DEV Community

Cover image for Reviving an Abandoned Django Attendance Tracker: From ModuleNotFound to Production Ready | GitHub Finish-Up-A-Thon
Kingsmichaei
Kingsmichaei

Posted on

Reviving an Abandoned Django Attendance Tracker: From ModuleNotFound to Production Ready | GitHub Finish-Up-A-Thon

GitHub “Finish-Up-A-Thon” Challenge Submission

This is a submission for the GitHub Finish-Up-A-Thon Challenge

What I Built

I revived an abandoned Employee Attendance and Leave Management application. What started as a rushed, barely-functional proof of concept is now a secure, single app Django system with role based authentication, mobile responsive UI, and production ready database configurations. It allows employees to self-manage leave requests and clock in, while giving staff a full dashboard for attendance tracking and exports.

Demo

Github Repository
https://github.com/Kingsmichaei/attendance.git

Live link:
https://attendance-njst.onrender.com/attendance/

Dashboard

Clock in/ Clock out page

Mobile View

The Comeback Story

The Broken "Before" State
When I dusted off this legacy project, it was trapped under a mountain of critical technical debt and architectural fragmentation:
Crashing on Startup: The project split logic unnecessarily between an ⁠accounts⁠ app and an ⁠attendance⁠ app. To make matters worse, a simple filename typo (⁠accounts/url.py⁠ singular instead of ⁠urls.py⁠) and a missing project-level ⁠include⁠ import caused immediate ⁠ModuleNotFoundError⁠ crashes.
Infinite Loops: The application’s routing was caught in a recursive logic trap. The sub-app URLs were trying to include themselves, creating an infinite routing loop that paralyzed the Django server.
Security & Configuration Vulnerabilities: The setup script was a security hazard—featuring a hardcoded ⁠SECRET_KEY⁠, ⁠DEBUG = True⁠ left wide open, completely empty ⁠ALLOWED_HOSTS⁠, and zero environment tracking. On top of that, every single frontend form entirely lacked csrf_token tags, making the application completely vulnerable to cross-site request forgery.
Rigid Database: The data layout was hard-coded exclusively for local SQLite development, making it impossible to scale or run reliably in a production container ecosystem.

The Transformation Arc

I decided to execute a complete architectural pivot and code overhaul to transform this project into a secure, cohesive application:
1 Architectural Consolidation: I gutted the broken dual-app dependency and moved all core entities including the user flows, dashboard access, and tracking metrics directly into a streamlined, single-app setup under ⁠attendance⁠.
2 Environment Isolation: I integrated ⁠python-decouple⁠ to completely isolate application secrets. The application settings now dynamically assess the runtime environment: executing on lightweight local SQLite files when ⁠DEBUG=True⁠ and effortlessly scaling out to a robust production PostgreSQL cluster when ⁠DEBUG=False⁠.
3 Ironclad Access Control & Security: I systematically refactored the URL configurations to be completely linear, explicit, and non-recursive. Every single user facing form now contains explicit CSRF protection, and user logout routes are strictly bound to secure POST methods. I isolated public kiosk views entirely away from sensitive staff management views using explicit role checks.
4 Feature Expansion & Responsive UI: I introduced an entirely new ⁠LeaveRequest⁠ data layer to support self-service employee leave management alongside regular clock-in tasks. Finally, the interface received a major design upgrade—featuring data layouts adapted for small screens and an interactive mobile navigation engine powered by a sleek glassmorphic hamburger dropdown menu.

My Experience with GitHub Copilot

My Experience with GitHub Copilot
GitHub Copilot was an invaluable asset during this intense refactoring process, acting as an agile pair programmer that significantly accelerated the path to completion.
Smashed Through Debugging Blocks
The absolute highlight of working with Copilot was diagnosing the broken legacy routing configuration. When I was tracking down why the server was locking up on launch, Copilot instantly highlighted the recursive dependency in ⁠attendance/urls.py⁠ and provided the clean, linear Django path code to resolve the circular loop. It also immediately picked up on the singular ⁠url.py⁠ naming mismatch across the workspace, saving me hours of tracking down obscure traceback logs.
Effortless Configuration Boilerplate
Switching an entire application from standard hardcoded settings to environment variables using ⁠python-decouple⁠ usually requires a lot of tedious copy pasting. Copilot predicted my implementation pattern perfectly. The second I imported ⁠config⁠ from decouple into ⁠settings.py⁠, Copilot automatically suggested the complete, production-hardened variable fallbacks for my PostgreSQL configuration, database credentials, and dynamic ⁠ALLOWED_HOSTS⁠ listings.

Rapid Prototyping for Front-End Interactions
Writing standard vanilla JavaScript to toggle navigation containers and handle UI transitions can be repetitive. Copilot helped draft the event listeners and class-toggling scripts required for the mobile hamburger navigation bar. It let me focus entirely on refining the CSS glassmorphism styles and layout responsiveness, while it quietly handled the structural element selectors behind the scenes.

Top comments (0)