# Domain Rules ## Portfolio ### Current implementation - A project must belong to one category - Categories cannot be deleted while linked projects exist - Public portfolio pages only show published projects - Category filters only use active categories - Project content is localized across `ar` , `en` , `de` - Project sections and assets are ordered by `sortOrder` - Project view mode is limited to: - `GRID` - `STORY` - `CASE_STUDY` ## Media ### Current implementation - Media assets are tracked separately from portfolio records - Media usage bindings connect assets to entity fields - Usage binding is unique by `usageType + entityType + entityId + fieldKey` - Media is currently used by: - portfolio cover - portfolio sections - portfolio assets - site settings ## Contact ### Current implementation - Contact submission requires valid name, email, and message - Turnstile is optional and controlled by settings - Rate limiting is optional and keyed by hashed client IP plus time window - Successful submission sends email only - No submission record is stored in the database ## Admin ### Current implementation - Admin access depends on environment configuration - Middleware can require HTTP Basic Auth before app access - In-app admin session is cookie-based - Repeated failed password attempts trigger temporary lockout ## Configuration ### Current implementation - Global settings are stored in `AppConfig` - Site settings, SMTP settings, contact protection, marquee settings, and maintenance mode all depend on configuration keys ## Recommended Improvements - Add explicit domain rules for future `products` , `orders` , `downloads` only after data models exist - Introduce database retention and moderation rules for contact or inquiry submissions if they become persisted