This is a submission for the GitHub Finish-Up-A-Thon Challenge
What I Built
I revived an abandoned Employee Attendance and Leave Management application. What started as a rushed, barely-functional proof of concept is now a secure, single app Django system with role based authentication, mobile responsive UI, and production ready database configurations. It allows employees to self-manage leave requests and clock in, while giving staff a full dashboard for attendance tracking and exports.
Demo
Github Repository
https://github.com/Kingsmichaei/attendance.git
Live link:
https://attendance-njst.onrender.com/attendance/
The Comeback Story
The Broken "Before" State
When I dusted off this legacy project, it was trapped under a mountain of critical technical debt and architectural fragmentation:
Crashing on Startup: The project split logic unnecessarily between an accounts app and an attendance app. To make matters worse, a simple filename typo (accounts/url.py singular instead of urls.py) and a missing project-level include import caused immediate ModuleNotFoundError crashes.
Infinite Loops: The application’s routing was caught in a recursive logic trap. The sub-app URLs were trying to include themselves, creating an infinite routing loop that paralyzed the Django server.
Security & Configuration Vulnerabilities: The setup script was a security hazard—featuring a hardcoded SECRET_KEY, DEBUG = True left wide open, completely empty ALLOWED_HOSTS, and zero environment tracking. On top of that, every single frontend form entirely lacked csrf_token tags, making the application completely vulnerable to cross-site request forgery.
Rigid Database: The data layout was hard-coded exclusively for local SQLite development, making it impossible to scale or run reliably in a production container ecosystem.
The Transformation Arc
I decided to execute a complete architectural pivot and code overhaul to transform this project into a secure, cohesive application:
1 Architectural Consolidation: I gutted the broken dual-app dependency and moved all core entities including the user flows, dashboard access, and tracking metrics directly into a streamlined, single-app setup under attendance.
2 Environment Isolation: I integrated python-decouple to completely isolate application secrets. The application settings now dynamically assess the runtime environment: executing on lightweight local SQLite files when DEBUG=True and effortlessly scaling out to a robust production PostgreSQL cluster when DEBUG=False.
3 Ironclad Access Control & Security: I systematically refactored the URL configurations to be completely linear, explicit, and non-recursive. Every single user facing form now contains explicit CSRF protection, and user logout routes are strictly bound to secure POST methods. I isolated public kiosk views entirely away from sensitive staff management views using explicit role checks.
4 Feature Expansion & Responsive UI: I introduced an entirely new LeaveRequest data layer to support self-service employee leave management alongside regular clock-in tasks. Finally, the interface received a major design upgrade—featuring data layouts adapted for small screens and an interactive mobile navigation engine powered by a sleek glassmorphic hamburger dropdown menu.
My Experience with GitHub Copilot
My Experience with GitHub Copilot
GitHub Copilot was an invaluable asset during this intense refactoring process, acting as an agile pair programmer that significantly accelerated the path to completion.
Smashed Through Debugging Blocks
The absolute highlight of working with Copilot was diagnosing the broken legacy routing configuration. When I was tracking down why the server was locking up on launch, Copilot instantly highlighted the recursive dependency in attendance/urls.py and provided the clean, linear Django path code to resolve the circular loop. It also immediately picked up on the singular url.py naming mismatch across the workspace, saving me hours of tracking down obscure traceback logs.
Effortless Configuration Boilerplate
Switching an entire application from standard hardcoded settings to environment variables using python-decouple usually requires a lot of tedious copy pasting. Copilot predicted my implementation pattern perfectly. The second I imported config from decouple into settings.py, Copilot automatically suggested the complete, production-hardened variable fallbacks for my PostgreSQL configuration, database credentials, and dynamic ALLOWED_HOSTS listings.
Rapid Prototyping for Front-End Interactions
Writing standard vanilla JavaScript to toggle navigation containers and handle UI transitions can be repetitive. Copilot helped draft the event listeners and class-toggling scripts required for the mobile hamburger navigation bar. It let me focus entirely on refining the CSS glassmorphism styles and layout responsiveness, while it quietly handled the structural element selectors behind the scenes.



Top comments (0)