A secure PHP/MySQL admissions portal for students, admissions reviewers, sub-admins, and super administrators.
- Public AIT home page and applicant account registration
- Admission-issued student login by email or ID (for example
26BSCS001) - Enrolled student dashboard for subjects, attendance, teachers, exam marks, materials, and password changes
- Apply Online form for identity, contact, academic, program, and quota information
- Required and optional document uploads with one-file-per-field enforcement
- Draft preservation for text fields and accidental refresh/close protection
- Application status timeline and review notes
- Approval-gated branded fee challan
- Bank, university, and candidate challan copies
- Paid challan receipt upload
- Test slip access only after approved application status
- Admin and super-admin authentication
- Super-admin secret-key gate from
.env - Secure admin password recovery
- Application review with approve/reject actions and notes
- Approval generates the student's year/department/roll ID and temporary credential
- Race-safe approval transactions and idempotent action handling
- Sub-admin creation, expiry, profile updates, transfer, and termination
- Glassmorphism dashboard with responsive sidebar and mobile navigation
- Confirmation before sign-out and protection against losing edited modal forms
- PHP 8.x
- MySQL 8.x or MariaDB
- Apache/XAMPP
- HTML5, CSS3, JavaScript
- Bootstrap 5 and Bootstrap Icons
- MySQLi for the established application workflow
- PDO with native prepared statements for admin authentication and recovery
- GD, Fileinfo, and OpenSSL PHP extensions
Public pages
pages/home.php, pages/about.php, pages/admissions.php, ...
|
Applicant + student portal
student/log-in.php, student/registration.php
student/dashboard.php, student/student-login.php, student/student-dashboard.php
|
Workflow endpoints
student/submit_application.php
student/upload_challan.php, student/upload_semester_challan.php
student/generate_challan.php, student/generate_semester_challan.php, student/generate_slip.php
student/download_file.php
|
Admin portal Staff portal Teacher portal
admin/login.php staff/login.php teachers/login.php
admin/forgot-password.php staff/dashboard.php teachers/dashboard.php
admin/dashboard.php staff/* teachers/*
|
Shared services
backend/security.php
backend/session.php
backend/data.php
backend/pdo.php
backend/rbac.php
backend/site.php
backend/env.php
|
Database
database/schema.sql
|
Error handling
errors/404.php
Every PHP entry point lives under a role-scoped folder — there are no loose workflow scripts at the repository root:
| Folder | Contains |
|---|---|
pages/ |
Public marketing pages rendered through backend/site.php |
student/ |
Applicant login/registration and enrolled-student login, dashboards, and the fee-challan/document workflow endpoints |
admin/ |
Super-admin and sub-admin authentication, review, and management |
staff/ |
Staff (HOD/security/worker/clerical) authentication and dashboard |
teachers/ |
Teacher authentication, dashboard, and class tools |
backend/ |
Shared services: sessions, security/CSRF/CSP/rate limiting, PDO/mysqli, RBAC helpers, public site rendering |
admission/ |
Reserved for future admission-cycle management tooling |
errors/ |
Custom error pages (404.php) |
database/ |
schema.sql |
uploads/ |
Runtime-only file storage (never committed) |
- Public pages have clean URLs such as
/AIT/about,/AIT/programs, and/AIT/admissions; direct.phprequests are canonicalized by.htaccess. - Shared public rendering, database-backed content, CSP bootstrap, and navigation live in
backend/site.php. - Public visual tokens and responsive layouts live in
assets/css/public.css;assets/js/theme.jspersists the light/dark preference asait-themeacross public and portal pages. - GitHub Actions validates PHP syntax, tracked-file whitespace, and the public rewrite map on every push and pull request through
.github/workflows/ci.yml. - Public presentation entry points live under
pages/;student/,admin/,staff/, andteachers/hold every authentication and workflow endpoint, while.htaccessserves nested public pages (and legacy flat-file links from those endpoints) through clean URLs. robots.txtandsitemap.xmlare served from the project root for search engines; private/authenticated pages send<meta name="robots" content="noindex, nofollow">.
