
The EdTech landscape just shifted. While others are still struggling with basic "school scripts" and messy integrations, we’ve been busy building the future.
Today, we are thrilled to announce the launch of ProjectWorlds Multi-School ERP SaaS V3.6 — the direct successor to V2.0. Rebuilt on Laravel 12 and Flutter 3.x, this version isn't just an update—it’s a complete technological overhaul designed for entrepreneurs who want to dominate the global education market.
🔗 Saas Landing Page : https://demo.multischoolerp.com
🔗 Login Page : https://demo.multischoolerp.com/login
💡 Tip: If the main demo is slow or unavailable, switch to the
backup — both show the identical, full V3.6 experience.
One payment. Seven deliverables.
No add-on modules to unlock later. No hidden dependencies. Every component ships with full, unencrypted source code.
Every module a school needs. Toggle on or off.
Core modules are always available. Toggle optional modules on or off per school to keep the interface clean. 9 new modules shipped in v3.6 — CCTV live view, parent–teacher chat, surveys, compliance and more.
Plus features built inside these modules — Gate Pass & approvals, Campus Workers Register, Exam Datesheet Manager, Export Hub, Storage Center, Support Tickets, off-site backup to your own R2 / B2 / Telegram, and per-school white-label branding.
🚀 What’s New in V3.6? (The Innovation Leap)
If Version 1.0 was about management, Version 3.6 is about Intelligence and Automation. We’ve added heavy-hitting features that separate the "amateurs" from the "enterprise-grade" platforms.
🧠 1. Data-Grounded AI Intelligence
We’ve integrated Gemini & OpenAI models directly into the ERP. But this isn't just a chatbot—it’s "Grounded AI."
➢ Zero Hallucination: The AI reads your specific school data (fees, attendance, grades) to provide factual answers.
➢ Intent Detection: It knows when a parent is asking about "dues" versus "homework" and triggers the correct data fetcher instantly.
➢ Role-Based Privacy: Security is baked in; parents only see their own children’s data.

🚌 2. Dedicated Driver App & Zero-Cost GPS
In V3.0, tracking was a challenge. In V3.6, we’ve launched a standalone Driver App.
➢ No Hardware Needed: Uses the driver's smartphone GPS.
➢ OpenStreetMap Integration: Say goodbye to expensive Google Maps API bills.
➢ Real-time WebSocket Sync: Parents see the bus moving with sub-second accuracy on their app.
🛡️ 3. The Biometric Desktop Bridge (V2 Exclusive)
Stop worrying about Static IPs. Our new Windows Biometric Agent (.EXE) acts as a cloud bridge for ZKTeco devices.
➢ Push Protocol: Logs sync to the cloud automatically.
➢ Cloud Template Sync: Back up and restore fingerprints across different devices from the admin panel.
🎨 4. White-Labeling V2 & Custom Domains
Give your clients a premium experience.
➢ Custom Domain Mapping: Each school can run on its own domain (e.g., www.yis.projectworlds.com).
➢ 6+ Dashboard Themes: Choose from Mac OS style, Futuristic, or Analytics Pro layouts.
➢ Auto-Styling Engine: The system automatically matches UI colors to the school’s uploaded logo.
🛠️ The Tech Stack of 2026
We don't use outdated libraries. V2.0 is built for speed and security:
➢ Backend: Laravel 12 (PHP 8.3+)
➢ Mobile: Flutter 3.x (iOS & Android)
➢ Security: AES-256 Encryption for all API keys and credentials.
➢ Optimization: Specifically optimized for low-bandwidth 4G/5G networks (perfect for global scaling).
💼 Your Business in a Box
When you buy the V2.0 Source Code, you aren't just buying a product; you're buying a SaaS Empire.
➢ 100% Unencrypted Source Code: No hidden "premium" locks.
➢ Multi-Tenancy: Manage infinite schools from one Super Admin panel.
➢ Subscription Management: Automated billing via Stripe, Razorpay, and UPI QR Codes.
➢ 1 Year Support & Updates: We’ve got your back for the long haul.
🛠️ The Ultimate Feature Matrix: Everything in V2.0
| Core SaaS & Admin | Academic & Student | Finance & Operations | Logistics & High-Tech |
|---|---|---|---|
| Multi-Tenancy: Unlimited Schools | 360° Student Profiles | Complex Fee Structures | Grounded AI Assistant |
| Custom Domain Mapping | Bulk Import (CSV/Excel) | Stripe/Razorpay/PayPal | Live GPS Driver App |
| 6+ Dashboard Themes | Visual Timetable Builder | UPI QR Code Payments | Biometric Cloud Sync |
| Subscription Billing | Student Promotion Logic | Automated Payroll/Slips | Windows Desktop Agent |
| White-Label Settings | Subject & Teacher Assign | Expense & Income Ledger | WhatsApp API Notify |
| Role-Based Permissions | Syllabus & Study Center | Inventory & Stock Alert | In-App Push Alerts |
| Detailed SaaS Analytics | Class & Section Setup | Hostel & Room Allocation | ZKTeco ADMS Support |
| Custom Menu Manager | Parent-Sibling Linking | Library (Barcode/ISBN) | AES-256 Data Security |
| Addon Management | Digital Admit Cards | Certificate Generator | Multi-Language Support |
| Audit Logs (Security) | Online CBT Exams | Visitor & Postal Logs | Offline/Online Exams |
🌐 Experience the Power: Live Interactive Demos
Explore the V2.0 ecosystem across all platforms. Experience the seamless transition between the web panels and the specialized mobile applications.| 1. Super Admin (SaaS) | 2. School Portals | 3. Mobile Apps & Tools |
|---|---|---|
| Control the Empire | Manage the Institution | On-the-Go Access |
| 🔗 SaaS SuperAdmin Panel | 🔗 Standard Demo (Yug School) | 📱 Student & Parent App |
| ( easy button login quick access ) | 📱 Teacher & Staff App | |
| Demo Video Click Here | 📱 Dedicated Driver App | |
| Landing Page | (Try to create a New school for a better experience with an actual working email so you can receive test notifications properly) | ---(Student, Parent, and Driver app logins can be generated from the school admin panel) |
| Tools & Sync: | Hardware Integration: | |
| 📥 Download Biometric EXE | |
⚙️ Real-time Cloud Sync Enabled Details Biometric Guide |
| Manual Docs Link |
💳 Get Started Today: Purchase & Support
Ready to launch your EdTech empire? Choose your preferred way to connect with us. Whether you are ready to buy or have a few technical questions, our team is standing by.🚀 Direct Purchase
What's Included:- ✅ 100% Unencrypted Source Code
- ✅ All 3 Mobile Apps (Student, Staff, Driver)
- ✅ Biometric Sync Agent (.EXE)
- ✅ 1 Year Updates & Support
📞 Inquiry & Support
Have Questions? Get a quick response. Connect with Us:- 📱 WhatsApp: +91 6263056779
- 📞 Call: +91 6263056779
- 📧 Email: [email protected]
- 🌐 Website: www.projectworlds.com
🛡️ Why Choose ProjectWorlds?
We don't just provide a script; we provide an enterprise-grade foundation.
➢ Scalability: Built on Laravel 12 to handle thousands of schools and millions of students.
➢ Security: AES-256 encryption ensures your school's data and API keys stay private.
➢ Innovation: With integrated Grounded AI and real-time Biometric sync, you are offering technology that traditional ERPs simply cannot match.
📝 Final Checklist Before You Launch
➢ Host the Web Panel: Deploy the Laravel 12 code on your server.
➢ Rebrand the Apps: Change logos and colors in the Flutter source code.
➢ Configure the Agent: Link your ZKTeco devices using the Desktop Sync tool.
➢ Set Your Pricing: Define your SaaS subscription plans and start onboarding schools!
Got Questions? Before you buy (FAQ)
ProjectWorlds is a complete Multi-Tenant School ERP SaaS solution built with Laravel 12 and Flutter. It includes the web application, Student & Parent App, Staff App, Driver App, and Super Admin Panel.
Yes. You can create unlimited schools from one Super Admin Panel.
No. You receive 100% unencrypted source code with full ownership rights according to the license.
Yes.
You may modify every part of the source code.
Yes.
The system is fully white-label.
- Laravel 12 +
- Flutter 3 +
- PHP 8.3+
- MySQL
Yes.
Works on desktop, tablet and mobile browsers.
Three apps are included:
- Student & Parent
- Staff
- Driver
Yes.
Yes.
Yes.
Yes.
You can deploy your modified version for clients, SaaS platforms, and commercial projects under the license terms.
No.
One-time payment.
No royalty.
No.
You may build your own product from it, but the original unmodified source cannot be redistributed as your own product.
Yes.
1 year included.
Yes.
One production installation is included.
- Remote Assistance
- UPI
- Bank Transfer
- International Transfer
Instant Download
Yes.
Unlimited.
Yes.
Yes.
Yes.
Yes.
Yes.
Grounded AI Assistant for school data.
Yes.
REST APIs are included for Flutter applications.
Yes.
Although VPS or Cloud hosting is recommended for production.
Changelog — ProjectWorlds Multi School ERP SaaS
Release Date: 4 August 2026 Previous Version: 3.5.0-beta (23 July 2026) Scope: ~490 files changed across the platform — backend (425), Parent/Student app (37), Staff app (28), Driver app (3)
A big release. Where 3.5.0 was about breadth (CRM, website builder, SMS gateways, ID-card designer), 3.6.0 is about daily-visibility features schools see in a demo (engagement, chat, surveys, gate pass, CCTV) and assessment/attendance depth (Online Exam Pro, biometric ADMS, QR scanner), plus a quiet but important infrastructure win: PDFs no longer need Node.js on the server.
🚀 New Modules
- Surveys & Feedback Engine — One survey engine for the whole platform: builder (9 question shapes), publish to student/parent/staff audiences, reporting with averages/distribution/NPS/trend sparklines, a feedback triage board (assign, prioritise, tag, resolve), recurring cycles, public share links (
/sv/{token}, anonymous + throttled), a 6-template gallery, and an important-survey launch pop-up. Full respond parity in the parent app and staff app. - Student–Teacher Chat — 1-to-1 teacher ↔ student/parent messaging built on MySQL as the single source of truth with FCM used only as the free "wake up" signal (no Firestore, no per-message cost). Threads, participants, moderation/reporting, and push delivery; surfaced in both the parent and staff apps.
- Gate Pass Management (inside Front Office) — Records every non-routine gate crossing: student early-exit and staff short-leave/out-duty passes, an approval chain, QR verification at the gate, a gate terminal, automatic attendance write-back (a student who left at 11 AM is no longer counted Present all day), and parent notifications on exit. Distinct from the existing visitor pass.
- Campus Workers Register (inside Front Office) — A home for the third campus population — contract/daily third-party workers (housekeeping, canteen, security, gardeners). One CRUD screen, a printable badge, and a hook into the gate scanner. One idea keeps it small: a one-day electrician and a six-month contract are the same record — only
valid_todiffers. - Compliance & Governance — A thin governance layer over existing modules (not a rebuild): country-specific Compliance Packs (India-CBSE / India-State / Kenya-CBC / Generic, one-click install per school), a statutory document vault with expiry tracking, validation rules that check data before government export, inspection checklists, rule runs/results/waivers, and a compliance readiness dashboard.
