This project runs entirely without AWS. It uses PHP + MySQL on XAMPP for the main app and a local browser-based face recognition flow powered by @vladmandic/face-api.
- Teacher and student login
- Student registration with hashed passwords
- Attendance sessions with 6-character live codes
- Teacher-side face enrollment with multiple webcam samples per student
- Student attendance through code + local browser face verification
- Manual teacher attendance fallback
- Attendance history, metrics, and CSV export
- Start
ApacheandMySQLin XAMPP. - Open
http://localhost/phpmyadmin. - Import
database/schema.sqlinto theattendance_systemdatabase. - Open
https://localhost/attendance-app/.
Default teacher credentials:
Username: admin
Password: admin123
The app is configured for secure local use over https://localhost.
- Apache uses a local
localhostcertificate. - Session cookies are sent with
HttpOnly,SameSite=Lax, andSecureover HTTPS. - The app sends security headers including
Content-Security-Policy,X-Frame-Options, andX-Content-Type-Options. - Sensitive face image storage under
storage/is blocked from direct web access.
Important:
- Use
https://localhost/attendance-app/, nothttps://127.0.0.1/..., because the certificate is issued forlocalhost. - If the browser still shows an old warning after certificate changes, fully restart the browser.
- On other devices or Windows accounts, the local certificate must be trusted separately.
No AWS account is needed.
The local face system uses:
assets/dist/face-recognition.jsassets/models/face-api/- webcam access in the browser
If you rebuild frontend assets later, run:
npm.cmd install
npm.cmd run build:faceThe model files must exist in assets/models/face-api. They are already included in this workspace.
The local face settings live in config/app.php.
Useful options:
FACE_REQUIRED_SAMPLES=3
FACE_MIN_CAPTURE_QUALITY=78
FACE_MIN_DETECTION_CONFIDENCE=0.82
FACE_MAX_DESCRIPTOR_DISTANCE=0.48
FACE_CAPTURE_BURST_FRAMES=3
You can either:
- Set them as environment variables before Apache starts.
- Or edit the default values directly in
config/app.php.
Teacher workflow:
- Sign in as teacher.
- Create student accounts in
Students. - Click
Manage Facefor each student. - Capture at least 3 clean webcam samples per student.
- Create an attendance session and share its 6-character code.
- Monitor records or export CSV.
Student workflow:
- Sign in with the student ID and password created by the teacher.
- Enter the 6-character attendance code.
- Complete the webcam face check.
- Attendance is marked if the local descriptor match passes.
- Allow camera access in the browser when testing on
localhost. - The teacher must finish face enrollment before student self-attendance will work.
- This no-AWS version is intended for local deployment on XAMPP and is now hardened for secure local HTTPS use.
- Face verification is still browser-based descriptor matching, so it is not equivalent to a dedicated enterprise liveness platform.
- Good lighting, one visible face, and a steady front-facing pose matter a lot for reliable matches.
- Manual teacher attendance is still available as a fallback.
- Internal folders such as
src,config,views, anddatabaseare protected by Apache access rules. database/schema.sqlmatches the current application code and can be re-imported to rebuild the database from scratch.