LBook
Staff-facing library system built with a team of three: catalog books, track students and loans, and put every page behind a login.
LBook is a staff-facing library system. You add books, students and employees, hand a book out against a borrow date and a due date, and read it all back off one dashboard. Staff sign up first: every page behind the menu calls loggedin() in includes/functions.php, which throws the session away after 1800 seconds of quiet. The storage is five MySQL tables, books, students, employees, borrowbooks and user, each defined by a small script in db/ that you open once to create the table.
I built the books pages and the employee pages, and I wrote the staff signup. Adding a loan wrote the borrowbooks row and set books.status to 1 in the same request, so the book list and the dashboard read one column instead of counting open loans. The loan list is a three-table join across students, borrowbooks and books. Three days of commits in June 2024 got the app to that state; the log holds 106 commits, 32 of them mine.
I came back in January 2025 and stripped the starter template’s redundant comments and reformatted the HTML, CSS and JS, in five commits, then fixed the README. What is still wrong is in the issues: md5 passwords kept in the session, no prepared statements anywhere, and a dashboard tile counting a status the book form never writes.
- 1 Five tables, five files books, students, employees, borrowbooks and user, each created by a runnable file in db/.
- 2 One gate on every page loggedin() in includes/functions.php redirects to login.php after 1800 idle seconds.
- 3 The loan list is a join borrow_books_list.php joins students, borrowbooks and books in one query.
- 4 md5 for passwords checking.php hashes the posted password with md5 and keeps the hash in the session.
Overview
What I built
- +Eight add and list pages over five tables, every one of them behind a staff login.
- +Adding a loan wrote the borrowbooks row and set books.status to 1 in the same request.
- +A dashboard of eight stat tiles and four percentage dials, each tile one query.
- +A loan list that joins students, borrowbooks and books, so one row shows the student and the book.
What I rebuilt
- ~Removed a debug print_r that was left in the tree.
- ~Replaced the seven per-day shift checkboxes on the employee form with one three-way shift field.
- ~Took the icons off the list pages.
- ~Stripped the starter template's redundant comments and reformatted the HTML, CSS and JS, in five commits in January 2025.
Known limitations
- !Passwords are md5, and checking.php keeps the same hash in the session for the life of the login.
- !No prepared statements anywhere: the id from ?eid= goes into four SELECTs unescaped, and the list pages delete on a posted id.
- !The dashboard's Unavailable tile counts books.status = 2, but the book form only writes 0 or 1, so that tile reads zero.
Decisions
- 1. One integer for state I chose carry a status column on books, students, employees and borrowbooks, and flip it from the borrow form, Instead of deriving the state in the query, or a lookup table of states, Because each dashboard tile is a SELECT id FROM a table WHERE status = n and the list pages read the same integer, so one column is what every screen already expects.
- 2. A gate in every file I chose call loggedin() from includes/functions.php at the top of all nine pages, with a 1800 second idle timeout, Instead of one front controller or a rewrite rule that checks the session once, Because there is no front controller and no rewrite config, so each page is its own top-level script and the same guard is what sends an expired session back to login.php.
- 3. Tables made by opening a page I chose five scripts under db/ that include config.php and run one CREATE TABLE each, Instead of a single .sql file to import in phpMyAdmin, Because the mysqli connection already lives in config.php, so each script reuses it and echoes whether the table was created.
Timeline
| Version | Date | Description |
|---|---|---|
| v0.1.0 | 2024-06 | Five tables and the eight add and list pages, built over three days of commits. |
| v0.2.0 | 2024-11 | README written up with the dashboard and page screenshots. |
| v0.3.0 | 2025-01 | Debug output removed, template comments stripped, HTML, CSS and JS reformatted. |