- Engagement & Creatives — The demo-critical "daily delight" module: one publishable entity with a
kind(birthday card, festival banner, thought of the day, ticker, home slider, story, pop-up) rather than nine separate features. Design gallery + render pipeline, automatic birthday and festival greetings with per-school timezone handling, idempotency, push image support, and a run log. - Datesheet Manager (inside Exams) — Build and publish exam datesheets against an
exam_classesscope; parents see nothing until an unscheduled subject is given a date/time and the sheet is published, with a parent notification on publish. - CCTV / Live Surveillance — The school's existing IP cameras, promoted out of the biometric device list into a badged module: a control-room Camera Wall (2×2 / 3×3 / 4×4, fullscreen, live auto-reconnecting tiles), cameras assigned to a class/section, a class-scoped wall for teachers, and — where the school opts in — parent live-view of their own child's classroom. Pure streaming: no recognition, no attendance writes, and no new camera hardware. One idea keeps it honest: a camera is one device with several duties, not three device rows. See "Parent CCTV governance" below for how the parent path is fenced.
📝 Online Exam — "Basic → Pro" upgrade
The single largest work item in this release (175 backend tests passing). The single-shape MCQ module became a professional assessment engine:
- 9 question types with an abstract base, plus rich attachments (audio / video / image / equation / passage / table)
- Three delivery modes — Exam · Quiz · Practice Set
- Sectioned papers, multi-schedule targeting, blueprint + balance meter, draft/publish, and a Quick Setup that is now the only way to build a paper
- Player + grading — 9 renderers, autosave / resume / auto-submit, a manual review queue for subjective answers, re-grade, item analysis (distractor spread, heatmap, leaderboard, CSV), and a calibration engine
- Practice mode — a ladder engine, instant feedback, topic-mastery reporting, retakes, and ad-hoc "practise my weak topics" (guarded so self-practice can never leak an unsat paper)
- Question topics & attachments, a module dashboard, and an illustrated guide
- All four surfaces built — admin web, parent web portal, parent app, and staff app (including the full staff-app paper builder and per-answer marking queue)
🕒 Attendance & Biometric
- Biometric ADMS overhaul — Real ZKTeco/eSSL push protocol (
iclock/cdata) so devices report in without polling, push-users to devices, a device brand catalog, per-device allowed-IP allowlisting, nullable device IP, a school-level punch mode, and a natural-unique index on logs. Dedup is punch-timestamp based. New maintenance commands:biometric:prune-logs,biometric:requeue-stale-commands. - QR Attendance — staff-app scanner ("Plan B") — A phone/tablet scanner inside the staff app treated as a security surface: two scan modes (gate vs classroom) with scoped mark permissions, a self-mark block, a re-arm rule that prevents scan-loops, and an evidence-grade scan-audit viewer (
qr_scan_audits). Teachers no longer get the kiosk permission implicitly.
📹 Parent CCTV governance
A parent watching a classroom is also watching other families' children, so the parent path is fenced deliberately rather than implicitly. Nothing about it is on by default.
- Five independent gates, all required — the school's master switch, the individual camera's opt-in, the camera's class matching the child's class, the parent's acknowledgement of the viewing policy, and the permitted-hours window (evaluated on the school's clock, not the server's). A refusal names its reason, so the app says "available 09:00 – 15:30" rather than a blank "unavailable".
- Stream URLs are short-lived capabilities, not permanent links — every view mints a 5-minute token pinned to one camera and one viewer, validated by the media server on each request. A URL copied out of the app dies within minutes; revoking a session stops playback mid-stream. Turning off a camera's parent flag — or the school-wide switch — ends sessions already running, not just future ones.
- Every view is logged (
cctv_view_logs) — who, which camera, for how long, from where — for all viewer types including school admins. An audit that exempts the most privileged viewer is not an audit. Admins get a filterable Access Log with a live "watching right now" count. - Parents get live video only — no recording, download, export or share affordance exists on the parent surface.
- Split permissions —
cctv.view(whole school) ·cctv.view.own(teacher, their classes only) ·cctv.manage(camera settings + the parent policy) ·cctv.logs.view. Being trusted to watch the cameras is not the same as being trusted to open the school up to parents.
🆔 ID Cards
- Dedicated Student/Staff ID Card module — Promoted out of the certificate engine into its own sidebar section over the existing designer, with a
certificates.categorysplit so ID cards and certificates no longer share one bucket. The old HR StaffIdCard controller/view were retired in favour of the unified engine.
🖨️ Infrastructure — PDF engine migration (no more Node.js on the server)
chrome-php/chromereplaces Browsershot — Every PDF/PNG now renders by driving Chrome directly over the DevTools Protocol from PHP. Node.js + npm + Puppeteer are no longer required on a customer server. All 10 render call-sites funnel through one seam; output quality is unchanged.- Two run modes —
launch(one Chrome per render, default) orpersistent(one shared Chrome, ~2× faster), managed withphp artisan pdf:chrome --status | --stop | --restart. - Safe rollback —
PDF_DRIVER=browsershotkeeps the old Node path working, andPDF_CHROME_PATHfalls back toBROWSERSHOT_CHROME_PATHso existing servers need no edit. NewPdfEngineCheckhealth check;BrowsershotCheckretired. Seedocs/PDF_ENGINE_SETUP.md.
📱 White-Label & Branding
- Per-school white-label push (Tier B) — Each school can supply its own Firebase App ID + API Key (
school_fcm_configs); the four login endpoints return a per-schoolfirebase_configmerged over the global (blank keys inherit). Send path is unchanged — all packages live in one shared Firebase project. - Per-app mobile branding (P0–P4) — Driver, Parent/Student and Staff apps each own their own brand (name, logo, colours) instead of one shared config;
?app=resolution, per-app cache keys, both admin UIs and per-app previews. Blank fields inherit.
☁️ Backup
- Per-school off-site backup (bring-your-own storage) — Each school can connect their own off-site destination — Cloudflare R2, Backblaze B2, or a Telegram bot — so a copy of the nightly backup leaves the server to storage the school controls (3-2-1 rule). Credentials are encrypted per school. The existing one-click restore is untouched; off-site copies feed back into it for disaster recovery.
- Backup Management promoted to a top-level SYSTEM item (out of the Settings & Billing submenu).
👨👩👧 Parent App — home & personalization
- "Today" home screen — A server-decided, band-organised home surface (Today + All-features tabs); bands are ordered by the server and never re-sorted client-side.
- Personalization — Parents can pin features (
parent_pinned_featureson users) and schools can hide features per school (parent_hidden_features); capability gating is derived from the route table + a single feature catalogue rather than a hand-maintained list. - New parent-app features — Chat, Surveys inbox/respond, Online Exam Pro (hub, mastery, practice with instant feedback, answer review, retakes, first-run explainer), Datesheet, and CCTV (camera list for the selected child, policy consent sheet, live player that renews and closes its own session).
👩🏫 Staff App
- New features: Chat, Gate Pass, QR Attendance scanner, Surveys, and Online Exam (paper list/detail/analytics, marking queue, and the full paper builder — 23 staff API routes).
- Firebase push parity added to the staff app (it previously had no
firebase_core/firebase_messaging). - Dashboard analytics widgets and permission map updates.
🚚 Driver App
- Per-app branding wiring and API-service updates aligned with the new branding resolver.
🧭 Menu & Module promotions
- Website Builder, Backup Management, and Biometric promoted to top-level modules with their own permissions/menu groups.
- Apps Center presentation fixes — orphan-category guard, honest badge priority (Popular outranks New), coming-soon toggle, and correct placement under MODULES.
🔐 Security & Correctness fixes
- Parent API IDOR closed — a shared
AuthorizesParentStudenttrait replaces the unguardedStudent::findOrFail($request->student_id)pattern across parent endpoints. - CCTV access has exactly one implementation — every surface (admin wall, teacher wall, parent app, stream-token mint) asks the same service. Access rules for live video of children need one place to audit, not one per controller. Cameras are resolved by school-scoped query, never route-model binding.
- CCTV module registered in the module registry —
cctvwas previously granted through plan features alone, so it could not be disabled per school and did not appear in the module list. Now registered like every other module. - Removed stray duplicate controllers left in the tree (
DashboardController copy.php,AttendanceController(1).php). - Numerous list/report
withSum/withCountordering fixes so aggregate columns render correctly.
🗄️ Data & Infrastructure
- 60+ new migrations (2026-07-28 → 2026-08-04) covering all modules above — surveys, chat, online-exam pro, biometric ADMS, QR audit, gate pass, campus workers, compliance packs, engagement, datesheet, per-school FCM, off-site backup, parent personalization, and CCTV (camera metadata on
biometric_devices, pluscctv_view_logs/cctv_stream_tokens/cctv_parent_consents). - New config files:
pdf.php,online_exam.php,compliance.php,biometric_devices.php,app_branding.php,cctv.php. - New scheduled jobs (already wired in
routes/console.php):surveys:open-due-cycles(06:15),engagement:send-festival-greetings(hourly),compliance:scan-documents(06:30),biometric:prune-logs(03:45),biometric:requeue-stale-commands(every 5 min),cctv:reap-sessions(every 5 min — closes live-view sessions whose viewer vanished, so the access log never claims someone is still watching). - Competitive Gap Register added under
docs/gaps/— all 104 Class ON brochure modules audited against the codebase (68 HAVE / 11 PARTIAL / 25 GAP), plus tiered build plans.
⚠️ Notes for operators
- Run the upgrade guide (
UPGRADE-3.5.0-to-3.6.0.md) — this release adds a Composer dependency (chrome-php/chrome), 60+ migrations, and new permissions/menu items that are created by migration and seeder. - The default PDF driver is now
chrome. Existing servers keep working via theBROWSERSHOT_CHROME_PATHfallback, but confirm on Server Health → PDF Engine after upgrading. - Mobile apps require a rebuild/republish to pick up the new parent/staff features and per-app branding.
- CCTV is safe to leave alone. Parent viewing is off at the school level by default, so upgrading cannot expose a classroom to anyone. Existing cameras keep appearing on the wall (they are opted in to the module by default and opted out of parent viewing). To offer parent live-view, a school assigns cameras to classes under CCTV → CCTV Cameras, then enables the policy there.
- CCTV per-segment stream enforcement is optional but recommended. Set
CCTV_STREAM_AUTH_SECRETand point MediaMTX's external-auth endpoint atPOST /api/cctv/stream-auth(config indocs/cctv-module-plan.md). Without it the module still issues short-lived tokens and logs every view; it just cannot refuse an already-extracted manifest URL before the token expires.
