Digilibrary · loading case study

Portfolio case study · 2024

Digilibrary 

Digital Library & e-Repository Management System for Brit College of Engineering & Technology (BCET) — one PHP + MySQL core, three role-based experiences, wrapped in a zero-reload AJAX UI with a Firebase mirror and SMTP mail engine.

PHPJavaScript + AJAXMySQL FirebaseSMTP MailMobile-first UI
3ROLES · ADMIN / STAFF / STUDENT
12AJAX ENDPOINTS
0FULL-PAGE RELOADS
scroll
01 · Overview

A college library, reborn online

BCET needed one place where every eBook, PDF, journal and request lives — managed by admins, trusted by staff, and readable by students on any phone.

The problem

  • Books & PDFs scattered across drives, CDs and paper registers.
  • Students could only read inside the physical library, in library hours.
  • No role control — everyone shared one password, or none.
  • Book requests & notices travelled by paper and phone calls.

The solution

  • One admin panel to upload, categorise and host every eBook / PDF.
  • Student login with an online reader — stream, favourite, request.
  • Permission badges per staff member, enforced server-side.
  • AJAX everywhere: search, tables, mail and settings never reload the page.

Project facts

Client
BCET
Role
Full-stack · design → deploy
Author
developersazzad
Stack
PHP · JS/AJAX · MySQL · Firebase · SMTP
Database
8 core tables
Delivery
6 weeks, solo
02 · Roles & permissions

One system, three doors

Every login lands in a different world, powered by the same AJAX core. Permissions are stored per user and re-checked on every single API call.

Admin

Owns everything: uploads books & PDFs, creates students and staff, assigns rights, sends mail, tunes SMTP and re-skins the whole panel.

create_studentcreate_bookedit_bookmail_studentmanage_staff

Staff

A staff account only sees what the admin badges it with. Rights toggle live from the staff table — no redeploy, no reload.

create_studentedit_studentcreate_bookedit_bookmail_student

Student

Logs in, browses the shelf, streams books in the browser, hearts favourites, and fires book requests straight to the admin's panel.

read_bookfavoriterequest_bookmail_admin
03 · Functionality

Everything the panel actually does

Switch between the three surfaces. Every button below exists in the shipped product — the screenshots are real.

  • eBook / PDF pipelineCover + PDF upload with author, publisher, year, category; host-state and file-size tracked per book.
  • Zero-reload CRUDEdit, activate, delete on every table row via fetch() — DataTables with server-side search, export to Copy / Excel / PDF.
  • Students & staff desksCreate accounts, watch activity trails, mail any student or staff member from the row itself.
  • Permission engineBadge-style rights per staff (create_student, edit_book, mail_student…) toggled live and enforced in PHP.
  • SMTP control panelHost, port, mail, app-password saved from the dashboard; last-update stamp shows the live config.
  • Theme engineLight / colour / dark / gradient skins for sidebar & header, plus transparent bg-image styles.
Admin eBook and PDF manager table
eBook / PDF manager — server-side search, host state, one-click actions
  • Role-aware loginOne login form, three destinations. Sessions are guarded on every endpoint.
  • Online readerPDFs stream in chunks over HTTP Range requests — the book opens in seconds, not minutes.
  • Favourite shelfHeart any book; the favourite counter on the student dashboard updates instantly.
  • Book requestMissing title? One AJAX call files the request and alerts admin + staff.
  • Mail the adminDirect SMTP-backed channel from the student dashboard.
  • Activity trailEvery read, request and login is logged — visible to admin per student.
Student dashboard with book cards
Student dashboard — shelf meter, cover cards, favourite & read actions
  • Server-side tablesDataTables wired to PHP: search, paging and sorting query MySQL directly — no client bloat.
  • Firebase mirrorUploads sync to Firebase Storage and auth tokens verify client sessions — cloud backup out of the box.
  • SMTP queueApprovals, requests and admin notices are templated mails sent through the configured relay.
  • Live countersTotal PDFs, students, staff, categories, online students and today's open books — polled over AJAX.
  • Hardened uploadsMIME + size validation, hashed passwords, CSRF-safe posts, permission re-checks server-side.
  • Mobile-first skinEvery table, card and reader reflows from 360 px up; touch targets ≥ 44 px.
Dark mode admin dashboard with SMTP panel
Dark skin + SMTP configuration panel, saved without a reload
04 · Architecture

How a click becomes a row, a file, a mail

Plain PHP endpoints behind a fetch()-driven front end, MySQL as the source of truth, Firebase as the cloud mirror, SMTP as the voice of the system.

Student browserreader · requests Admin / Staff panelCRUD · mail · settings Mobile (360px+)same core, touch UI AJAX layerfetch() · FormDataJSON in / JSON out PHP 8 API12 endpointsrole guards · validation MySQL8 tablessource of truth Firebasestorage mirror · auth SMTP relaygmail:587 · templates
1

Client fires fetch()

Forms serialize to JSON / FormData; tables send search + page params. Nothing ever reloads.

2

PHP validates & guards

Session role + permission badge checked on every endpoint before a single query runs.

3

MySQL writes, Firebase mirrors

Book rows land in MySQL; PDFs sync to Firebase Storage; activity log appended.

4

UI patches + mail queues

JSON response patches the DOM, toast confirms, and SMTP mails the humans who care.

usersroles_permissionsbooks categoriesbook_requestsfavorites activity_logssettings
06 · Challenges

What fought back, and lost

13 MB PDFs on campus-speed Wi-Fi
Chunked Range streaming. The reader requests byte ranges, so page one paints in seconds while the rest streams silently; size meters keep everyone honest.
"This staff should only do some things"
Permission badges as data. Rights live as JSON per staff row, toggled from the table via AJAX, and re-verified in PHP on every request — UI honesty plus server truth.
Shared hosting that eats outgoing mail
Admin-owned SMTP panel. Host, port, mail and app-password configurable at runtime with a test-send button; approvals and requests never went silent again.
07 · Results

Launch day, in numbers

Counters below are hydrated by the same AJAX call that powers this page's gallery.

  • Zero full-page reloads across admin CRUD — every create, edit, toggle and mail is a fetch() round-trip.
  • One codebase, three experiences — admin, staff and student surfaces share the same guarded API.
  • Re-skinnable without code — BCET switches sidebar/header skins from Settings, not from a repo.
  • Reading without walls — students read from any phone, any hour; requests reach admin instantly.
next: PWA offline shelfreader highlights & notes native app on same APIreading analytics