You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CRUD APIs exist; no Stripe, credits model, or enforcement
Documentation
Mixed
Production docs current; onboarding/architecture/API docs stale
2. Gap Analysis — General App Software Readiness
2.1 Authentication & Account (Critical)
Gap
Current state
Impact
Google OAuth
UI buttons show demo toast only (frontend/src/pages/Login/Login.jsx); backend has GOOGLE_REDIRECT_URL / Auth0 env vars but no routes (backend/app/config.py)
Users expect one-click sign-in; friction at signup
Forgot password
Backend stub always returns success (backend/app/core/router.py); frontend page exists but no route, authService.forgotPassword undefined (frontend/src/pages/ForgotPassword/ForgotPassword.jsx)
Account recovery broken
Email verification
Not implemented
Spam accounts, unverified email changes
Server-side logout
No token blacklist; frontend clears local storage only
Sessions cannot be revoked
Authorization bugs
Avatar upload unauthenticated; any user can CRUD other users; is_active not enforced; RBAC model unused
GET /me → actual: GET /auth/me; PATCH /me → PUT /users/{id}; access TTL "15 min" vs 300 min default; /docs → /api/docs; text upload "no Job" is wrong; missing /voices/*, /tasks/*, billing CRUD
Current database ERD (video_tasks, voices, notification prefs)
User-facing help / FAQ (none exists)
3.5 Recommended doc actions (priority)
Add deprecation banner to architecture.md → point to root README + microservices_lld.md
Rewrite onboarding.md for docker compose up --build as primary path
Regenerate or manually fix api.md against live OpenAPI at /api/docs
Archive backend/SILMA_*, DIALECT_GUIDE.md as historical
Create docs/env-reference.md from .env.production.example + config.py
4. Product Requirements
4.1 Product vision
DabljaAR enables creators, educators, and media teams to dub video content into natural Arabic in minutes — without studios, voice actors, or manual translation. The product must feel as easy as "upload → choose voice → download," while building trust through reliable auth, transparent usage, and timely feedback.
4.2 Target users
Persona
Goal
Success metric
Content creator
Dub YouTube/social clips to Arabic audience
First dubbed video in <15 min
Educator
Translate lecture videos with captions
Accurate transcript + downloadable SRT
SMB media team
Batch-process client content
Team accounts, usage tracking
Casual visitor
Try before buying
Guest preview or free credits
4.3 Product principles
Trust first — real auth, real billing, no demo buttons in production
Progressive disclosure — simple default path; advanced options (voice clone, trim, reprocess) available but not blocking
Feedback loops — users always know job status and when results are ready
Bilingual by default — EN/AR UI with RTL support maintained
4.4 Must-have use cases (P0 — launch blockers)
UC-01: Sign up and sign in with email
Actor: New or returning user
Flow: Register with email/password → receive JWT → land on dashboard
Acceptance: Form validation, rate limiting, remember-me, protected routes work
Gap: Core works; fix authz on user CRUD and avatar upload
Remove or hide demo-only UI (Google, upgrade buttons) until wired
P0
FR-UX-04
Credit cost shown before job submit
P0
FR-UX-05
WCAG 2.1 AA baseline (keyboard nav, focus trap, skip link)
P1
FR-UX-06
Wire forgot-password route (/forgot-password)
P0
4.8 Non-functional requirements
ID
Requirement
Target
NFR-01
API availability
99.5% uptime (production)
NFR-02
Job status latency
<10s perceived update (polling ≤5s or SSE)
NFR-03
Upload limit
Documented max file size/duration per plan
NFR-04
Security
OWASP top 10; no default SECRET_KEY in prod; HTTPS only
NFR-05
Data privacy
GDPR-style account deletion removes S3 objects
NFR-06
i18n
EN + AR for all user-facing strings including errors
NFR-07
Mobile
Responsive layouts on 375px+ viewports
NFR-08
Observability
Job failure alerts in Grafana; user-facing error IDs
NFR-09
Test coverage
E2E happy path in CI; frontend CI re-enabled
4.9 Recommended implementation phases
gantt
title Product Launch Phases
dateFormat YYYY-MM-DD
section Phase1_LaunchBlockers
Fix authz and security :p1a, 2026-07-01, 2w
Wire forgot password plus email :p1b, after p1a, 2w
Credits model and enforcement :p1c, after p1a, 3w
Stripe checkout and webhooks :p1d, after p1c, 3w
Google OAuth :p1e, after p1a, 2w
Remove demo UI hide broken flows :p1f, after p1c, 1w
section Phase2_Engagement
Onboarding wizard :p2a, after p1f, 2w
Email notifications :p2b, after p1b, 2w
In app notification center :p2c, after p2b, 2w
Doc rewrite onboarding api :p2d, after p1f, 2w
section Phase3_Growth
Real time job updates SSE :p3a, after p2c, 3w
Share links and teams :p3b, after p3a, 4w