Changelog — v3.5.0-beta
Release Date: 23 July 2026
Previous Version: 3.0.0-beta3
Total Files Changed: 1,282
🚀 New Modules
- Lead Management (CRM) — Full pipeline with sources, stages, scoring, kanban board, document collection, entrance tests, activity timeline, and bulk import
- Support Ticket System — School-to-superadmin ticketing with threaded replies and status tracking
- School Website Builder — Per-school customizable website with pages, sections, navigation, slides, testimonials, and template blueprints (Modern / Elegant / Heritage)
- Export Hub — Centralized data export tool across modules
- Storage Center — Disk usage analytics, orphan file detection, and cleanup tools
🎨 Landing Page & Marketing
- 8 new landing section types: Hero Slider, AI Showcase, Apps Ecosystem, Awards Strip, Blog Feed, CTA, Ratings Bar, Why Us Split
- Section registry architecture for plug-and-play landing blocks
- Preview shell for live section previewing
- Repeater-based form builder for landing section content
💬 Communication
- 30+ SMS gateways added — Beem, BulkSMS, BulkSMSBD, ClickSend, Fast2SMS, Hubtel, Infobip, Kaleyra, MessageBird, Msegat, NotifyLk, Plivo, SMSAPI, Semaphore, Sinch, SparrowSMS, Telnyx, Termii, TwoFactor, Unifonic, Vonage, Zenvia, Zenziva, and more
- Abstract SMS gateway architecture with delivery-report tracking
- WhatsApp gateway layer — Gupshup, Meta Cloud, SendWapi, 360Dialog, Twilio, UltraMsg, Wati
- Manual WhatsApp button (FAB) for schools
- Comms wallet country-based rate cards
🆔 ID Card & Certificate Designer
- Canvas-based card designer with JSON content storage
- Front + back side support for ID cards
- Card imposition service for duplex printing
- Card asset management
- Template blueprints and ready-template system
📚 Academics & Exams
- Academic session context switching with scoped data isolation
- Assessment analytics service
- Exam grade and exam type form improvements
- Co-curricular grade management
- Student report remarks
- CBC (Competency-Based Curriculum) controller updates
💰 Fees
- Fee session scoping — isolate fee data per academic session
- Fee integrity audit system
- Receipt number series by date
- Collect-fee PIN guard
- Cascade-delete protection for fee payment records
- Due-fees query and due-slip service improvements
👨🎓 Students & Parents
- Dedicated parent management module (CRUD + linking)
- Student bulk upload with themed form UI
- Admission form settings and checkout flow
- Admission status tracking page
- Public admission pages with design tokens
👩💼 HR & Staff
- Payroll holiday calendar support
- Payroll days-worked switched to decimal precision
- Bulk staff upload improvements
🏫 School Admin
- Settings Hub with terminology customization (rename labels system-wide)
- Onboarding wizard with dismissible state
- Command Center warm dashboard
- Class sort-order support
- Guide pages for Academics, Front Office, Hostel, Library, and Transport modules
🔐 Auth & Security
- OTP login service with visibility controls
- Login identifier resolver (email / phone / username flexibility)
- Registration friction controls
- Login hardening and custom login page builder
- Custom login style picker per school
📹 Live Classes & Meetings
- Meeting provider abstraction (Jitsi, Zoom, External Link)
- Live class promoted to standalone module with top-level menu
- Meeting link made optional
🛠️ Super Admin
- Branch dashboard with capabilities, comparison, and sign-in views
- Storage center and orphan file management
- FCM push notification setup guide modal
- SMS gateway admin with gateway-specific field rendering
- Notification type management improvements
- System health page enhancements
- API documentation catalog page
- Team management UI refresh
- Dashboard redesign with new widgets
- Template designer page for school templates
🏷️ Terminology Engine
- System-wide label customization service
- Branding payload integration
- Verification sweep script
📖 Documentation
- Full VitePress documentation site added under
/docs - Covers superadmin, school, installation, and configuration guides
🧪 Tests Added
- Academic context & session scope tests
- Fee session scope & receipt series tests
- Login hardening, OTP visibility, and registration friction tests
- Student bulk upload and HR payroll holiday tests
- Onboarding wizard tests
- Card imposition and fabric card data tests
- Terminology service and branding payload tests
- Landing section registry tests
🔧 Infrastructure
- Platform notification template backfill migration
- Menu seeder updates for new modules
- Route file expansions (school, superadmin, API, apps, auth, web)
- AdminLTE page layout and navbar updates
- TPL design system CSS and datatable JS utilities
- Vite config updates
Period: June 2026 · Entries 36–63
New Modules
- QR Code / Barcode Attendance — Self-service scan station for student & staff attendance with signed QR tokens, anti-double-scan cooldown, and 59-test suite
- Lesson Planner — Weekly lesson plans with teacher → HOD → principal approval chain, syllabus-topic mapping, coverage tracking, auto-classwork sync, and PDF report
- Parent–Teacher Meeting (PTM) — End-to-end scheduling, invitations via WhatsApp/SMS/email, attendance & remarks, parent feedback, follow-ups, and reports
- Asset Management — Full fixed-asset lifecycle: register, QR tagging, allocation, depreciation (SL/DB/WDV), maintenance, disposal with approval, physical audit, and 7 reports
- Digital Evaluation (OSM) — On-screen marking with canvas annotations, evaluator assignment, moderation workflow, analytics, and exam marks sync
- Continuous Assessment — Full staff-app API for authoring, mark entry, publish, and reporting (parity with web module)
Offline Examinations Upgrade
- Release & lock layer for admit cards and results
- Immutable result snapshot engine with tie-aware ranking
- Teacher submit → admin finalise → lock workflow for marks
- Class-wise analytics, merit list PDF
- School-scoped public result portal with two-factor lookup and rate limiting
Timetable Overhaul (4 Phases)
- Academic session scoping, break periods, period ordering
- Elective block scheduling with per-student resolution
- Modern builder UX: Select2 dropdowns, live conflict detection, partial-success save
- Teacher workload view, free-teacher finder, substitution/cover management, print/PDF export
Finance & Accounting
- Tally-compatible double-entry bookkeeping (Chart of Accounts, GL engine, auto-posting)
- Accountant dashboard, day book/cash book, trial balance
- One-click Tally XML/CSV export
- Finance & Fees dashboard with collection trends, charts, and top defaulters
- M-Pesa integration hardening with webhook fixes and integration test suite
HR & Staff
- Staff lifecycle login enforcement (suspended/resigned/terminated blocked at all login paths)
- Bulk staff photo & document upload via ZIP+CSV
- HR overhaul: promotions, performance appraisals, HR dashboard & guide
- Class due fees teacher API for fee follow-up from the staff app
Inventory Overhaul
- Expanded item model (SKU, types, expiry, barcode, photo)
- Point of Sale with barcode scanner and GST support
- Vendor-on-behalf billing (CBSE compliance)
- Procurement pipeline: Purchase Orders → Goods Receipt → Supplier Payments
Academic Session & Student Lifecycle
- Session dates, status lifecycle, soft deletes,
academic:doctorCLI - Duplicate enrollment prevention (composite unique index)
- Cascade → Restrict on 16 foreign keys for deletion safety
- Rollover engine foundation
Dashboard & UI
- Executive Pro X dashboard theme with drag-and-drop personalization
- Role-based smart default layouts (Admin / Teacher / Accountant)
- Mobile dropdown bug fix and universal sidebar logout
- Academic dashboard enhancements and mobile grid optimization
- Study Center layout modernization
Parent API
- Authorization hardening across all parent controllers
- PDF downloads for fee receipts, admit cards, and report cards
- New modules: CBC, Lesson Plans, Live Classes, OSM, PTM
Platform & Infrastructure
- Dynamic onboarding templates (region-aware, SuperAdmin-managed)
- Orphan-free school termination with schema-driven purge
- Data Explorer: relationship graph, guard-railed editor with audit trail
- AI chatbot intent engine enhancements
- Classwork RBAC (teacher scoping, tenant hardening)
- Classwork file upload fix (single file standardization)
- Client-side instant file validation on student admission photo uploads
- Backend photo validation rule added for student photo field
Full technical details in CHANGELOG.md
Detailed PDF Download Click Here
35. Super Admin Documentation Rewrite
Completely overhauled the Super Admin Panel documentation in the main projectworlds_docs.html file to transition from high-level summaries into detailed, actionable instructional guides.
Documentation Enhancements
- Step-by-Step Guides: Replaced static feature grids with numbered, step-by-step instructional blocks (
pw-step-list) across all 19 major Super Admin modules (including School Management, Subscription Plans, Orders, Landing Page Builder, and Platform Settings). - Capabilities Summary: Restored a master capabilities grid on the top-level Super Admin Overview page, providing a fast index of all available modules before drilling down into the specific guides.
- Gateways Deep-Dive: Expanded the Payment & SMS Gateways section to explicitly document all supported third-party providers (Stripe, Razorpay, Twilio, MSG91, etc.) and added a dedicated setup guide for configuring the platform-level Meta/DLT Comms Wallet credentials.
34. Inventory & Stock Management — Full Module Overhaul
Transformed the inventory module from a thin name-and-quantity CRUD into a complete stock lifecycle system covering procurement, storage, issuance, and point-of-sale — delivered in three phases with a redesigned dashboard, demo data, an in-app guide, and an automated test suite. All records remain strictly per-school (tenant-scoped) with granular permissions.
Phase 1 — Items, Stock Control & Dashboard
- Expanded Item Model: Items now carry SKU (auto-generated, unique per school), item type (consumable / saleable), unit of measure (predefined list + free-text "Other"), purchase & selling price, minimum-stock level, expiry date, storage location, barcode, photo, description, and active status.
- Category, Supplier & Issuance Upgrades: Categories gained type/description/icon; suppliers gained contact person, GSTIN, PAN, supplier type and active flag; item issuance became polymorphic — items can be issued to staff, students, or departments (previously staff-only) with an audit of who issued what.
- Stock Adjustments: A new audited adjustments screen for damage, expiry write-offs, loss, corrections, and opening balances — the controlled way to alter stock instead of hand-editing quantities.
- Inventory Dashboard & Sub-Nav: A new dashboard with stat cards (total items, low-stock, expired, stock value), an items-by-category chart, recent-activity timeline, and low-stock / expiring-soon alert tables — plus a module sub-navigation header matching the Academic module pattern.
- Granular Permissions: Replaced the single
inventory.managewithinventory.dashboard.view,inventory.items.manage,inventory.stock.manage,inventory.issues.manage, andinventory.suppliers.manage. Backward compatible — existing roles/users keep access via a migration that grants the new permissions to anyone who hadinventory.manage.
Phase 2 — Saleable Items, POS & Vendor-on-Behalf Billing
- Point of Sale: A cart-based POS screen with type-to-search and barcode scanner support (keyboard-wedge), editable per-line quantity, price, discount and GST %, live totals, buyer selection (student / staff / walk-in), and multiple payment modes (cash / UPI / card / wallet / bank transfer). Sales decrement stock and generate a sequential, per-school invoice number.
- Vendor-on-Behalf Billing (CBSE compliance): Schools can issue an invoice under a vendor's name, GSTIN and address while acting as a collection agent — the printable invoice header switches to the vendor and notes "Collected by [School] on behalf of [Vendor]". A Vendor Collections report totals amounts owed to each vendor.
- Printable Invoice, Sales History & Refunds: A clean printable tax invoice, a searchable sales history, and a full-refund action that restores stock.
Phase 3 — Procurement (Purchase Orders → Goods Receipt → Payments)
- Purchase Orders: Create draft POs with per-line cost and GST. POs require explicit approval (a dedicated
inventory.purchase.approvepermission) before any goods can be received. - Goods Received Notes (GRN): Receiving against an approved PO records received/rejected quantities, increases stock, refreshes the item's purchase cost to the latest PO cost, and automatically advances the PO status (sent → partially received → received).
- Supplier Payments: Record payments against a PO (or general), with paid / balance tracking shown on each purchase order.
Tooling, UI & Quality
- Redesigned Dashboard UI: Rebuilt the inventory dashboard with the same custom soft-card styling and colored icon badges as the Academic dashboard, a category doughnut chart, and an Operations summary (open POs, sales this month, suppliers).
- In-App Module Guide: A new "Guide" tab visually documents the full workflow (procurement → stock → issue → sale), with a tab-by-tab reference and a permissions table, so staff can understand the large module at a glance.