erDiagram
STUDENTS ||--o{ APPLICATIONS : submits
STUDENTS ||--o{ STUDENT_SUBJECTS : enrolls
SUBJECTS ||--o{ STUDENT_SUBJECTS : contains
STUDENTS ||--o{ ATTENDANCE : records
STUDENTS ||--o{ EXAM_MARKS : receives
APPLICATIONS ||--o{ DOCUMENTS : contains
APPLICATIONS ||--|| CHALLANS : receives
APPLICATIONS ||--o{ APPLICATION_STATUS_HISTORY : records
ADMINS ||--o{ APPLICATIONS : reviews
APPLICATIONS }o--|| ADMISSIONS_CYCLES : belongs_to
APPLICATIONS }o--|| CAMPUSES : selects
APPLICATIONS }o--|| FACULTIES : selects
APPLICATIONS }o--|| PROGRAMS : selects
| Path | Responsibility |
|---|---|
student/dashboard.php |
Authenticated applicant dashboard and Apply Online form |
student/submit_application.php |
Validates and stores applications/documents/challan transactionally |
student/upload_challan.php |
Stores paid challan receipt and preserves approved status |
student/generate_challan.php |
Renders the branded fee voucher |
student/student-dashboard.php |
Enrolled-student dashboard: subjects, attendance, marks, semester challans |
admin/login.php |
Admin authentication and super-admin key verification |
admin/forgot-password.php |
Protected super-admin password recovery |
admin/dashboard.php |
Application review and admin operations |
backend/security.php |
CSRF, CSP, rate limiting, and upload validation |
backend/session.php |
Secure session bootstrap, fingerprinting, and expiry |
backend/pdo.php |
Strict PDO connection for authentication operations |
errors/404.php |
Site-wide 404 page (route-agnostic, computes its own base path) |
database/schema.sql |
Schema, constraints, indexes, and reporting views |
- CSRF token required on state-changing forms.
- CSP nonce generated per response for inline scripts/styles.
- Prepared statements with MySQLi or native PDO prepares.
- Admin sessions regenerate after successful login.
- Admin records must be active and within their expiry window.
- Super-admin login and recovery require
SUPERADMIN_SECRET_KEY. - Login, recovery, uploads, and admin actions are rate limited.
- Approval uses
FOR UPDATErow locks and transactions. - Challans are unique per application and action requests are idempotency guarded.
- Uploaded images are MIME inspected, dimension checked, and re-encoded to WebP.
- PDFs must have an application/pdf MIME type and
%PDF-signature. - Upload directories block PHP and other executable extensions.
- Production deployments should add antivirus scanning such as ClamAV for uploaded documents.
Sample dashboard and document visuals are stored in assets/images/dashboard_sample/ and assets/images/ait_sample_doc/. The application is demonstrated by running the local setup and walking through registration, application submission, super-admin approval, challan generation, and receipt upload.
- Production target:
https://ait.ahmershah.dev/at the domain root. Local development runs under the/AIT/XAMPP subfolder, so.htaccess(RewriteBase,ErrorDocument) andsitemap.xml/robots.txtassume a root deployment in production — update every/AIT/reference in.htaccessto/(andRewriteBaseto/) when cutting over to the real vhost. - Terminate TLS at Apache or the reverse proxy and redirect HTTP to HTTPS in the production virtual host.
- Use a least-privilege database account and rotate
SUPERADMIN_SECRET_KEY. - Keep
.env, uploads, database backups, and logs outside public download paths. - Configure PHP with
display_errors=0, secure cookie defaults, and centralized error logging. - Add antivirus scanning before uploaded files are made available to staff.
sitemap.xml/robots.txtreferencehttps://ait.ahmershah.dev; update them if the production domain changes.
See SECURITY.md for reporting and operational guidance.
- Install PHP 8.x with
mysqli,pdo_mysql,fileinfo,gd, andopenssl. - Start Apache and MySQL.
- Import
database/schema.sqlinto MySQL. - Copy
.env.exampleto.envand set database credentials and a strong secret key. - Ensure
uploads/is writable by the web server and not executable. - Open the project through Apache, for example
http://localhost/AIT/.
Example configuration:
DB_HOST=localhost
DB_USER=ait_user
DB_PASS=replace-with-a-strong-password
DB_NAME=ait
SUPERADMIN_SECRET_KEY=replace-with-a-long-random-secretNever commit .env, database dumps, uploaded documents, or generated credentials.
Admin login is at admin/login.php. Super-admin accounts require both their account password and the configured .env secret key. Password recovery is at admin/forgot-password.php and requires the same secret key.
The schema seeds the support super-admin account only when the database import is run. Rotate that password immediately in a real deployment.
Run syntax checks on changed PHP files:
php -l admin/login.php
php -l admin/forgot-password.php
php -l admin/dashboard.php
php -l student/dashboard.php
php -l student/submit_application.php
php -l student/upload_challan.php
php -l student/generate_challan.php
git diff --check- SECURITY.md: security controls and vulnerability reporting
- llms.txt: concise machine-readable project context
- llms-full.txt: detailed architecture and change constraints
- LICENSE.txt: MIT license
sitemap.xml/robots.txt: search-engine discovery for the public pages athttps://ait.ahmershah.dev