rental period for a single renter. - Cancellations & refunds. Tiered cancellation policies (flexible / moderate / firm / strict / non-refundable) determine the refund amount from the policy and lead time. Both customer-initiated and host-initiated cancellations are supported; units are released on cancellation and the request enters the admin refund approval queue (
booking_refunds). Email/WhatsApp/SMS notifications are sent. - Extras & notes —
booking_extrasrecords paid add-ons on a booking;booking_notesandbooking_emailscapture internal notes and the message trail.
Customer Portal
Portal under /customer (customer session, dynamically rendered to reflect live theming).
| Route | Purpose |
|---|---|
/customer/dashboard |
Overview: upcoming bookings, spend, recent activity |
/customer/bookings |
All bookings with status; open a booking for full detail |
/customer/bookings/[public_id] |
A single booking — rental period, units, payments, cancel/refund |
/customer/payments |
Payment history and invoices |
/customer/wishlist |
Saved vehicles |
/customer/reviews |
Reviews you've written on rented vehicles |
/customer/messages |
Messaging with hosts |
/customer/notifications |
In-app notifications |
/customer/support |
Support tickets |
/customer/settings |
Profile, addresses, password, preferences |
Host
Portal under /host (host session).
| Route | Purpose |
|---|---|
/host/dashboard |
Hosting overview |
/host/listings |
Author vehicles (details, what's included, rental periods) |
/host/calendar |
Rental periods calendar — schedule availability and units |
/host/reservations |
Incoming bookings and their status |
/host/inbox |
Messaging with customers |
/host/insights |
Utilisation and revenue analytics |
/host/payouts |
Earnings and payout requests |
/host/billing |
Host subscription plan to list vehicles |
/host/reviews |
Customer reviews with host replies |
/host/settings |
Host profile and settings |
Admin / CMS
Panel under /admin/(panel) (admin session, permission-gated).
- catalogue — listings (vehicles), rental periods, master-data (body types / fuel types / transmissions), extras, amenities.
- bookings (with per-booking detail and Mark as Paid), refunds (approval queue), customers, hosts, dashboard (revenue/analytics).
- marketing — coupons, gift-cards, partners, testimonials, leads. subscription — host subscription plans.
- Content/CMS — pages, blogs (+ categories), hero-slider, gallery, faqs, reviews, about, menus, theme builder, builder-pages.
- influencers — affiliate accounts, commissions, payouts.
- settings sections include: channels/integrations, notifications (email/sms/whatsapp/in-app/push/webhook) + notification-log, languages, currencies, countries, locations, invoice, theme, roles, permissions, users, api-tokens, webhooks, license, master-data, advanced, activity.
Add-ons & Licensing
- CarRental ships 53 channel integration providers across categories — Payments, Email, Storage, Analytics, Calendar, CAPTCHA, Realtime Chat, AI Chatbot, Live Chat, SMS, Social Auth, WhatsApp.
- Free defaults include SMTP (email), PayPal + Bank Transfer (payments), Cloudflare R2 (storage), and GA4 (analytics); other providers are premium.
- Gating. A premium provider serves only when unlocked. Activation is per-add-on via an Envato-style purchase code entered in admin → Add-ons, exchanged once for an RS256 JWT bound to
{ addon, domain }and then verified offline on every check; the domain license can also grant entitlements ("*", a channel id, or"channel:provider"). Localhost/dev hosts are unlocked. - Toggling. Server-side gates (
premiumBlock/featureBlock) and the clientuseFeatureActive()hook check installation and entitlement before exposing a feature.
Auth & Permissions
| Aspect | Customer / Host / Influencer | Admin |
|---|---|---|
| Session cookie | portal session (HS256 JWT, 30 days) | admin_token (HS256 JWT, 7 days default) |
| Routing | portal by account role (customer / host / influencer) | Direct admin login |
| Verification | Email/OTP via email, SMS, or WhatsApp | — |
| Social sign-in | OAuth providers (e.g. Google, Facebook) when configured | — |
| Authorization | Role-based portal access, owner-scoped queries | Fine-grained resource:action matrix |
- Auth routes (
/(auth)):login,register,forgot-password,reset-password,verify-email. - OTP/verification delivery channel is admin-configurable; a QA test-contact/test-code bypass exists for staging.
- Admin RBAC —
permissions-catalog.tsdefines resources × CRUD actions;requirePermission(action, resource)enforces per route and returns 403 when denied, emitting an audit event on mutations. System/super roles bypass the matrix.
Validation & Business Rules
- Server-side re-pricing: booking totals, deposits, coupons, and gift-card balances are recomputed on the server at booking time — never trusted from the client.
- File uploads pass through the server to R2/S3; images are processed (resize/convert) with sharp before storage.
- BR-A Units are claimed atomically; a booking is created only if
units_total - units_booked >= units. - BR-B A booking is confirmed only when payment (deposit or full) succeeds; offline bookings require admin Mark as Paid.
- BR-C Cancellations release units and compute a tiered refund routed through the admin approval queue.
- BR-D Premium add-ons require a valid entitlement or purchase code (dev/localhost unlocked).
- BR-E Integration secrets are stored AES-256-GCM encrypted and never returned to clients.
- BR-F Admin mutations are permission-checked and audited.
- BR-G A valid driver's licence must be captured on the booking before pickup; vehicle-level mileage limits and fuel policy are shown to the customer at checkout and enforced by the host at return.
For functional questions or feature requests, contact support at creative-cape.com.
© CreativeCape Solutions · creative-cape.com · support@creative-cape.com