System Implementation
Not a tile gallery. Each project is part of a larger story about what I've learned, where I struggled, and how my thinking has evolved over the course of this bachelor.
MoveWise was a SKIL project week group proof of concept: a browser-based quiz application that helps road users refresh traffic knowledge. The objective was to deliver a working demo with clear user/admin role separation, secure authentication, quiz flow, scoring, and reliability measures that could be defended to a stakeholder.
This was group work, but I fully owned the security features. I implemented authentication cookie handling, CSRF protection, rate limiting against brute-force behavior, safer error responses, input validation, and other security controls around the API. I also set up the containers for both the API and the frontend so the application could run as a separated, repeatable environment.
The application was split into a frontend, backend API, and database. The API handled login, role checks, quiz logic, scoring, and protected data access. Sensitive configuration was kept out of source code through environment variables, passwords were handled securely, and the security layer focused on preventing common web application issues such as CSRF, brute-force login attempts, unsafe input, and information leakage through error messages.
This project developed my ability to think about security as part of the application architecture, not as something added at the end. I learned how authentication, cookies, CSRF tokens, rate limits, validation, and container boundaries work together to make a demo defensible instead of only functional.
The main challenge was making security controls fit the team project without blocking the quiz features. I corrected this by treating security requirements as acceptance criteria: login had to use protected cookies, repeated requests had to be limited, state-changing requests needed CSRF protection, and API errors had to stay useful without exposing sensitive implementation details.
A next iteration would add automated security tests, stronger logging and monitoring, HTTPS deployment, and a clearer admin audit trail for content changes and reward assignment.
Year 1 IoT Essentials project designed as a multi-device thermostat system. The objective was to make sensing, control, messaging, and visualization operate as one reliable pipeline instead of separate demos.
Implemented an Orange Pi controller that read BMP280 sensor data, evaluated setpoint logic, and switched the heating circuit through transistor/relay control. A Raspberry Pi Pico handled local LCD output and user input. MQTT connected components with publish/subscribe messaging, and ThingSpeak received telemetry for cloud dashboarding and trend history.
This project developed my ability to reason about distributed systems where hardware and software fail differently. I applied MQTT and Python skills to trace data flow from device to broker to dashboard and confirm message integrity at each hop. This directly strengthened my understanding of end-to-end system behavior across sensor acquisition, edge logic, and cloud telemetry.
The first integration had inconsistent MQTT topic names, which caused intermittent control behavior despite healthy individual modules. I corrected this by enforcing topic contracts, standardizing payload formats, and logging publish/subscribe events on each component to verify delivery order and stale retained messages.
Next iteration would define versioned message schemas, split control and telemetry topics, and add broker-side monitoring plus watchdog logic to handle disconnected nodes safely.
Concreto was our SKIL2 semester 2 hosting project, where we built a production-like hosting environment for a real client. The objective was to create a deployable web platform using modern infrastructure practices, including containerization, automated deployments, controlled network access, and shared storage. The project combined software development with system administration and DevOps concepts, providing experience beyond traditional web development.
By the end of the project, we successfully delivered a working hosting environment. The client website was containerized and could be deployed through our infrastructure instead of relying on manual uploads. We configured the required virtual machines, implemented firewall rules to secure the environment, set up shared storage using NFS, and integrated GitHub Actions with Argo CD to create a GitOps-based deployment workflow.
Throughout the project we held regular meetings with the client to gather feedback and demonstrate progress. The final solution reflected both the technical requirements and the client's expectations, resulting in a deployable platform that could be maintained through version control and automated deployment processes.
My primary responsibility was developing the complete frontend for the Concreto website. In addition, I designed and implemented the GitHub Actions workflow that automatically built the frontend, created a container image, and prepared it for deployment within our hosting environment. This allowed changes to move through a consistent deployment pipeline instead of requiring manual uploads, making the application easier to maintain and deploy.
Beyond frontend development, I collaborated with the team during the infrastructure setup, ensuring that the application integrated correctly with the container platform and deployment workflow.
This project significantly expanded my understanding of how modern applications are delivered. Instead of focusing solely on frontend development, I gained practical experience with containerization, CI/CD pipelines, GitOps deployments using Argo CD, firewall configuration, virtual machine management, and shared storage through NFS.
One of the biggest takeaways was learning that delivering software involves much more than writing code. A successful application also needs reliable deployment, secure infrastructure, repeatable automation, and effective collaboration between developers and system administrators. This project provided valuable hands-on experience with the technologies and workflows commonly used in professional DevOps environments.
Year 2 Application Security project focused on identifying and exploiting real web vulnerabilities with OWASP-driven methodology. The objective was to move from isolated findings to full attack chains with measurable system impact.
Executed reconnaissance and request interception with Burp Suite, manipulated HTTP traffic to test trust boundaries, and validated exploitable paths for SQL Injection, XSS, CSRF, and Command Injection. Findings were documented with payload evidence, privilege level reached, and affected components.
This project developed my ability to think like an attacker and prioritize exploit paths by impact instead of novelty. I applied Burp Suite and HTTP manipulation skills to chain low-severity weaknesses into account takeover and command execution scenarios. This directly strengthened my understanding of how input validation, session handling, and server-side execution controls fail under adversarial pressure.
Early testing was too vulnerability by vulnerability and missed exploit chaining opportunities. I corrected this by mapping trust transitions between endpoints, reusing authenticated context where relevant, and sequencing payloads to escalate from reflected XSS and CSRF weaknesses toward broader compromise.
Year 1 Web Design Essentials and my first real front-end project. The objective was to build a structured multi-section portfolio and make layout behavior stable across desktop and mobile breakpoints.
Implemented semantic HTML structure, CSS layout rules, Flexbox alignment, float-based fallback sections, and Bootstrap utilities where they accelerated responsive spacing and component consistency. The focus was page structure, readable hierarchy, and predictable reflow behavior.
This project developed my ability to translate static page ideas into maintainable layout systems. I applied HTML and CSS skills to build section hierarchy first, then used Flexbox and Bootstrap selectively to control alignment and responsiveness. This directly strengthened my understanding of browser layout calculation, box model side effects, and why small CSS conflicts create large visual regressions.
Initial versions mixed float and Flexbox rules in ways that produced collapse and overflow at breakpoint edges. I corrected this by isolating layout contexts, reducing utility class overuse, and debugging computed styles in browser dev tools before changing global rules.
The full story behind these projects is on the About page, where they came from, what broke, and what they changed about how I work.