# Inventory — TinyPOS (`tnx-pos`)

> Produced by the Reversa **Scout** (phase: reconnaissance) · doc_level: `complete`
> Generated on 2026-09-16

**Confidence scale:** 🟢 CONFIRMED (read directly from code) · 🟡 INFERRED (pattern-based, may be wrong) · 🔴 GAP (needs human validation)

---

## 1. Overview

- **Product name:** TinyPOS 🟢 (`README.md`)
- **Repository slug:** `tnx-pos` 🟢 (`.reversa/state.json`, `config.toml`)
- **What it is:** A simple Point of Sale (POS) system. 🟢 (`README.md`: "A simple Point of Sale")
- **Base framework:** Laravel `5.6.39` (constraint `5.6.*`), built on top of the `salipropham/laravel55-admin` scaffolding that provides authentication and the admin UI shell. 🟢 (`composer.json`, `config/admin.php`, `routes/web.php` → `Admin::registerAuthRoutes()`)
- **Language runtime:** PHP `7.4.33`. 🟢 (`composer.json` → `"php": "7.4.33"`)
- **Default landing route:** `/` redirects (301) to `/pos`. 🟢 (`routes/web.php`)

---

## 2. Languages

| Language | Extensions | Approx. files | Confidence |
|----------|------------|--------------|------------|
| PHP | `.php` | ~142 (tracked, excl. `vendor/`, `public/`) | 🟢 |
| Blade templates | `.blade.php` | 31 | 🟢 |
| JavaScript / Vue | `.js`, `.vue` | ~4 (frontend assets) | 🟢 |
| SCSS | `.scss` | 2 | 🟢 |

**Primary language:** PHP. 🟢

> Note: the file counts above exclude the vendored Composer dependencies (`vendor/`, ~7.8k files) and compiled/public assets (`public/`, ~299 files). Python/shell files present in the tree belong to `.reversa/` and `openspec/` tooling, not to the application.

---

## 3. Directory structure (top level)

```
app/            Application code (Console, Exceptions, Http, Models, Providers)
bootstrap/      Framework bootstrap (app.php)
config/         Laravel + admin configuration (14 files)
database/       Migrations (27), seeds (2), factories
deploy/         Deployment assets (cron.d/tnx-pos-dev)
docker/         Dockerfiles + apache/nginx configs + entrypoint
openspec/       (pre-existing spec tooling — not part of Reversa)
public/         Web root (index.php + assets)
resources/      Blade views (31), assets (js/sass), lang (en, vi)
routes/         web.php, api.php, console.php
scripts/        setup scripts
storage/        Framework storage
tests/          PHPUnit tests (Feature/OrderControllerTest.php)
```
🟢 (`find` on the tracked tree)

### `app/` layout (technical layering, not domain folders)

```
app/Console/Commands/CustomerOrderSummaryLogging.php
app/Console/Kernel.php
app/Exceptions/
app/Http/Controllers/   (13 controllers + Auth/ + bootstrap.php)
app/Http/Middleware/    (6 middleware)
app/Models/             (12 Eloquent models)
app/Providers/
app/helpers.php
```
🟢

---

## 4. Modules / business domains

Domains are inferred from the resource controllers, Eloquent models, and route groups. There are **no top-level domain folders** — Laravel's standard technical layering is used. 🟡 (inferred grouping)

| Module | Controller | Primary model(s) | Route surface (from `routes/web.php`) |
|--------|-----------|------------------|----------------------------------------|
| `auth` | `Auth/*` | — | `Admin::registerAuthRoutes()` 🟢 |
| `dashboard` | `DashboardController` | — | `resource /dashboard` 🟢 |
| `pos` | `PosController` | — | `resource /pos`, `/pos/scan` 🟢 |
| `products` | `ProductController` | `Product`, `ProductUnit`, `Discount` | `resource /products`, `/products/get-price` 🟢 |
| `customers` | `CustomerController` | `Customer`, `CustomerOrderSummary` | `resource /customers`, `/customers/scan`, `/{customer}/orders`, `/check-gift`, `/gift-received`, `/statistic`, `/debt`, `/redeem-points`, `/debts`, `/repayments` 🟢 |
| `orders` | `OrderController` | `Order` | `resource /orders`, `/orders/scan`, `/{order}/print`, `/{order}/note` 🟢 |
| `debts` | `DebtController` | `CustomerDebt` | `/debts` (index) 🟢 |
| `gifts` | `GiftController` | `Gift` | `resource settings/gifts`, `/gifts/scan` 🟢 |
| `brands` | `BrandController` | `Brand` | `resource settings/brand` 🟢 |
| `categories` | `CategoryController` | `Category` | `resource settings/categories` 🟢 |
| `units` | `UnitController` | `Unit` | `resource settings/units` 🟢 |