- Demo Data Seeder:
InventoryDemoSeederpopulates a school with realistic, varied data (low-stock, expiring and expired items, suppliers, issues, adjustments, sales including a vendor-on-behalf bill, purchase orders, a goods receipt and a supplier payment). Safe to re-run — it clears prior demo rows first. - Automated Tests: Added a feature test suite covering SKU generation, issue/return stock movement, adjustment guards, sale total computation + refund, the PO approve→receive→cost/status flow, and supplier payments.
33. Academic Dashboard Enhancements & Mobile Optimization
Polished the Academic Dashboard for a more fluid, responsive, and geometrically balanced user experience across devices.
Features added / Fixed
- Scrollable Class Overview Widget: Removed bulky pagination from the "Class & Section Overview" table. It now loads all classes in a single query with a sticky-header, vertically scrollable table for seamless browsing without page reloads.
- Geometric Layout Alignment: Permanently eliminated uneven visual gaps between the left table and right sidebar widgets. Applied strict fixed-height constraints (400px table / 250px timetable) that guarantee perfect alignment across columns without causing unnatural card stretching or internal white space.
- Mobile Grid & Button Optimizations: The four primary stat cards automatically arrange into a balanced 2x2 grid on mobile screens instead of stacking into a single tall column. The "Add New Class" header button smoothly collapses into a space-saving icon-only button on small devices.
- Data Binding Fixes: Corrected an issue where the "Student Count" column for classes displayed as zero due to a missing property binding. It now correctly maps the pre-calculated session counts to each row. Added missing external link icons to the Timetable Alerts widget header for consistency.
32. Data Explorer — Relationship Graph & Guard-Railed Editor
Extends the per-school Data Explorer with an interactive relationship graph, a carefully guard-railed manual editor (with a full audit trail), and a denser phpMyAdmin-style browsing experience.
Features added
- Relationship Graph (Cytoscape): A per-school visual map of the database — every table that holds data is a node sized by row count and coloured by type, with foreign-key links drawn between them. Supports force / concentric / hierarchy / grid layouts, hover-to-highlight a table's relations, search-to-focus, and click-a-node to jump straight into browsing it. The library is vendored locally so it works fully offline.
- Per-Record Relationship Map: Each record's detail page now shows a focused ego-network graph — its parent records point in and its child records point out — built from data already on the page (no extra queries).
- Guard-Railed Manual Editor: Root admins can now insert, edit, and delete a single school's records directly. Editing is read-only until a per-session "Enable edit mode" toggle is switched on, and every change runs a preview → confirm → commit flow that shows an exact before/after diff. Updates and inserts require typing the table name plus a reason; deletes additionally require the operator's password.
- Tenant-Safe Write Guarantees: The target row is re-resolved within the school's scope on every operation;
school_idandidare immutable; any changed or added foreign key must reference a row that exists and belongs to the same school; and values are validated for type, length and required-ness against the live schema. The audit-log table itself is protected from editing to preserve trail integrity. - Change History & Audit Log: Every manual change is written to a dedicated log capturing the full before/after snapshot, the reason, the operator, IP and timestamp. A new Edit History screen lists all changes for a school with an expandable diff.
- phpMyAdmin-Style Navigation & Dense UI: Browsing and record pages gained a sticky, searchable table-list sidebar for jumping between tables without leaving the page, plus a far denser, isolated table style (compact rows, sticky headers, internal scrolling, aligned numeric counts) and a configurable rows-per-page control (25 / 50 / 100 / 200). Table counts are briefly cached so the navigation stays fast across a fleet of 1000+ schools.
31. Per-School Data Explorer (Read-Only)
A superadmin tool to browse and audit a single school's data inside the shared multi-tenant database — phpMyAdmin-style visibility, but tenant-scoped and guard-railed for a fleet of 1000+ schools. Reached via Manage → Data Explorer on each school.
Features added
- Shared Tenant Data Map: Extracted the school-scoping logic (tenant / dependent / belongs-to-parent table classification plus foreign-key-chain resolution) that powers Backup and Restore into a single
SchoolDataMapservice, so all three features agree on exactly which rows belong to a school. Backup output verified byte-identical after the refactor. - Scoped Dashboard: Per-school landing page listing every table that holds data for that school, with scoped row counts, tenant/dependent badges, and a live table filter.
- Tenant-Safe Table Browser: Paginated, sortable, searchable view of any tenant or dependent table. Every query is forced through the scope resolver, so another school's rows can never appear. Includes one-click child-record drill-down.
- Record Detail with Relations: Single-record view that resolves foreign keys to human-readable labels (e.g. student names instead of raw IDs) and lists incoming child relations with live counts.
- Audit-Log Foundation: Added the
school_data_editstable as the schema target for the upcoming guard-railed manual editor (captures before/after, reason, and operator for every change).
30. System Tooling & Gateway Integrations
Features added
- MSG91 SMS Gateway: Integrated MSG91 as a supported SMS gateway, providing administrators with an additional robust provider for automated transactional notifications.
- Send Test Mail Functionality: Implemented a dynamic testing tool within the Superadmin Platform Settings. Administrators can now test SMTP configurations in real-time via a modal before finalizing the settings, ensuring reliable email delivery.
- Library Barcode Generation: Added a native "Download Barcodes" button to the Library Books management interface, allowing librarians to easily export and print barcode labels for inventory management.
29. Secure Integrated Document Viewer
Replaces native browser file tabs and downloads with an immersive, in-app Document Viewer modal. Integrated across Staff Profiles and the Parent Portal (Documents, Study Materials).
Features added
- Unified Alpine Component: Created
x-document-viewer, a robust Alpine.js component utilizingpdf.jsto render PDFs and images natively within the application, maintaining user context. - Storage Path Refactoring & Security: Fixed a critical bug in
StaffController@storeDocumentwhere staff documents were incorrectly uploaded to the privatelocaldisk but served via public URLs (causing 403 Forbidden errors). Uploads now target thepublicdisk. Ran a background migration to move existing staff documents into the correct public storage structure. - Dynamic File Type Resolution: Integrated an explicit
extproperty resolution handler. Handles URLs that obscure file extensions (e.g. AWS S3 signed URLs or dynamic routes) by reading the databasePATHINFO_EXTENSIONdirectly, ensuring the viewer always knows how to render the file. - Mobile-Optimized Layout: Engineered a fully responsive flexbox header for the Document Viewer. Automatically stacks titles and close buttons on mobile devices while converting the zoom/pagination toolbar into a horizontally-scrollable area to prevent overflow and UI clipping.
28. Native Custom UI Google Translate
Replaces the default Google Translate toolbar with a completely custom AdminLTE-native language switcher dropdown, improving layout stability and performance.
Features added
- Custom UI Integration: Added
language_switcher.blade.phpto the top navbar, hiding the bulky Google iframe and 40px layout shifts. - Instant Translation & Render Blocking Fix: Google Translate is now initialized fully asynchronously after the DOM loads, completely removing the initial blank screen flicker.
- Regional Native Fonts: Automatically detects the selected language and dynamically injects specialized premium Google Fonts (like
Noto Sans DevanagariandNoto Sans Bengali) strictly when needed, transforming the UI for regional users without bloating the English site. - Aggressive Cookie Reset: Built a highly robust cookie destroyer loop to fix translation caching issues, ensuring users can natively revert back to English without being stuck in a translated DOM.
- African Languages Supported: Added Swahili, Hausa, Yoruba, and Igbo to the language dropdown options to support clients in Nigeria and Kenya out of the box.
27. Superadmin Communications Report
Adds a global platform-level report for the Superadmin to monitor all outgoing notification logs (SMS, WhatsApp, Push, Email).
Features added
- Communications Report: Introduced
communicationsReport()inApp\Http\Controllers\SuperAdmin\ReportController.phpwhich queries thenotification_deliverability_logstable. Features efficient query clustering for KPI summary boxes (Total Sent, Total Failed, Breakdown by Channel) and usesreorder()to prevent MySQL strict mode (ONLY_FULL_GROUP_BY) conflicts. - Filtering & UI: A new detailed AdminLTE view with extensive filters (by School, Channel, Status, Date Range). The data table includes an interactive modal to view raw message contents and failure reasons safely. Fixed summary card height mismatches using flexbox utilities.
- CSV Exports: Added
exportCommunications()endpoint to safely chunk and stream the logs into a.csvfile.
26. Superadmin Platform Default Notification Templates
Adds a fully-featured UI in the Superadmin dashboard to edit the "Platform Default" notification templates, allowing superadmins to define global fallback messages for new or unconfigured schools.
Features added
- Superadmin Template Controller (
App\Http\Controllers\SuperAdmin\NotificationTemplateController.php): Mirrors the school's template editing logic but specifically saves records withschool_id = null, acting as the platform-level default. Added robustDB::beginTransaction()error handling to ensure atomic persistence and graceful 500 JSON API responses. - UI Integration (
resources/views/superadmin/notification-types/index.blade.php): Added an "Edit Defaults" button and ported the template editor modal from the school settings. Includes sequential numbering in the table for better UX. - Error Handling: Backported the robust
try-catchdatabase transaction error handling into theSchool\NotificationTemplateControllerto ensure data consistency across both ends.
25. Dynamic Currency Refactoring
Eliminates all hardcoded instances of the Indian Rupee (INR / ₹) across the application, replacing them with a fully dynamic currency resolution system suitable for international multi-tenant deployments.
Key Changes
- Currency Helper: Introduced
platform_currency_code(),platform_currency_symbol(),school_currency_code(), andschool_currency_symbol(). - API & Payments: The UPI Gateway, Parent App endpoints, and Comms Wallet APIs now dynamically resolve the school's active currency.
- Dashboards & Views: Superadmin analytics, school fee collections, and reporting tables render the dynamic currency symbol contextually instead of defaulting to India localization.
- Onboarding: Newly registered schools automatically inherit the Superadmin's platform default currency settings.
24. Editable Notification Templates — Phase 4 (WhatsApp Providers + DLT)
Adds opt-in WhatsApp Official Meta Cloud (Graph) API and 360dialog approved-template sending, plus fuller India SMS DLT binding. Entirely additive and per-template opt-in: a channel only uses a provider when a school saves a WhatsApp template with provider = meta_cloud (or 360dialog) and a meta_template_name. Every existing free-text WhatsApp send is byte-identical.
WhatsApp provider routing
MetaWhatsAppGateway(app/Services/Gateways/MetaWhatsAppGateway.php):sendTemplate()/sendText()againstgraph.facebook.com/{api_version}/ {phone_number_id}/messages. Pre-flight (config present, E.164 normalization), builds positionalcomponentsfrom the template'smeta_componentsmap, masks recipients in logs, recordsfbtrace_id.- Error classification + retry (
TransientWhatsAppException): transient (HTTP 429/5xx, Meta130429/80007/131056/131048, connect/timeout) vs permanent (bad token, template paused, param mismatch, undeliverable). The gateway throws only on transient and never bubbles an uncaught error (no 500s). - 360dialog (
ThreeSixtyDialogGateway::sendTemplate()): approved-template (type:template) sends with optional WABA namespace, alongside the existing free-text path. Also fixed a latent$apiKeytype (string→?string). WhatsAppChannelnow branches: a resolved Meta/360dialog template routes to the provider gateway (config read fromschool.whatsapp_config['meta']/['threesixty_key']); anything else uses the unchanged free-text SendWAPI path. If the chosen provider isn't configured, it falls back to free-text. Outcomes are written tonotification_deliverability_logs.- No churn in the 12 wired notification classes: the
RendersNotificationTemplatestrait exposes the resolved template to the channel viawhatsAppRenderedTemplate()/whatsAppTemplateData()(render is memoized per channel), so provider routing needed zero edits to anytoWhatsApp().
