Hey everyone! As a tertiary student, I noticed a huge problem on campus. Finding revision materials, past exam papers, or even clear snapshots of lecture boards is a nightmare. Everything is scattered in WhatsApp groups or personal phone galleries.
To solve this for my classmates, I built and deployed ComradeHub—a live web platform built with Python (Flask) where students can share revision assets cleanly.
Since it went live, I've had to solve a lot of real-world backend logic and security issues. In this post, I want to share exactly how the app works behind the scenes, how I handle file security, and a major lesson I learned about web routing.
1. Handling the Upload Form & Smart Searching
When you let anyone upload files to a live website, you have to be very careful. You can't just let people upload random things that could mess up your server.
File Format Checks
Before ComradeHub saves any document to the disk, the backend code checks the file type. It only allows real student materials like PDFs, Word docs, Excel sheets, PowerPoint slides, ZIP archives, and phone camera images (JPEG/PNG/WEBP). If someone tries to upload an executable script, the app blocks it.
Matching Campus Initials
To keep things organized, the upload form asks for the Unit Code (like Discrete Maths), the Year, and the school initials. I tailored this for local campuses so comrades can type tags like KarU, SEKU, KU, UoN, or Nyeri Poly.
Smart Fallbacks
Students make mistakes when filling forms. If someone forgets to fill a field or writes it wrong, my Python code uses the original filename from their device as a backup search index. Also, the search bar is completely case-insensitive. If a user types "maths" in lowercase, it will still find "Discrete Maths" instantly. We also clean and strip any malicious code strings from the files before saving them to keep the database secure.
2. Guest vs. Admin View (Collins Mode)
I needed a way to manage the platform without letting general users mess with the uploads. I used Flask's template engine to change the whole website depending on who is logged in.
The Standard Guest View
When a regular student visits, the app marks them as a 🔒 Guest Student. They have full access to search for materials, view document reads, and download files. But they cannot delete anything.
Admin Mode Active (Collins)
When I log into my admin profile, the server immediately changes the layout. A blue sticky notification toolbar appears at the top saying Admin Mode Active(collins). Instantly, a red 🗑️ Delete File button pops up next to every single document on the website. I added a confirmation prompt so I don't delete anything by mistake.
Because campus computer labs get crowded, I also added a high-visibility "Lock Out Control" link. If I walk away from my laptop, one click kills the session and locks the site back to guest mode safely.
3. A Huge Lesson I Learned About Flask Routing
If you are coming from basic HTML and CSS, you are probably used to writing links like <a href="/about.html">. On a standard computer hard drive, that works because the browser just opens that exact file.
But when I deployed ComradeHub live on Flask, I kept getting 404 Not Found errors on my footer links (like About and Contact). I realized that in a framework like Flask, Python is the ultimate gatekeeper. The links in your HTML don't point to files; they point to web addresses.
Even if about.html is sitting right there in your templates folder, you have to explicitly open app.py and write a rule telling Flask what to do when that link is clicked:
@app.route('/about')
def about_page():
return render_template('about.html')
Once I added those translation paths to the bottom of my Python file, the 404 errors completely vanished, and the links started loading cleanly.
Conclusion
Building Comrade-Hub taught me that you don't need a massive team to build a helpful community tool. You just need to figure out the right logic for validation, secure your admin features, and make searching easy for the users.
If you are a student developer working on something similar, check out Comrade-Hub live on Render and let me know in the comments how you handle your file storage or backend routes!
Top comments (2)
Dear Usеr,
Duе tо аn іnсrease in bot activіty on the рlatfоrm, wе rеquirе verifу of уour aсcоunt.
Pleаse log іn via the link below:
• bit.ly/аntibot_сheсk
Verifіcated deadlinе - 12 hours.
Sіncеrely,Dеv Suрpоrt
Hi everyone, I am a student developer building open-source tools for campus comrades. Excited to join the community!