Other models seen: `Setting`, `Unit`, `ProductUnit`, `Discount`, `CustomerDebt`, `CustomerOrderSummary`. 🟢 (`app/Models/`)

The `brand`, `categories`, `units`, and `gifts` resources are nested under a `settings/` route prefix. 🟢

---

## 5. Entry points

| Path | Type | Confidence |
|------|------|------------|
| `public/index.php` | HTTP web entry | 🟢 |
| `artisan` | CLI entry | 🟢 |
| `server.php` | PHP built-in server shim | 🟢 |
| `bootstrap/app.php` | Framework bootstrap | 🟢 |
| `app/Console/Kernel.php` | Scheduler (see §8) | 🟢 |
| `routes/web.php` | Web routes | 🟢 |
| `routes/api.php` | API routes (only `auth:api` `/user`) | 🟢 |
| `routes/console.php` | Console routes | 🟢 |

---

## 6. Database (surface only)

- **Engine:** MariaDB 10.11.13. 🟢 (`config/database.php` `DB_CONNECTION=mysql` is Laravel's driver name, shared by MySQL/MariaDB; actual engine confirmed as MariaDB)
- **ORM:** Eloquent — 12 models under `app/Models/`. 🟢
- **Migrations:** 27, spanning `2016_01` (admin tables) through `2026_08` (settings, product units, customer debts). 🟢 (`database/migrations/`)
- **Seeds:** `DatabaseSeeder`, `MenuTableSeeder`. 🟢 (`database/seeds/`)
- Detailed schema/ERD analysis is deferred to `reversa-data-master`. 🟡

Key recent migration themes (2022–2026): reward points, earned points on orders, wholesale prices, gifts + customer-gift pivot, customer order summary, settings table, product units, customer debts. 🟢 (migration filenames)

---

## 7. Tests

- **Framework:** PHPUnit 7. 🟢 (`composer.json` require-dev, `phpunit.xml`)
- **Test files:** 1 feature test — `tests/Feature/OrderControllerTest.php` (plus `TestCase.php`, `CreatesApplication.php` scaffolding). 🟢
- **Coverage:** Effectively minimal at the surface — a single feature test. 🔴 (real coverage requires deeper analysis / execution)

---

## 8. Scheduling & background work

- `App\Console\Kernel::schedule()` registers a **daily** closure calling `Order::summaryLogging()`. 🟢 (`app/Console/Kernel.php`)
- A dedicated Artisan command exists: `CustomerOrderSummaryLogging`. 🟢 (`app/Console/Commands/`)
- Cron is driven externally: `deploy/cron.d/tnx-pos-dev` runs `php artisan schedule:run` every minute (documented in `README.md`, timezone Asia/Ho_Chi_Minh). 🟢

---

## 9. CI/CD & deployment

- **GitLab CI:** `.gitlab-ci.yml` with a single `pos-dev` job (stage `deploy`) that redeploys and reinstalls the cron file on every deploy. 🟢
- **Docker:** `docker/Dockerfile`, `docker/docker-compose.yml`, `docker/apache/` (Dockerfile + `laravel.conf`), `docker/nginx/default.conf`, `docker/entrypoint.sh`. 🟢
- Runs as `www-data` (Apache/mod_php). 🟢 (`README.md`)

---

## 10. External integrations

- **None detected at the surface.** No third-party HTTP clients, payment gateways, or messaging providers were found in configuration or dependencies. Image handling is local via `intervention/image`. 🟡 (inferred from dependencies + config; confirm during excavation)

---

## 11. Notes / gaps for later phases

- 🔴 The single PHPUnit test suggests low automated coverage — validate whether business rules are tested elsewhere.
- 🟡 Barcode/scan endpoints (`/pos/scan`, `/orders/scan`, `/customers/scan`, `/gifts/scan`) hint at hardware/barcode workflows — to be detailed by the Archaeologist.
- 🟡 The `salipropham/laravel55-admin` package supplies menus, RBAC, and auth; its behavior must be read from `vendor/` when interpreting permissions (Detective phase).