SMS DLT binding
CustomGatewaynow also substitutes[dlt_pe_id]and[sender_id]URL placeholders (alongside the existing[dlt_template_id]).SmsChannelforwardsdlt_pe_id/sender_id, auto-filled from the resolved SMS template (smsRenderedTemplate()hook) whentoSms()doesn't supply them. Platform gateways ignore the extra arguments.
Known follow-ups (not in this change)
- Per-channel retry: a transient Meta failure is logged, not rethrown — a queue retry re-runs the whole notification and would duplicate the other channels (SMS/push). True retry needs channel-isolated jobs.
- Meta credential entry UI: creds are read from
whatsapp_config; a settings form to capturephone_number_id/access_token/etc. is still TODO. - Meta delivery webhooks (Phase 5).
Files
| Action | File |
|---|---|
| NEW | app/Exceptions/TransientWhatsAppException.php |
| NEW | app/Services/Gateways/MetaWhatsAppGateway.php |
| MODIFIED | app/Services/Gateways/ThreeSixtyDialogGateway.php |
| MODIFIED | app/Services/Gateways/CustomGateway.php |
| MODIFIED | app/Channels/WhatsAppChannel.php |
| MODIFIED | app/Channels/SmsChannel.php |
| MODIFIED | app/Traits/RendersNotificationTemplates.php |
23. Editable Notification Templates — Phase 2 Expansion (6 More Types)
Extends the editable-template system (sections 20–21) to the remaining parent-facing notification types, so each now appears in the "Customize Message" editor (SMS/WhatsApp/Push) with a legacy fallback identical to its old message.
Low-risk — wired existing senders
live_class_start(LiveClassReminderNotification): added the template trait +templateData()+ per-channelrenderTemplate()guards.via()now honours the per-type matrix toggles when a settings row exists, falling back to the previous global-switch behaviour when none does (no regression).bus_proximity_alert: refactoredSendProximityAlertto dispatch a newBusProximityNotificationthrough the standard channel stack instead of ad-hocHttp/Mailcalls. This fixes the dead SMS placeholder (SMS now actually sends via the school gateway) and unifies WhatsApp throughWhatsAppChannel.
New classes + dispatch triggers
online_exam_publish(OnlineExamPublishedNotification): dispatched fromSchool\Exam\OnlineExamController::store()(online exams have no manual publish step — creation is the publish event) to active students of the exam's class/section in the current session, via the parent account.library_book_issue(LibraryBookIssuedNotification): dispatched fromSchool\Library\BookIssueController::store()for student members, to the borrowing student's parent.transport_fees(TransportFeesNotification): dispatched fromSchool\Transport\StudentTransportController::store()when a transport fee is assigned (fare > 0), to the student's parent.
All new dispatches are fail-safe (wrapped so a notification error never breaks the underlying action) and fired after the DB transaction commits.
Cleanup
- Removed dead
app/Channels/ParentFeePaid.php: a non-autoloadable stub (file path ≠ namespace), never dispatched, with an emptytoMail(); it duplicatedfee_submission(FeeSubmissionNotification), which already covers parent fee-payment alerts. Theparent_fee_paidtype definition itself is left untouched.
Registry & seeds
TemplateVariables: registered variable catalogues for all 6 types.NotificationTemplateSeeder: added inactive platform-default SMS/WhatsApp/Push templates mirroring the legacy strings.NotificationTypeSeeder: added thebus_proximity_alerttype (previously only seeded via migration) for consistency.
Files
| Action | File |
|---|---|
| MODIFIED | app/Notifications/LiveClassReminderNotification.php |
| NEW | app/Notifications/BusProximityNotification.php |
| NEW | app/Notifications/OnlineExamPublishedNotification.php |
| NEW | app/Notifications/LibraryBookIssuedNotification.php |
| NEW | app/Notifications/TransportFeesNotification.php |
| MODIFIED | app/Jobs/SendProximityAlert.php |
| MODIFIED | app/Http/Controllers/School/Exam/OnlineExamController.php |
| MODIFIED | app/Http/Controllers/School/Library/BookIssueController.php |
| MODIFIED | app/Http/Controllers/School/Transport/StudentTransportController.php |
| MODIFIED | app/Support/Notifications/TemplateVariables.php |
| MODIFIED | database/seeders/NotificationTemplateSeeder.php |
| MODIFIED | database/seeders/NotificationTypeSeeder.php |
| DELETED | app/Channels/ParentFeePaid.php |
22. Parent Portal — Session-Change Crash Fix (Critical)
Root Cause
currentSessionReturns Null: TheStudent::currentSession()relationship filters byacademic_session.is_current = true. When the school admin switches the current academic session, any student not enrolled in the new session getsnullfromcurrentSession. Controllers then crash on$student->currentSession->school_class_idwithAttempt to read property "school_class_id" on null(500 Internal Server Error).
Fix Applied — Graceful Degradation
- Controller Null Guards: Added
if (!$student->currentSession)early-return guards to 4 controllers. Instead of crashing, each controller now returns the view with safe empty defaults (empty collections, empty JSON arrays) and anoCurrentSessionflag. - Blade Nullsafe Operators: Replaced unsafe
$student->currentSession->schoolClass->namechains with PHP 8.0 nullsafe$student->currentSession?->schoolClass?->name ?? 'N/A'in 2 Blade templates. - User-Facing Warning Banner: Added a visible alert banner on the parent dashboard when
$noCurrentSessionis true, informing the parent that their child is not enrolled in the current academic session and to contact the school if unexpected. - Session-Independent Features Unaffected: Fees, Library, Transport, Attendance History, Profile, and other pages that don't depend on
currentSessioncontinue working normally for unenrolled students.
Files Changed
| Action | File |
|---|---|
| MODIFIED | app/Http/Controllers/Parent/DashboardController.php |
| MODIFIED | app/Http/Controllers/Parent/NoticeController.php |
| MODIFIED | app/Http/Controllers/Parent/TimetableController.php |
| MODIFIED | app/Http/Controllers/Parent/OnlineExamController.php |
| MODIFIED | resources/views/parent/dashboard.blade.php |
| MODIFIED | resources/views/parent/profile/edit.blade.php |
21. Fee Submission Notification — Duplicate WhatsApp/SMS Fix
Root Cause Analysis
- Double-Send on Same Phone Number: The
FeeDepositObserverdispatchedFeeSubmissionNotificationto both the parentUserand the studentUser. The deduplication guard only compared User IDs ($studentUser->id !== $parentUser->id), but in most schools both accounts resolve to the same phone number (e.g.father_phone) viarouteNotificationForSms()— resulting in the recipient receiving two identical WhatsApp/SMS messages per fee payment. - Contrast with Attendance: The
StudentAttendanceObserveronly sends to$student->parent(single recipient), which is why attendance notifications correctly sent once.
Fix Applied
- Phone-Number-Aware Dedup (
FeeDepositObserver.php): The student User now only receives the notification if both their User ID and resolved phone number differ from the parent User. If both accounts resolve to the samefather_phone, the duplicate send is skipped.
Files Changed
| Action | File |
|---|---|
| MODIFIED | app/Observers/FeeDepositObserver.php |
20. Editable Notification Templates — Phases 0–3
Phase 0 — DLT Pass-Through Fix
- SMS DLT Template ID Forwarding (
SmsChannel.php): Fixed a silent bug whereSmsChannelcalled the gateway'ssend()with only 2 arguments, causing the[dlt_template_id]URL placeholder inCustomGatewayto always resolve to empty — non-compliant for India DLT (mandatory). The channel now forwardsdlt_template_idfrom each notification'stoSms()return array as the 3rd argument.
Phase 1 — Foundation (Additive, Dormant)
- Database Schema: Created
notification_templatesmigration with support for per-school overrides (school_idnullable — NULL = platform default), per-channel templates (email|sms|whatsapp|push), WhatsApp Meta Cloud fields (provider,meta_template_name,meta_template_language,meta_componentsJSON), and SMS DLT fields (dlt_template_id,dlt_pe_id,sender_id). Unique constraint on(school_id, notification_type_id, channel, language). - Template Renderer (
TemplateRenderer.php): Resolve order: school template → platform-default template (school_id = NULL) →null(legacy fallback). Substitutes{{variables}}in template body. - Rendered Template DTO (
RenderedTemplate.php): Immutable value object carryingbody,subject,dlt_template_id, and Meta component builder for Phase 4. - Trait (
RendersNotificationTemplates.php): Mix-in for notification classes providingrenderTemplate($channel)— returns aRenderedTemplateornull(legacy path). - Variable Registry (
TemplateVariables.php): Per-type variable catalogue with labels and sample values — powers editor variable chips and server-side validation. - Platform Default Seeder (
NotificationTemplateSeeder.php): Seeds platform defaults forexam_resultandfee_submission(4 channels each), idempotent viaupdateOrCreate. Runs automatically in the migration'sup()and is reversible indown().
Phase 2 — Wire Notification Classes (10 Types, 11 Classes)
- Template-Driven Rendering: Wired 10 notification types across 11 classes:
exam_result,fee_submission,fee_reminder_due,student_absent,student_birthday,student_punch_out,homework_assigned,behaviour_incident,online_admission_submit,due_slip_generated. Each class receivednotificationTypeName(),templateData(), andrenderTemplate()guards intoSms()/toWhatsApp()/toFcm()— with unchanged legacy fallback when no active template exists. - Email Deferred:
toMail()deliberately left on legacy across all classes (HTML mailable strategy pending). - Security Exclusion:
login_credentialnotification excluded from the template system (contains sensitive OTP/password data).
Phase 3 — School Editor UI
- Template Editor Controller (
NotificationTemplateController.php):edit()returns per-channel content (school override, else platform default prefill) + variables as JSON;update()upserts school-owned rows. Validates unknown{{variables}}→ 422, invalid Meta-components JSON → 422, and deletes override on empty body (reverts to legacy). - Routes:
school.settings.notifications.templates.edit|updateunderpermission:settings.school.manage. - Settings Integration (
SettingController.php):notificationSettings()now passes$templatableTypesfromTemplateVariables::registeredTypes()so the "Customize Message" button only shows for wired types. - Blade Editor Modal (
notifications.blade.php): Tabbed editor (SMS / WhatsApp / Push) with clickable{{variable}}chips, live client-side preview, per-channel Active toggle, SMS DLT template ID field, and WhatsApp provider selector + Meta template-name/language/components fields (shown when provider ismeta_cloudor360dialog).
