Konco adalah arsitektur microservice dua-repo — dazo-whitelist (web app) dan dazo-whitelist-api (Meta API engine) — yang berkomunikasi via REST API diamankan RSA signature + Passport Bearer Token. Meta Graph API v20.0 sepenuhnya diisolasi di API engine.
Diagram alur
┌────────────────────────────────────────────────────────────────────────┐
│ DAZO-WHITELIST (Konco Web) │
│ Frontend Web App / SaaS (Port 8000) │
│ │
│ Browser ─── Livewire/Blade ─── Controllers (thin) ─── Services │
│ │ │
│ │ App\Src\MyApi / FacebookApi │
│ │ (GuzzleHTTP + RSA sign + Bearer) │
│ Reverb WS ◄── Events ◄── Observers │ │
│ Schedule:work ───── Cron jobs ─────┘ │
└───────────────────────────────────┬────────────────────────────────────┘
│ POST /api/application/token (RSA)
│ Authorization: Bearer {PassportToken}
▼
┌───────────────────────────────────────────────────────────────────────┐
│ DAZO-WHITELIST-API (Port 8081) │
│ Dedicated Meta Marketing API Engine │
│ │
│ ValidateSignature (signed URL) ─── Auth:api (Passport) ─── myapi │
│ │ │
│ Controllers ─── Services ─── Jobs (Queue) │
│ │ │
│ │ FacebookApiService (php-business-sdk ^20.0) │
│ │ FacebookTokenManagerService │
│ │ FacebookImportService │
│ │ TransferBalanceService │
│ ▼ │
│ Meta Graph API v20.0 ──── 🌐 Facebook Servers │
└───────────────────────────────────────────────────────────────────────┘Separation of concerns
| Aspek | dazo-whitelist (Web) | dazo-whitelist-api (Engine) |
|---|---|---|
| Fokus | UX, business logic, billing, role, invoicing | Koneksi Meta Graph, token lifecycle, import massal, mutasi spend cap |
| UI | Livewire 2.x + Blade + Bootstrap 4 + CoreUI 5 | Tidak ada — REST API only |
| Auth end-user | Session guard member + guard admin + Google 2FA | Tidak ada — hanya Passport client_credentials |
| Database | PostgreSQL (default) | MySQL / MariaDB |
| Background jobs | Sync (Queue sync) — scheduler jalan via schedule:work | Database queue — import massal via ImportAdAccountsJob |
| Realtime | Laravel Reverb + Echo + Pusher JS | Tidak ada |
| Meta Graph | Tidak langsung — via API engine | Langsung via facebook/php-business-sdk ^20.0 |
Lapisan dazo-whitelist (web app)
Browser
│
▼
Livewire Components (app/Http/Livewire/) ─── real-time UI, polling
│
▼
Controllers (app/Http/Controllers/) ─── thin, delegasi ke Services
│
▼
Services (app/Services/) ─── business logic layer
├── OrderService # subscribe & topup
├── PaymentService # gateway integration
├── AdminRequestService # approval workflow
├── TeamService # team management
├── PermissionService # role/permission
└── MonitpayService # MonitPay specific
│
▼
App\Src\MyApi / FacebookApi ─── GuzzleHTTP ke API engine
│ + RSA sign + Passport Bearer
▼
dazo-whitelist-api (port 8081)Lapisan dazo-whitelist-api (engine)
REST Request (from dazo-whitelist)
│
▼
Middleware stack
├── auth:api (Passport Bearer token)
└── myapi (cek header public-key vs user->public_key)
│
▼
Controllers (app/Http/Controllers/)
├── ApplicationController # RSA verify, token issue
├── FacebookOAuthController # OAuth URL, callback, accounts
├── FacebookBusinessController # BM fetch/import/rename
├── FacebookAdAccountController # campaigns, adsets, ads, status, budget
├── FacebookImportController # import jobs progress/cancel
├── AccountController # spend cap, balance, insight, rename
├── BusinessController # BM operations
└── TransferBalanceController # transfer saldo antar-akun
│
▼
Services (app/Services/)
├── FacebookApiService # wrapper Meta Graph SDK
├── FacebookTokenManagerService # token rotation & validation
├── FacebookImportService # chunked import logic
└── TransferBalanceService # atomic balance mutations
│
├──► Jobs (app/Jobs/)
│ ├── ImportAdAccountsJob # background import massal
│ ├── SyncAccount # sync data akun
│ └── TransferBalanceJob # eksekusi transfer via queue
│
▼
Meta Graph API v20.0 (via php-business-sdk)Scheduler (dazo-whitelist)
Scheduler berjalan via php artisan schedule:work (dimulai oleh local:start). Definisi ada di app/Console/Kernel.php:
| Command | Frekuensi | Fungsi |
|---|---|---|
cron:ads-expired | Tiap menit | Reminder email H-7/H-3/H-1 ke member + grace notification 30D + auto-deactivate akun lewat grace |
expiry:order | Tiap menit | Batalkan order/invoice belum dibayar melewati batas waktu |
monitpay:sync | Tiap 2 menit | Sinkronisasi status transaksi MonitPay (timeout 5 menit) |
meta:monitor | Tiap 30 menit | Monitoring status & metrik akun iklan Meta (log storage/logs/meta-monitor.log) |
ads:sync-active-campaigns | Tiap jam | Sinkronisasi status kampanye aktif dari Meta API |
notify:subscription-reminder --interval=3600 | Tiap jam | Reminder ke admin untuk order paid belum diproses + reminder withdraw |
| Scheduled export | Harian 07:00 | Dispatch SendScheduledAdsExportJob untuk jadwal AdsExportSchedule daily & weekly |
Scheduler (dazo-whitelist-api)
Hanya satu scheduled command di API engine:
| Command | Frekuensi | Fungsi |
|---|---|---|
facebook:refresh-tokens | dailyAt('02:00') + emailOutputOnFailure('support@konco.id') | Refresh token dengan expires_at <= now()+7 hari, tukar dengan long-lived token (60 hari), tandai needs_reauth=true bila gagal |
Bahasa & konvensi kode
| Aspek | Konvensi |
|---|---|
| Bahasa kode & UI | Indonesia (komentar, field database, label) |
| PSR | PSR-12 untuk PHP |
| Pattern | Service Layer (app/Services/), thin Controllers, Observer pattern |
| Model traits wajib | App\Traits\UUID, App\Traits\WithAuthor |
| Frontend real-time | Livewire 2.x + Reverb (WebSocket) |
| Auth | Multi-guard: member (default), admin + Google 2FA |
Yang TIDAK boleh diubah tanpa koordinasi
| Area | Lokasi |
|---|---|
| Payload RSA signature | App\Src\MyApi::get_token ↔ ApplicationController::token — `implode(’ |
| Headers handshake | x-client-key, x-timestamp, x-signature, Authorization: Bearer, public-key |
| Passport token storage | Tabel configs (kolom api_token) di dazo-whitelist |
| Public key client | storage/rsa_keys/public_key.pem ↔ kolom public_key tabel applications di API engine |
| Meta Graph version | FACEBOOK_GRAPH_VERSION=v20.0 (di API engine .env) |
Langkah berikutnya
- Detail database & model? Lihat Database.
- Detail RSA handshake + Passport? Baca Auth & Security.
- Konvensi penulisan kode baru? Lihat Conventions.
- Service eksternal (MonitPay, Crisp, Meta)? Lihat External Services.