A PHP MVC web application built for Web Technologies Project 07. Visitors browse restaurants and food items, members post reviews and food experiences, and admins manage all content.
- PHP 8 (no framework, hand-rolled MVC)
- MySQL 5.7+ / MariaDB
- Vanilla JavaScript (no jQuery, no build step)
- Single CSS file with a custom "warm food vibes" theme
MVC/
index.php front controller / router
.htaccess Apache URL rewrite
config/ db.php, session.php, helpers.php
models/ one PHP class per table
controllers/
auth/ register, login, logout
profile/ show / update / change password
home/ visitor home
restaurants/ public browse + single page
menu/ menu item detail
admin/ admin CRUD + moderation
foodexperience/ food experience posts
api/ AJAX endpoints (return JSON)
views/ PHP view templates
public/
css/style.css theme
js/ main.js, search.js, reviews.js, foodexp.js, admin_inline.js
uploads/menu/ menu item images
uploads/profiles/ profile pictures
database/
schema.sql shared schema (do not modify)
seed.sql sample data
Make sure Docker Desktop is running, then:
docker compose up -d --buildOpen http://localhost:8080/. That's it - MySQL is started, schema + seed are loaded automatically.
To stop:
docker compose downTo start fresh (wipes DB volume):
docker compose down -v && docker compose up -d --buildmysql -u root -p < MVC/database/schema.sql
mysql -u root -p < MVC/database/seed.sqlEdit MVC/config/db.php if your local MySQL user/password is not
root / empty (or export DB_HOST, DB_USER, DB_PASS env vars).
PHP built-in server:
cd MVC
php -S localhost:8000Open http://localhost:8000/.
Apache (XAMPP/MAMP): point DocumentRoot to the MVC/ folder so
.htaccess is honored.
| Role | Password | |
|---|---|---|
| admin | admin@foodly.com | admin123 |
| member | sara@foodly.com | member123 |
| member | tariq@foodly.com | member123 |
| Task | Student ID | What it covers |
|---|---|---|
| 1 | 23-52978-3 | Auth, register, login, Remember Me, profile, visitor home, basic browse |
| 2 | 23-52980-3 | Admin dashboard, restaurant + menu CRUD with image upload |
| 3 | 23-53027-3 | AJAX search/filter, member reviews on food items (post / delete via AJAX) |
| 4 | 24-56637-1 | Food Experience posts + comments, admin moderation (remove members/reviews/posts/comments) |
- Passwords hashed with
password_hash(bcrypt), verified withpassword_verify - All DB queries use PDO prepared statements
- Output escaped via
e()(htmlspecialchars) - Image uploads validated server-side for MIME type and ≤2MB
- Session check on all auth-gated pages
- Admin gate on
/admin/*routes - Member-only gate on review posting and food experience creation