Files Changed
| Action | File |
|---|---|
| MODIFIED | app/Channels/SmsChannel.php |
| NEW | database/migrations/2026_05_31_120000_create_notification_templates_table.php |
| NEW | app/Models/NotificationTemplate.php |
| NEW | app/Services/Notifications/TemplateRenderer.php |
| NEW | app/Services/Notifications/RenderedTemplate.php |
| NEW | app/Traits/RendersNotificationTemplates.php |
| NEW | app/Support/Notifications/TemplateVariables.php |
| NEW | database/seeders/NotificationTemplateSeeder.php |
| MODIFIED | app/Notifications/ExamResultNotification.php |
| MODIFIED | app/Notifications/FeeSubmissionNotification.php |
| MODIFIED | app/Notifications/FeeDueNotification.php |
| MODIFIED | app/Notifications/StudentAbsentNotification.php |
| MODIFIED | app/Notifications/StudentBirthdayNotification.php |
| MODIFIED | app/Notifications/StudentPunchOutNotification.php |
| MODIFIED | app/Notifications/HomeworkAssignedNotification.php |
| MODIFIED | app/Notifications/BehaviourIncidentNotification.php |
| MODIFIED | app/Notifications/OnlineAdmissionSubmitNotification.php |
| MODIFIED | app/Notifications/DueSlipGeneratedNotification.php |
| MODIFIED | app/Notifications/StudentAttendanceNotification.php |
| NEW | app/Http/Controllers/School/NotificationTemplateController.php |
| MODIFIED | app/Http/Controllers/School/SettingController.php |
| MODIFIED | resources/views/school/settings/notifications.blade.php |
| MODIFIED | routes/school.php |
19. Bulk Student Photo & Document Upload
Architecture & Capabilities
- ZIP + CSV Integration: Developed two dedicated bulk upload modules—one for Student Photos and one for Student Documents. Schools upload a single ZIP archive containing all media files along with a lightweight CSV mapping file (
photo_mapping.csvordocument_mapping.csv), allowing hundreds of files to be ingested in one click. - Idempotent Background Processing: Uploads are dispatched to background queue jobs (
ProcessBulkStudentPhotosandProcessBulkStudentDocuments). They track progress row-by-row, automatically caching database lookups for students, and safely skipping or overwriting existing records without duplicating data. - Progress & Error Tracking: Integrated directly with the existing
ImportTaskmodel to provide real-time UI progress bars. To prevent memory exhaustion, error logs are automatically capped at 100 entries per job, keeping the database light even during massive failures.
Robust Server Limit Handling
- Dynamic Configuration Detection: The UI now actively interrogates PHP's
upload_max_filesizeandpost_max_sizeconfiguration. It natively restricts file inputs to the effective maximum size, ensuring that end-users cannot crash the server or experience silent failures. - Pre-Flight Size Validation: Built server-side guards that intercept POST requests that exceed the configured size limit before they reach Laravel validation, providing a clean redirect and a descriptive error message instead of a generic server fault.
- Magic Byte Security: Implemented deep validation for photo uploads by checking the actual binary headers ("Magic Bytes") of files inside the ZIP, preventing malicious scripts disguised as images from being stored.
Files Changed
| Action | File |
|---|---|
| NEW | app/Http/Controllers/School/Student/BulkStudentPhotoController.php |
| NEW | app/Http/Controllers/School/Student/BulkStudentDocumentController.php |
| NEW | app/Jobs/ProcessBulkStudentPhotos.php |
| NEW | app/Jobs/ProcessBulkStudentDocuments.php |
| NEW | resources/views/school/student/bulk-photo-upload/create.blade.php |
| NEW | resources/views/school/student/bulk-document-upload/create.blade.php |
| MODIFIED | routes/school.php |
| MODIFIED | resources/views/school/student/students/index.blade.php |
18. Certificate Template Thumbnail Engine
Core Architecture
- Database Schema Expansion: Added
thumbnail_pathto bothready_templates(Superadmin library) andcertificates(School Admin templates), along with aready_template_idforeign key on thecertificatestable to track template provenance. - Smart Cascading Inheritance: Designed a sophisticated
getEffectiveThumbnailAttribute()on theCertificatemodel. It checks for a custom thumbnail first, falls back to the parentReadyTemplatethumbnail via relationship tracking, and defaults to an iframe preview if neither exists. - Zero-Downtime Migration: Schema updates were made using nullable columns and
nullOnDelete()constraints, ensuring zero disruptions for schools and 100% backward compatibility for older templates without thumbnails.
UX & Performance Enhancements
- Massive Render Optimization: Replaced resource-heavy
srcdociframes in the gallery grids with fast, static thumbnail<img>tags. This drastically reduces CPU overhead and DOM node counts when browsing large template libraries. - Click-to-Zoom Intuitive UI: Scrapped clunky hover overlays and side buttons. The entire template image is now natively clickable with a
zoom-incursor, fading in a crisp whitefa-search-plusicon perfectly centered in the preview area on hover. - Live Upload Preview & Override: Added seamless AJAX-like image preview behavior to the file upload inputs on both Superadmin and School Admin edit pages. School Admins can instantly override an inherited Superadmin thumbnail with their own custom design.
- UI Origin Badges: Added contextual badges to the School Admin gallery:
📷 Original previewwhen inheriting a Superadmin thumbnail, giving users clear visibility into the template's source.
Files Changed
| Action | File |
|---|---|
| NEW | database/migrations/2026_05_30_060802_add_thumbnail_support_to_templates.php |
| NEW | resources/views/partials/_thumbnail_preview_modal.blade.php |
| MODIFIED | app/Models/ReadyTemplate.php |
| MODIFIED | app/Models/Certificate.php |
| MODIFIED | app/Http/Controllers/SuperAdmin/TemplateController.php |
| MODIFIED | app/Http/Controllers/School/Certificate/CertificateTemplateController.php |
| MODIFIED | resources/views/superadmin/templates/index.blade.php |
| MODIFIED | resources/views/superadmin/templates/create.blade.php |
| MODIFIED | resources/views/superadmin/templates/edit.blade.php |
| MODIFIED | resources/views/school/certificates/templates/index.blade.php |
| MODIFIED | resources/views/school/certificates/templates/create.blade.php |
| MODIFIED | resources/views/school/certificates/templates/edit.blade.php |
| MODIFIED | resources/views/school/certificates/templates/_template_library.blade.php |
| MODIFIED | resources/views/school/certificates/templates/_styles_and_scripts.blade.php |
17. Topbar User Menu & Quick Nav Enhancements
Dynamic Role-Based SVG Avatars
- Fallback Avatars: Added
adminlte_image()andgenerateSvgAvatar()methods to theUsermodel. When a user lacks a profile photo, the system now generates a beautiful, responsive SVG avatar featuring their initials on a gradient background that is distinctly color-coded based on their primary role (e.g., Red for Superadmin, Purple for School Admin, Blue for Teachers).
Role-Aware Profile Routing
- Intelligent Links: Implemented
getProfileUrl()andgetPasswordUrl()on theUsermodel. The user menu dropdown now dynamically routes the "My Profile" and "Change Password" links to the correct endpoints depending on whether the user is a Superadmin, Staff member, or Parent, avoiding 404s.
Quick Nav Mega Menu
- Data Parsing: Developed a brand new
menu-item-quick-nav.blade.phppartial that intercepts the existing$adminlte->menu('sidebar')data. It parses the nested array structure, extracts top-level string headers and module submenus without requiring any additional database queries. - Masonry UI Grid: Rendered the extracted modules into a dense, multi-column masonry layout (similar to professional SaaS app switchers).
- Live Search: Integrated a JavaScript-powered live search input inside the mega menu dropdown that instantly filters the nested module links.
- Inline Cache-Busting CSS: Injected structural CSS styles directly into the blade template to bypass aggressive browser CSS caching and guarantee immediate layout rendering for users.
User Menu Cleanups
- Removed Redundancy: Removed the duplicate username text next to the avatar on the topbar trigger for a cleaner, modern look.
Files Changed
| Action | File |
|---|---|
| MODIFIED | app/Models/User.php |
| MODIFIED | config/adminlte.php |
| MODIFIED | public/css/custom_v3.css |
| MODIFIED | resources/views/vendor/adminlte/partials/navbar/navbar.blade.php |
| NEW | resources/views/vendor/adminlte/partials/navbar/menu-item-dropdown-user-menu.blade.php |
| NEW | resources/views/vendor/adminlte/partials/navbar/menu-item-quick-nav.blade.php |
16. Hostel Dashboard Module
Custom View & Controller
- Hostel Dashboard: Designed a brand new
Hostel Dashboardpage mapping exactly to UI designs, providing live statistical tracking for Total Hostels, Rooms, Occupied Beds, and Available Beds. - DashboardController: Added a new controller dedicated strictly to collecting Hostel statistics, occupancy calculations (percentage based per-hostel), and recent allocations list without muddying existing controllers.
- Dynamic Menu Injection: Added a migration to inject the
Hostel Dashboardmenu item directly into the database'smaster_menu_itemsand assigned it to theschool_adminrole securely dynamically (without resetting seeded menu logic).
Styling & Theming
- Strict CSS Isolation: Introduced CSS custom properties within
header.blade.phpapplying a strict.hst-prefix. This completely isolated styling method guarantees zero class collisions across other dashboards (e.g. Transport or Library). - FontAwesome Optimization: Refactored the dashboard to implement standard FontAwesome icons rather than Material Symbols, preventing icon-font rendering latency and UI glitches inside AdminLTE.
- Universal Tab Headers: Injected the dynamic isolated header and tabs (
Dashboard,Student Allocation,Manage Rooms,Room Types,Manage Hostels) onto all index pages under the Hostel module for unified navigation.
Files Changed
| Action | File |
|---|---|
| NEW | app/Http/Controllers/School/Hostel/DashboardController.php |
| NEW | database/migrations/2026_05_29_071617_add_hostel_dashboard_to_menu.php |
| NEW | resources/views/school/hostel/partials/header.blade.php |
| NEW | resources/views/school/hostel/dashboard.blade.php |
| MODIFIED | routes/school.php |
| MODIFIED | resources/views/school/hostel/hostels/index.blade.php |
| MODIFIED | resources/views/school/hostel/rooms/index.blade.php |
| MODIFIED | resources/views/school/hostel/room_types/index.blade.php |
| MODIFIED | resources/views/school/hostel/allocations/index.blade.php |
15. Transport Dashboard Module
Custom View & Controller
- Transport Dashboard: Developed a comprehensive
Transport Dashboardoffering live tracking of total vehicles, active routes, daily commuters, and vehicle maintenance status. - DashboardController: Added a dedicated
DashboardControllerunder theTransportnamespace for isolated metric calculations. - Dynamic Menu Injection: Created a migration (
2026_05_29_060814_add_transport_dashboard_to_menu.php) to dynamically insert the Transport Dashboard into the sidebar for theschool_adminrole.
Styling & Theming
- Isolated CSS (
.ts-): Encapsulated all Transport dashboard styling under a strict.ts-prefix inpartials/header.blade.phpto prevent global CSS bleed. - Universal Tab Headers: Integrated the new header with navigation tabs across all Transport module index pages (Vehicles, Routes, Tracking).
14. Library Dashboard Module
Custom View & Controller
- Library Dashboard: Built a new
Library Dashboardfeaturing a clean, zero-padding boundary layout for tracking total books, issued books, overdue returns, and available inventory. - DashboardController: Added a dedicated
DashboardControllerinside theLibrarynamespace. - Dynamic Menu Injection: Deployed a migration to inject the Library Dashboard into the
school_adminmenu.
Styling & Theming
- Isolated CSS (
.lib-): Encapsulated Library dashboard styling under a strict.lib-prefix inpartials/header.blade.php. - Universal Tab Headers: Integrated the Library navigation tabs (Overview, Issue/Return Book, Categories, Manage Books) consistently across all Library module views.
