A teaching project for a 4-role resell marketplace: admin, buyer, seller, delivery man. Written in plain PHP with procedural mysqli and prepared statements. No frameworks, no Composer, no build step. Copy it into XAMPP and it runs.
Clone git repository :
git clone https://github.com/Scynr-Software-Development-Services/Resell-Market-Management-System-Open-Source-.gitCopy the resell-market folder into C:\xampp\htdocs\ so it becomes htdocs/resell-market/.
Start Apache and MySQL in the XAMPP control panel.
Open http://localhost/phpmyadmin → Import → choose database.sql → Go.
Open http://localhost/resell-market/index.php?page=login.
Sign in as the default admin: dhrubo@resell.com / admin123 (or any demo account below).
The admin account is created automatically the first time a page loads (see the bottom of config/config.php). Everyone else signs up on the register page.
If your MySQL uses a password, change DB_PASS in config/config.php.
resell-market/
├── index.php Front controller: the ONLY entry point (router)
├── database.sql Schema + demo accounts + sample products
├── README.md
│
├── config/
│ └── config.php DB connection, session settings, app constants
│
├── helpers/
│ └── helpers.php esc(), CSRF, login guards, flash messages
│
├── models/ M — every SQL query lives here
│ ├── user_model.php all 4 roles (one users table)
│ ├── product_model.php products + notifications + invoices (seller domain)
│ ├── order_model.php orders + payments + reviews (buyer domain) + revenue
│ └── delivery_model.php deliveries + drivers (delivery domain)
│
├── controllers/ C — request handling, validation, decisions
│ ├── auth_controller.php login / register / logout
│ ├── admin_controller.php
│ ├── seller_controller.php
│ ├── buyer_controller.php
│ ├── delivery_controller.php
│ └── ajax_controller.php all JSON endpoints
│
├── views/ V — HTML only
│ ├── partials/ header.php, footer.php (shared layout)
│ ├── auth/ login.php, register.php
│ ├── admin/dashboard.php
│ ├── seller/dashboard.php
│ ├── buyer/dashboard.php
│ └── delivery/dashboard.php
│
└── assets/
├── css/style.css black & white theme
└── js/app.js validation, escaping, live search, AJAX tables (jQuery)
The MVC rule used throughout: a view never runs a query, and a model never prints HTML. The controller sits in the middle: it reads $_POST, validates, calls the model, then requires the view.
Every URL looks like this:
index.php?page=<dashboard>&action=<what to do>&id=<row id>
URL | What happens |
|---|---|
| Login page |
| Signup page |
| Admin dashboard (list mode) |
| Load product 4 into the form |
| Cancel order 7 |
| Returns JSON |
| Sign out |
index.php loads config → helpers → models → controllers, checks the session timeout, then sends the request to one controller. require_role('admin') blocks anyone who is not an admin before the controller even starts.
Each role owns one table and does full Create, Read, Update, Delete and Search on its own dashboard. The form sits at the top of the page; the searchable table sits below it. Clicking Edit reloads the same page with the row loaded into that same form.
Role | Manages (CRUD) | Feature 1 | Feature 2 | Feature 3 |
|---|---|---|---|---|
Admin | User accounts (all roles) | Ban user temporarily | Product approval | Monthly revenue report |
Seller | Products | Update stock status (live indicator) | Invoice generation | Notification (low-stock alerts) |
Buyer | My orders | Search (autocomplete catalogue) | Payment | Review |
Delivery | My deliveries | Assign a driver | Delivery schedule (collapsible) | Driver history |
No feature appears on two dashboards.
A buyer places an order → stock drops; if it falls below the low-stock threshold, the seller gets an automatic notification.
The buyer pays for the order → its status becomes paid.
The seller generates an invoice once an order is paid.
The delivery man assigns a paid order to a driver → the order becomes shipped; marking it delivered sets it to completed and frees the driver.
The admin approves new sign-ups and pending products before they go live, and can temporarily ban a misbehaving account.
Requirement | Where to look |
|---|---|
MVC |
|
DB (MySQLi procedural) | every function in |
Auth (session + cookie) |
|
PHP validation | the |
JS validation |
|
AJAX / JSON (jQuery) |
|
UI (HTML/CSS) |
|
Basic web security | see section 6 |
Feature completeness | CRUD + search + 3 features per role |
Attack | Defence | File |
|---|---|---|
SQL injection | Prepared statements everywhere — user text is never glued into SQL | all |
Stolen passwords |
|
|
XSS (server) |
|
|
XSS (client) |
|
|
CSRF | A secret token in every POST form and every delete/approve/ban link |
|
Session fixation |
|
|
Cookie theft |
|
|
Idle machines | Automatic sign-out after 15 minutes |
|
Wrong role |
|
|
URL tampering | A buyer/seller/delivery man can only load their own rows ( |
|
Username guessing | Wrong email and wrong password give the same message |
|
Self-lockout | An admin cannot delete, ban, or demote themselves |
|
Two things worth saying out loud to students:
JavaScript validation is a convenience, not a defence. Anyone can turn JavaScript off. That is why every controller repeats the checks in PHP.
"Remember me" only refills the email, never the password.
All in config/config.php:
define('LOW_STOCK', 5); // a product at or below this triggers a notification
define('CURRENCY', 'Tk'); // symbol shown next to prices
define('SESSION_TIMEOUT', 900); // idle sign-out, in seconds (15 minutes)
define('SESSION_REGEN', 300); // rotate the session id every 5 minutesRole | Password | |
|---|---|---|
Admin |
|
|
Buyer |
|
|
Seller |
|
|
Delivery |
|
|
New users sign up on the register page (buyer, seller, or delivery man only — the register page never offers admin, and the controller checks that list again on the server). New sign-ups need admin approval before they can log in. New admins are created by an existing admin from the Users dashboard.
Member | Role | Owns |
|---|---|---|
Mahir | Buyer |
|
Sanjida | Seller |
|
Dhrubo | Admin |
|
Tonmoy | Delivery Man |
|
index.php, config/, helpers/, controllers/auth_controller.php, controllers/ajax_controller.php, views/partials/, and assets/ are shared infrastructure all four roles depend on.