Skip to content
This repository was archived by the owner on Sep 29, 2026. It is now read-only.

Repository files navigation

Ahmer Institute of Technology Admissions Portal

A secure PHP/MySQL admissions portal for students, admissions reviewers, sub-admins, and super administrators.

Features

Student experience

  • Public AIT home page and applicant account registration
  • Admission-issued student login by email or ID (for example 26BSCS001)
  • Enrolled student dashboard for subjects, attendance, teachers, exam marks, materials, and password changes
  • Apply Online form for identity, contact, academic, program, and quota information
  • Required and optional document uploads with one-file-per-field enforcement
  • Draft preservation for text fields and accidental refresh/close protection
  • Application status timeline and review notes
  • Approval-gated branded fee challan
  • Bank, university, and candidate challan copies
  • Paid challan receipt upload
  • Test slip access only after approved application status

Administration

  • Admin and super-admin authentication
  • Super-admin secret-key gate from .env
  • Secure admin password recovery
  • Application review with approve/reject actions and notes
  • Approval generates the student's year/department/roll ID and temporary credential
  • Race-safe approval transactions and idempotent action handling
  • Sub-admin creation, expiry, profile updates, transfer, and termination
  • Glassmorphism dashboard with responsive sidebar and mobile navigation
  • Confirmation before sign-out and protection against losing edited modal forms

Technology

  • PHP 8.x
  • MySQL 8.x or MariaDB
  • Apache/XAMPP
  • HTML5, CSS3, JavaScript
  • Bootstrap 5 and Bootstrap Icons
  • MySQLi for the established application workflow
  • PDO with native prepared statements for admin authentication and recovery
  • GD, Fileinfo, and OpenSSL PHP extensions

Architecture

Public pages
  pages/home.php, pages/about.php, pages/admissions.php, ...
        |
Applicant + student portal
  student/log-in.php, student/registration.php
  student/dashboard.php, student/student-login.php, student/student-dashboard.php
        |
Workflow endpoints
  student/submit_application.php
  student/upload_challan.php, student/upload_semester_challan.php
  student/generate_challan.php, student/generate_semester_challan.php, student/generate_slip.php
  student/download_file.php
        |
Admin portal            Staff portal            Teacher portal
  admin/login.php         staff/login.php          teachers/login.php
  admin/forgot-password.php  staff/dashboard.php    teachers/dashboard.php
  admin/dashboard.php     staff/*                   teachers/*
        |
Shared services
  backend/security.php
  backend/session.php
  backend/data.php
  backend/pdo.php
  backend/rbac.php
  backend/site.php
  backend/env.php
        |
Database
  database/schema.sql
        |
Error handling
  errors/404.php

Project structure

Every PHP entry point lives under a role-scoped folder — there are no loose workflow scripts at the repository root:

Folder Contains
pages/ Public marketing pages rendered through backend/site.php
student/ Applicant login/registration and enrolled-student login, dashboards, and the fee-challan/document workflow endpoints
admin/ Super-admin and sub-admin authentication, review, and management
staff/ Staff (HOD/security/worker/clerical) authentication and dashboard
teachers/ Teacher authentication, dashboard, and class tools
backend/ Shared services: sessions, security/CSRF/CSP/rate limiting, PDO/mysqli, RBAC helpers, public site rendering
admission/ Reserved for future admission-cycle management tooling
errors/ Custom error pages (404.php)
database/ schema.sql
uploads/ Runtime-only file storage (never committed)

Public delivery conventions

  • Public pages have clean URLs such as /AIT/about, /AIT/programs, and /AIT/admissions; direct .php requests are canonicalized by .htaccess.
  • Shared public rendering, database-backed content, CSP bootstrap, and navigation live in backend/site.php.
  • Public visual tokens and responsive layouts live in assets/css/public.css; assets/js/theme.js persists the light/dark preference as ait-theme across public and portal pages.
  • GitHub Actions validates PHP syntax, tracked-file whitespace, and the public rewrite map on every push and pull request through .github/workflows/ci.yml.
  • Public presentation entry points live under pages/; student/, admin/, staff/, and teachers/ hold every authentication and workflow endpoint, while .htaccess serves nested public pages (and legacy flat-file links from those endpoints) through clean URLs.
  • robots.txt and sitemap.xml are served from the project root for search engines; private/authenticated pages send <meta name="robots" content="noindex, nofollow">.