13. SuperAdmin Page CRUD Enhancements
Validation & Slug Generation
- Dedicated Form Requests: Created
StorePageRequestandUpdatePageRequestto replace inline$request->validate()calls, ensuring compliance with strict type and validation conventions ($request->validated()). - Pre-Validation Slug Generation: Moved URL slug generation into
prepareForValidation()inside the FormRequests. This fixes a critical bug where empty slugs would bypass theunique:pages,slugrule, generate a duplicate slug in the controller/model, and trigger a databaseIntegrity constraint violation(500 Error). - Strict Return Types: Added explicit
ViewandRedirectResponsereturn types to all methods inPageController.php.
UI Improvements
- Validation Error Feedback: Added global validation error display blocks (
@if ($errors->any())) to the top of the form in bothcreate.blade.phpandedit.blade.php. Previously, validation failures would silently redirect back without showing the user what went wrong.
12. Fee Collection Audit & Analysis Enhancements
Collector Audit Trail
- Tracking Collections: Added a
collected_by_user_idfield to thefee_depositstable to track exactly which admin or accountant processed each payment. Both UI (CollectFeeController) and backend services (FeePaymentService) now capture the authenticated user. - Daily Collection Report: Enhanced the Daily Collection table to display a "Collected By" badge.
- Collector-Wise Report: Built a brand new audit report (
school/reports/finance/collector-wise-report) that allows filtering collections by date range and specific staff member, complete with summary cards (cash/card/online) and Excel export capabilities. - Telegram Notifications: "Collected By" name is now included in instant Telegram alerts to school admins.
Collection Summaries & PDF Exports
- Summary Tables: Injected three compact summary tables (Collector-wise, Account-wise, and Payment Mode) at the bottom of the Daily Collection Report view.
- PDF Export Sync: Updated the
collection_pdf.blade.phptemplate to render the new "Collected By" column in the main table and include all three summary tables in the exported PDF layout.
Fees Analysis Matrix Upgrades
- Concession & Fine Columns: Expanded the Fees Analysis Report matrix (grouped by Fee Heads or Months). Previously only showing Assigned/Paid/Due, it now breaks down
ConcessionandFineindividually, ensuringDueamounts calculate correctly factoring in late fines. - Fee Heads Filter: Added a multi-select "Fee Heads" dropdown to the analysis filter form. Users can now limit the massive matrix report to only show selected fee types (e.g., only "Admission Fee" and "Transport Fee"). All filters natively sync to the Excel Export function.
11. Login Page Logo Optimization
- Constrained Logo Dimensions: Fixed a bug where the
x-platform-logocomponent and user-uploaded school logos were rendering at their native, giant resolutions on the login page due to conflicting Tailwindw-auto/h-autoclasses. - Proportional Scaling: Replaced fixed utility classes with
max-h-24 max-w-[280px]andobject-containinguest.blade.phpto ensure any logo fits perfectly above the login box without breaking the layout. - Component Fix: Removed hardcoded SVG width/height from
platform-logo.blade.phpto allow parent layouts to control scaling.
Files Changed
| Action | File |
|---|---|
| MODIFIED | resources/views/layouts/guest.blade.php |
| MODIFIED | resources/views/components/platform-logo.blade.php |
10. Compact Sidebar Width — Professional Panel Layout
- Sidebar Width Reduced (
custom.css): Reduced the AdminLTE default sidebar from250pxto220px, gaining 30px of content area. All selectors scoped tobody:not(.sidebar-collapse)so the collapsed/mini sidebar is unaffected. - Nav Link Density: Tightened nav link padding (
1rem→0.6rem) and reduced font size to0.875rem(14px) for a professional density matching panels like aaPanel. - Submenu, Icons, Headers: Reduced icon width (
1.6rem→1.2rem), submenu indent, and section header font size for proportional compaction. - Brand Area: Logo reduced from
33px→28px, brand text from0.95rem→0.85remwithmax-width: 120px. - Search Box: Tighter padding and smaller font for the sidebar search input.
Files Changed
| Action | File |
|---|---|
| MODIFIED | public/css/custom.css |
9. Apply Discount — Individual Item Scoping
Bug Fixes
- Discount Applied to Entire Group Instead of Selected Items (
ApplyDiscountController.php): The "Apply Discount" button applied the discount to all items in a fee group, regardless of which individual fee items the user had checked. Now accepts optionalitem_ids[]from the form. When items are selected, only those items receive the discount; when no items are checked, it falls back to the full-group behavior (backward compatible). - Fixed-Amount Distribution Proportional to Selected Items: When
item_idsare provided, fixed-amount discounts are distributed proportionally among only the selected items' amounts, not the entire group total. - Status Bug (
pending→unpaid): The fallback status after applying a discount was set to'pending'which doesn't match the status enum used elsewhere (unpaid/partial/paid). Fixed to'unpaid'. - Discount Cap at Outstanding Balance: Previously capped at
item->amount; now correctly caps atamount - paid_amountto prevent discount exceeding the remaining payable.
UI Enhancements
- Selected Items Info Banner: The Apply Discount modal now shows a blue info banner indicating how many items are selected and their names, or a note that the discount will apply to all items if none are checked.
Files Changed
| Action | File |
|---|---|
| MODIFIED | app/Http/Controllers/School/Fees/ApplyDiscountController.php |
| MODIFIED | resources/views/school/fees/collect-fees/_student-ledger.blade.php |
8. Fee Collection Discount Validation Fixes
Bug Fixes
- 100% Discount Rejected (
CollectFeeController.php): When applying a full discount equal to the fee amount (e.g. ₹5,000 discount on a ₹5,000 fee), the paying amount correctly auto-calculated to ₹0.00, but the backend filter (amount > 0) silently dropped the item — resulting in a "No payment amount selected" error. Fixed by also including items wherediscount > 0, so full-discount items are properly processed and marked as paid. - Discount Exceeds Fee Amount — No JS Restriction (
index.blade.php): The discount input field in the Collect Fees modal had nomaxattribute or JavaScript cap, allowing users to enter a discount greater than the fee amount due (e.g. ₹10,000 discount on a ₹5,000 fee). Addedmaxattribute on the HTML input, and JSinputhandler that caps the discount value at the fee amount due in real-time. - Server-Side Discount Guard (
CollectFeeController.php): Added a backend safety check that capsdiscountAmountat the outstanding balance before processing, protecting against tampered form submissions that bypass JS validation.
Files Changed
| Action | File |
|---|---|
| MODIFIED | app/Http/Controllers/School/Fees/CollectFeeController.php |
| MODIFIED | resources/views/school/fees/collect-fees/index.blade.php |
7. Fee Reversal Bug Fix — Cross-Group Recalculation
Bug Fix
- Stale Group Summaries After Revert (
CollectFeeController.php): When a single payment receipt covered fees across multiple fee groups (e.g. "Enrollment Fees" + "Uniform & Books"), therevert()method only recalculated the oneStudentFeegroup stored on the deposit record ($deposit->studentFee->recalculate()). The other groups retained stalepaid_amountanddue_amountvalues, causing the "Total Paid" and "Balance Due" pills on the Collect Fees page to display incorrect totals after reversal. Fixed by collecting all uniquestudent_fee_ids from the deposit's items and recalculating every affected group — mirroring the same pattern already used instore().
Files Changed
| Action | File |
|---|---|
| MODIFIED | app/Http/Controllers/School/Fees/CollectFeeController.php |
6. Africa's Talking SMS Gateway Integration
- New Gateway Service: Added
AfricastalkingGateway.php— a zero-dependency gateway class using Laravel'sHttpfacade to call the Africa's Talking SMS API directly. Auto-detects sandbox vs production endpoint based on username. No additional composer packages required. - Admin UI Enhancement: Updated the SuperAdmin SMS Gateway create and edit Blade views with dedicated Africa's Talking credential fields (Username, API Key, Sender ID/Shortcode) that dynamically show/hide when the gateway name is set to
Africastalking. - Instructions Sidebar: Added AT-specific setup guidance in the edit form sidebar, including sandbox testing instructions and links to the AT Dashboard.
- Test Button on Index: Added a "Test" button alongside "Edit" on the SMS Gateways listing page, allowing direct access to the test SMS page without going through the edit form first.
- Seeder Migration: Created
2026_05_28_000001_seed_africastalking_sms_gateway.phpto auto-insert theAfricastalkinggateway record into thesms_gatewaystable with empty credentials (ready for admin configuration).
Bug Fixes
- Decrypt Crash Fix (
SmsGateway.php): Changed the credentials accessor catch block fromDecryptExceptionto\Throwable. Previously, corrupted encrypted data would pass decryption but fail onunserialize(), throwing an uncaughtErrorExceptionand crashing the edit page with a 500 error. Now gracefully falls back to an empty array. - Test Page Crash Fix (
test.blade.php): Added null-safe handling for$smsGateway->credentials['key_id']on the test page. Gateways with empty credentials no longer crash — they show "Not configured" instead.
Files Changed
| Action | File |
|---|---|
| NEW | app/Services/Gateways/AfricastalkingGateway.php |
| NEW | database/migrations/2026_05_28_000001_seed_africastalking_sms_gateway.php |
| MODIFIED | app/Models/SmsGateway.php |
| MODIFIED | resources/views/superadmin/sms-gateways/create.blade.php |
| MODIFIED | resources/views/superadmin/sms-gateways/edit.blade.php |
| MODIFIED | resources/views/superadmin/sms-gateways/index.blade.php |
| MODIFIED | resources/views/superadmin/sms-gateways/test.blade.php |
5. Custom Full HTML Landing Page System
- Independent Template Engine: Built a full HTML template system (
landing_page_full_templatestable) allowing superadmins to bypass the section builder and use a completely custom HTML template for the main root landing page (/). - Advanced Code Editor: Added a CodeMirror-powered editor (with Dracula theme and auto-formatting) under the Website > Full Templates menu. It includes a live responsive iframe preview with Desktop/Tablet/Mobile toggles and Ctrl+S save bindings.
- Smart Mode Switching: Integrated a global toggle in
Setting(landing_page_mode) that instantly routes traffic between the dynamic section builder and the active full HTML template. - Safe Rendering Engine: Replaced Laravel's
Blade::render()with a robuststr_replaceandpreg_replaceimplementation inHomeController@index. This ensures custom HTML featuring JSON-LD (@context,@type) or CSS (@media,@keyframes) does not trigger fatal Blade parse errors. - Quick Import Helper: Added a one-click import button to automatically seed the database with the pre-built
devx/school-erp-landing.htmllayout.
Authentication Shortcodes for Custom HTML
- Dynamic Variables: Injected
{{ $authUrl }}and{{ $authText }}variables into the template renderer, dynamically outputting/dashboardand "Dashboard" for authenticated users, and/loginand "Sign In" for guests. - Conditional Blocks: Implemented regex-based conditional rendering shortcodes. Wrapping HTML in
[if_logged_in]...[/if_logged_in]or[if_guest]...[/if_guest]allows the raw HTML templates to contextually hide or show navigation buttons without needing any complex logic.
1. Fee Receipt PDF Layout & Scaling Adjustments
Landscape Mode (Double Receipt Layout)
- Table-based Column Constraints: Converted the float-based and flex-based layout containers into a fixed HTML table (
table-layout: fixed; width: 100%). This addresses the lack of CSSbox-sizing: border-boxsupport in DomPDF, ensuring that borders and padding do not extend columns beyond 100% of A4 landscape width, resolving right-edge clipping. - Logo Consistency: Removed the duplicate logo on the right side of the Office Copy header to match the clean design of the Parent Copy.
- Vertical Compaction: Reduced the inner wrapper paddings (
16px 20pxto10px 12px), title bar sizing (13pxto11px), student info tables (11pxto10px), and other vertical spacings to prevent receipts with multiple fee heads from overflowing onto a second page.
