Skip to content
Omar Aldanaf

Case study

WebDashboard

passcode

Members-only discount club connecting subscribers with local vendors, with role-based dashboards and a shared verification code that rotates every 5 seconds.

Client
passcode (Lebanon)
Industry
Membership & local retail
Status
Live
Home page.

Overview

passcode gives subscribed members discounts across a curated network of local vendors in Lebanon, including restaurants, shops, perfumeries and roasteries. Accounts are created by the team after meeting each member and vendor in person, subscriptions are paid in person, and every discount is verified face to face at the counter with a code that appears identically on the member's and the vendor's screens.

The problem

Members needed one place to see which vendors they can use and at what discount, vendors needed a quick, reliable way to confirm who is entitled to it, and the operators needed full control over accounts, access and money.

What I built

  • Four role-based areas (member, vendor, admin and super admin), each enforced on the server
  • A rotating verification code derived from a per-vendor secret, identical on both screens
  • A redemption ledger with receipts and live financial summaries for every role
  • A fully content-managed public site with a vendor directory and a contact inbox

Key features

  • 01No self-registration: admins create every account and record subscriptions paid in person (Whish Money or cash)
  • 02Admin-controlled access table that decides which member can use which vendor; changes apply instantly on both dashboards
  • 036-digit code generated with HMAC-SHA256 that rotates every 5 seconds, shown beside the member's photo and name for a quick visual check
  • 04Redemptions logged by the vendor or the member, with the discount calculated on the server and receipts attached as proof
  • 05Member dashboard: accessible vendors, live codes, billing history and total saved
  • 06Vendor dashboard: members with access, redemption log, total sales, discounts given and net revenue
  • 07Admin finance: subscription revenue by month, revenue by vendor and discount by member, plus expiry warnings with one-click renewal
  • 08Content-managed homepage, public vendor pages with galleries, a contact inbox and an audit log of every admin action

Architecture

  1. Browser
  2. PHP pages
  3. Role guards
  4. MySQL (PDO)
Architecture: Browser to PHP pages to Role guards to MySQL (PDO)

Screens

How it works, for members and vendors.
Vendor directory with discount rates.
About the club.
Home page on a phone.
How it works on a phone.

Decisions & challenges

Time-based codes, nothing stored

Each code is computed from a vendor secret and the current 5-second window, so there is nothing to store or synchronise, and the secret never leaves the server.

Money logic stays on the server

Discounts are always calculated from the vendor's stored rate and snapshotted on each redemption, never taken from the browser.

Performance & security

Security

  • CSRF tokens on every form, parameterised SQL and escaped output
  • Receipts and photos stored outside public access and served only through permission-checked endpoints
  • Uploads validated by real content type and size

Inventory

Profile

Developer toolkit

  • GitHub

Systems toolkit

System

omar@world01

Client-side command palette. Type help to list commands.

WORLD_01 map

  1. SPAWN // OMAR Spawn Point / About
  2. CRAFTING // STACK Crafting Workshop / Skills
  3. MINE // PROJECTS Project Mine / Projects
  4. LAB // ARCHITECTURE Logic Lab / Architecture
  5. OPS // INFRASTRUCTURE Server Room / Infrastructure
  6. HALL // EXPERIENCE Achievement Hall / Experience
  7. PORTAL // CONTACT Portal / Contact