Database relationships

erDiagram
  STUDENTS ||--o{ APPLICATIONS : submits
  STUDENTS ||--o{ STUDENT_SUBJECTS : enrolls
  SUBJECTS ||--o{ STUDENT_SUBJECTS : contains
  STUDENTS ||--o{ ATTENDANCE : records
  STUDENTS ||--o{ EXAM_MARKS : receives
  APPLICATIONS ||--o{ DOCUMENTS : contains
  APPLICATIONS ||--|| CHALLANS : receives
  APPLICATIONS ||--o{ APPLICATION_STATUS_HISTORY : records
  ADMINS ||--o{ APPLICATIONS : reviews
  APPLICATIONS }o--|| ADMISSIONS_CYCLES : belongs_to
  APPLICATIONS }o--|| CAMPUSES : selects
  APPLICATIONS }o--|| FACULTIES : selects
  APPLICATIONS }o--|| PROGRAMS : selects
Loading

Important files

Path Responsibility
student/dashboard.php Authenticated applicant dashboard and Apply Online form
student/submit_application.php Validates and stores applications/documents/challan transactionally
student/upload_challan.php Stores paid challan receipt and preserves approved status
student/generate_challan.php Renders the branded fee voucher
student/student-dashboard.php Enrolled-student dashboard: subjects, attendance, marks, semester challans
admin/login.php Admin authentication and super-admin key verification
admin/forgot-password.php Protected super-admin password recovery
admin/dashboard.php Application review and admin operations
backend/security.php CSRF, CSP, rate limiting, and upload validation
backend/session.php Secure session bootstrap, fingerprinting, and expiry
backend/pdo.php Strict PDO connection for authentication operations
errors/404.php Site-wide 404 page (route-agnostic, computes its own base path)
database/schema.sql Schema, constraints, indexes, and reporting views

Security model

  • CSRF token required on state-changing forms.
  • CSP nonce generated per response for inline scripts/styles.
  • Prepared statements with MySQLi or native PDO prepares.
  • Admin sessions regenerate after successful login.
  • Admin records must be active and within their expiry window.
  • Super-admin login and recovery require SUPERADMIN_SECRET_KEY.
  • Login, recovery, uploads, and admin actions are rate limited.
  • Approval uses FOR UPDATE row locks and transactions.
  • Challans are unique per application and action requests are idempotency guarded.
  • Uploaded images are MIME inspected, dimension checked, and re-encoded to WebP.
  • PDFs must have an application/pdf MIME type and %PDF- signature.
  • Upload directories block PHP and other executable extensions.
  • Production deployments should add antivirus scanning such as ClamAV for uploaded documents.

Screenshots and demo assets

Sample dashboard and document visuals are stored in assets/images/dashboard_sample/ and assets/images/ait_sample_doc/. The application is demonstrated by running the local setup and walking through registration, application submission, super-admin approval, challan generation, and receipt upload.

Production deployment

  • Production target: https://ait.ahmershah.dev/ at the domain root. Local development runs under the /AIT/ XAMPP subfolder, so .htaccess (RewriteBase, ErrorDocument) and sitemap.xml/robots.txt assume a root deployment in production — update every /AIT/ reference in .htaccess to / (and RewriteBase to /) when cutting over to the real vhost.
  • Terminate TLS at Apache or the reverse proxy and redirect HTTP to HTTPS in the production virtual host.
  • Use a least-privilege database account and rotate SUPERADMIN_SECRET_KEY.
  • Keep .env, uploads, database backups, and logs outside public download paths.
  • Configure PHP with display_errors=0, secure cookie defaults, and centralized error logging.
  • Add antivirus scanning before uploaded files are made available to staff.
  • sitemap.xml/robots.txt reference https://ait.ahmershah.dev; update them if the production domain changes.

See SECURITY.md for reporting and operational guidance.

Setup

  1. Install PHP 8.x with mysqli, pdo_mysql, fileinfo, gd, and openssl.
  2. Start Apache and MySQL.
  3. Import database/schema.sql into MySQL.
  4. Copy .env.example to .env and set database credentials and a strong secret key.
  5. Ensure uploads/ is writable by the web server and not executable.
  6. Open the project through Apache, for example http://localhost/AIT/.

Example configuration:

DB_HOST=localhost
DB_USER=ait_user
DB_PASS=replace-with-a-strong-password
DB_NAME=ait
SUPERADMIN_SECRET_KEY=replace-with-a-long-random-secret

Never commit .env, database dumps, uploaded documents, or generated credentials.

Admin access

Admin login is at admin/login.php. Super-admin accounts require both their account password and the configured .env secret key. Password recovery is at admin/forgot-password.php and requires the same secret key.

The schema seeds the support super-admin account only when the database import is run. Rotate that password immediately in a real deployment.

Development checks

Run syntax checks on changed PHP files:

php -l admin/login.php
php -l admin/forgot-password.php
php -l admin/dashboard.php
php -l student/dashboard.php
php -l student/submit_application.php
php -l student/upload_challan.php
php -l student/generate_challan.php
git diff --check

Documentation

  • SECURITY.md: security controls and vulnerability reporting
  • llms.txt: concise machine-readable project context
  • llms-full.txt: detailed architecture and change constraints
  • LICENSE.txt: MIT license
  • sitemap.xml / robots.txt: search-engine discovery for the public pages at https://ait.ahmershah.dev

About

Ahmer Institute of Technology (AIT) is a PHP and MySQL admissions website for a university-style institution. The project combines a public-facing website, student admissions workflow, and admin review dashboard into one application.

Topics

Resources

Security policy

Stars

5 stars

Watchers

0 watching

Forks

Used by

Contributors

Languages