Portrait Mode (Stacked Layout)
- Adaptive CSS Overrides: Injected compact CSS overrides dynamically targeting the A4 portrait PDF container. Overrode hardcoded inline wrapper padding (
padding: 20px 24pxto8px 12px), margins, and default font-sizes (12px/11pxto9px) to guarantee that stacked copies fit cleanly on a single page.
2. Centralized Browsershot Binary Configuration
- Dedicated Config File: Created
config/browsershot.phpto centrally resolve Node.js, NPM, and Chrome headless binaries. - Environment Variable Support: Appended matching environment variables (
BROWSERSHOT_NODE_PATH,BROWSERSHOT_NPM_PATH,BROWSERSHOT_CHROME_PATH) to.envto enable clean cross-environment setup. - Reusable Trait Helper: Added a shared helper method
configureBrowsershot(Browsershot $browsershot)to theHandlesPdfAssetstrait. All PDF controllers now pull configurations from this single function instead of duplicating hardcoded server paths.
3. High-Quality Certificate Preview Downloads
- Orientation-Scoped PDF Options: Added form-based POST buttons for "Download PDF (Portrait)" and "Download PDF (Landscape)" on the Generated Documents Preview page.
- Browsershot with DomPDF Fallback: Integrated high-quality Browsershot rendering into
GenerateDocumentController.phpwith automatic fallback to Barryvdh DomPDF if Browsershot is unconfigured or encounters an error. - Base64 Asset Embedding: Enabled the
HandlesPdfAssetstrait in the generator controller to convert all local image files and CSS background assets to base64 data URIs before PDF compilation. - Page-Break Control: Restructured
pdf.blade.phpto dynamically enforcepage-break-after: alwayswhen generating multi-student certificates.
4. Marksheet & Report Card PDF Downloads
- Automatic PDF Engine Fallback: Implemented Barryvdh DomPDF fallback inside the
download()method ofMarkSheetController.php. If Chrome or Node.js are missing, the controller silently falls back to DomPDF, maintaining a seamless download path. - Cleaned Preview UI: Removed the blocking
$hasNodechecks inshow.blade.php, allowing users on local Windows WAMP/XAMPP environments to always download marksheet PDFs utilizing the fallback engine. - Code Simplification: Updated both the synchronous download controller and the asynchronous background queue job (
GenerateBulkMarksheetJob.php) to use the centralizedconfigureBrowsershotmethod.
📊 Deep Code Analysis (Backend & Web)
Based on a deep-dive into the actual codebase changes over the recent development cycles, V2.9.5 represents a massive expansion of the Parent API, Payment Gateways, and Study Center infrastructure.
Key Code-Level Enhancements:
- Parent API v1 Expansion: Extensive additions to
routes/api_v1.php. We've added dedicated API controllers forLibraryController,GalleryController,SchoolVisitController,HealthController,CommunicationHistoryController, andProfileController. This fully flesh out the Flutter Parent App's capabilities. - Payment Gateway Architecture: Integrated deeply with
PayuMoneyGateway.phpandCashfreeGateway.phpwithinapp/Services/Gateways. Added a unifiedWebhookController.phpto handle asynchronous payment confirmations securely, bypassing CSRF limitations properly. - Study Center & Live Classes: Added robust backend infrastructure for Live Classes. Created
SendLiveClassReminder.php(Job) andLiveClassReminderNotification.phpscheduled viaroutes/console.phpto alert students/parents before live sessions start. UpdatedHomeworkController.phpand submission views. - Data Models: Updated
Student.phpmodel andStudentProfileResource.phpto serialize complex nested relationships (health records, sibling links, communication history) cleanly for the mobile APIs.
📝 Detailed Changelog — ProjectWorlds Multi School ERP SaaS V2.9.5
V2.9.5 — API Expansion, Payments & Study Center (May 2026)
🏗️ API & Backend Architecture (Laravel)
- Parent App API Completeness: Rolled out comprehensive v1 endpoints for the Parent Mobile App.
- Library Module: Real-time book catalogs and issue/return history via
LibraryController. - Health Profiles: Access to student medical records, vaccination logs via
HealthController. - Communication Logs: Centralized view of all SMS/Push/Email alerts sent to parents via
CommunicationHistoryController. - Visitor Logs: Parent visibility into front-office gate passes via
SchoolVisitController. - Gallery & Albums: Media delivery endpoints via
GalleryController.
- Library Module: Real-time book catalogs and issue/return history via
- Resource Optimization: Refactored
StudentProfileResourceto efficiently load eager-loaded relationships without N+1 query issues. - Student Model: Enhanced the
Studentmodel with new data accessors for the extended Parent API.
💳 Payment Gateways & Finance
- New Integrations: Deployed full Service-layer implementations for PayU Money and Cashfree gateways.
- Unified Webhooks: Created a centralized, secure
WebhookControllerto reliably process asynchronous payment callbacks from Stripe, PayU, and Cashfree. - Fee Controllers: Enhanced both web (
Parent\FeeController) and API (Api\V1\Parent\FeeController) to support the new gateway ecosystem seamlessly. - Database Seeds: Added migration
2026_05_20_042900_seed_payu_cashfree_gateways.phpto automatically configure gateway settings for existing tenants.
📚 Study Center & Academics
- Live Class Reminders: Implemented an automated background queue job (
SendLiveClassReminder) and Notification class to push alerts to users before a scheduled live class begins. - Study Center Web Portal: Completely overhauled the Parent web portal for the Study Center, including new Blade views for
live_classes,_materials, and the live classroom. - Homework Engine: Upgraded the
HomeworkControllerwith improved tracking of student submissions and integrated file uploads for homework documents. - Console Routing: Configured
routes/console.phpto properly schedule the Live Class reminder dispatcher.
📡 Mobile Apps (Flutter Integration)
- Auth Controller Hardening: Enhanced state management and robust error handling in the Staff App's
auth_controller.dartfor seamless token transitions.
💬 WhatsApp Notification Message (For Existing Clients)
Hello [School Name/Admin Name], 👋
ProjectWorlds ERP V2.9.5 is officially live! We've deeply upgraded your system's core capabilities. 🚀
🌟 What's New in V2.9.5? • 💳 New Payment Gateways: Accept parent fee payments easily via PayU and Cashfree. • 📱 Massive Parent App Update: Parents can now view Library books, Health profiles, Gallery albums, and Visitor logs directly from their app! • 🎥 Live Class Automation: The system will now automatically send reminder notifications to students before a Live Class starts. • 📚 Study Center Upgrade: Improved homework submission tracking and a brand new web interface for accessing study materials. • ⚡️ Reliable Payments: Upgraded webhook systems ensure that fee receipts are generated instantly, even on slow connections.
Your system has been automatically upgraded to the latest version. Please refresh your browser or update your apps to see the changes! 📲
🔗 Access your dashboard here: [Insert Login URL]
Need help? Our support team is just a message away.
Best Regards, Projectworlds Support Team
Changelog — ProjectWorlds Multi School ERP SaaS V2.0
All notable changes to this project will be documented in this file.
V2.0.0 — Initial Release (April 2026)
🏗️ Architecture
- Complete rebuild on Laravel 12 (PHP 8.3+) and Flutter 3.35.4 (Dart 3.x).
- Multi-tenant SaaS architecture with single-database tenant isolation via
school_id. - Service-layer pattern with dedicated Service classes for business logic.
BelongsToSchooltrait for automatic tenant scoping on all models.- Spatie Permissions for role-based access control (RBAC).
- Laravel Sanctum for API token authentication.
🧠 AI & Intelligence
- Data-Grounded AI Assistant powered by Gemini & OpenAI.
- Intent-detection engine with specialized data fetchers (fees, attendance, marks).
- Role-based AI privacy — parents see only their children's data.
- Available in web admin panel, parent app, and staff app.
📱 Mobile Apps (Flutter)
- Student & Parent App — 13 modules (Dashboard, Fees, Attendance, Exams, Chatbot, Study Center, Bus Tracking, etc.)
- Staff & Admin App — 16 modules (Dashboard, Attendance, Marks, Homework, HR, Leave, Student Management, etc.)
- Driver GPS App — Standalone real-time tracking with background GPS, SOS, and trip management.
- All apps support Firebase push notifications (FCM).
- Biometric / PIN lock login support.
💻 Desktop Agent
- Windows Biometric Sync Agent (.NET 8.0 / WinForms).
- ZKTeco ADMS Push Protocol — no static IP required.
- Cloud-based fingerprint template backup & restore.
- Real-time attendance log sync to cloud ERP.
🎨 White-Labeling & Theming
- Custom domain mapping per school tenant.
- 6+ Dashboard Themes (Mac OS, Futuristic, Analytics Pro, Classic, etc.).
- Auto-Styling Engine — UI colors auto-match the school's uploaded logo.
- Custom login page styles (Modern / Split-Screen).
- Custom menu management per role.
💳 Payment & Finance
- 5 Payment Gateways: Stripe, Razorpay, PayPal, Flutterwave, UPI QR Code.
- Complex fee structures with groups, types, installments.
- Discount & fine rules engine.
- Fee carry-forward across academic sessions.
- Transport fee profiles linked to routes/stops.
- Automated payroll generation & payslip printing.
- Income & expense ledger with bank account management.
- Fee receipt generator with customizable HTML templates.
📚 Academic Modules
- Class, section, subject & teacher management.
- Visual timetable builder.
- Student promotion logic across sessions.
- Offline exams with weighted report cards & mark distributions.
- Online CBT exams with question bank & auto-grading.
- Marksheet & report card generator (multiple presets & orientations).
- Admit card & ID card generation.
- CBC (Competency-Based Curriculum) support for Kenya/Africa.
- Question Paper Generator (Apps Center).
- Syllabus management & study material uploads.
- Homework creation & submission tracking.
🏢 Operations
- Library: Book catalog, ISBN, barcode, issue/return management.
- Hostel: Room types, allocation, fee integration.
- Inventory: Stock management, supplier logs, item issuance, low-stock alerts.
- Front Office: Visitor logs, postal dispatch, complaint handling, admission enquiry CRM.
- Transport: Route/stop/vehicle management, fare profiles, proximity alerts.
📡 Communication
- Firebase push notifications to all mobile apps.
- WhatsApp API integration (interactive messages).
- Telegram bot notifications.
- SMS integration (Twilio).
- Email broadcasting with per-school SMTP configuration.
- Notice board (public / private).
🔒 Security
- AES-256 encryption for all stored API keys and credentials.
- CSRF protection on all web forms.
- Audit logging (owen-it/laravel-auditing).
- OTP-based login support.
- Login activity logs with device/IP tracking.
- Scoped super admin access control.
🌐 SaaS Platform (Super Admin)
- Unlimited school tenants.
- Subscription plans with automated billing.
- Auto-disable schools on subscription expiry.
- SaaS revenue analytics & reports.
- Platform server health monitoring.
- Blog / CMS engine with SEO & sitemap generator.
- Landing page builder for marketing site.
- Master menu manager & addon management.
- Multi-language support.
🆕 Additional Features
- Student health profiles & vaccination tracking.
- Image gallery with albums.
- School landing page builder with templates.
- Certificate generator with HTML templates.
- Event calendar management.
- Interactive Whiteboard (Apps Center).
- Financial Analytics Dashboard (Apps Center).
- Bulk student import via CSV/Excel.
- Student behavior records.
- Co-curricular area management & grading.