https://bharatpay-flaskbank-2.onrender.com/
A full-stack, production-ready banking web application with modern UI/UX, real-time insights, secure transactions, and comprehensive admin controls.
Features β’ Quick Start β’ Tech Stack β’ Documentation β’ Screenshots
- Overview
- Features
- Tech Stack
- Project Structure
- Quick Start
- Configuration
- User Roles
- API Routes
- Database Schema
- Security Features
- Screenshots
- Development
- Deployment
- Contributing
- License
Bharat Pay is a modern, full-stack banking application built with Flask and designed for educational purposes and rapid prototyping. It features a beautiful, responsive UI built with Tailwind CSS, comprehensive transaction management, real-time financial insights, and a powerful admin dashboard.
- β Production-Ready: Secure authentication, CSRF protection, and validated transactions
- β Modern UI/UX: Responsive design with Tailwind CSS, smooth animations, and intuitive navigation
- β Real-Time Insights: Dynamic charts, transaction analytics, and financial trends
- β Admin Controls: User management, profile approvals, and transaction monitoring
- β Beneficiary System: Save frequent recipients for quick transfers
- β One-Command Setup: Automated initialization script handles everything
- Secure Registration: Email validation, password strength requirements, bcrypt hashing
- Login System: Session-based authentication with remember-me functionality
- Profile Management: User onboarding with business details (PAN, GST, Aadhaar)
- Account Verification: Admin approval system for profile changes
- CSRF Protection: Form security with Flask-WTF tokens
- Account Management: Unique 13-digit account numbers (ACC format) and 16-digit card numbers
- Deposits: Add funds with transaction history tracking
- Transfers: Account-to-account money transfers with validation
- Withdrawals: Secure cash-out functionality with balance verification
- Mobile Recharge: Direct recharge with transaction logging
- Receipt Generation: Downloadable transaction receipts with templates
- Save Recipients: Store frequently used transfer recipients
- Quick Send: One-click transfers to saved beneficiaries
- Nickname Support: Custom names for easy identification
- Favorites: Mark important beneficiaries
- Usage Tracking: Automatic tracking of last used date and transaction count
- Real-Time Balance: Live balance updates with growth indicators
- Transaction Analytics: Category breakdown (deposits, transfers, withdrawals, recharges)
- Weekly Activity Graph: 7-day volume trend with SVG visualization
- Monthly Reports: Month-over-month comparisons
- Virtual Card Display: Interactive card with show/hide functionality
- User Management: View, search, and manage all users
- Profile Approvals: Review and approve user profile changes
- Transaction Monitoring: Track all transactions system-wide
- Statistics Overview: Total users, pending approvals, transaction volumes
- Responsive Layout: Mobile-friendly admin panel with hamburger menu
- Responsive Design: Mobile-first approach, works on all devices
- Modern UI: Gradient cards, glass morphism, smooth transitions
- Quick Actions: Easy access to Send Money, Add Funds, Withdraw
- Recent Transactions: At-a-glance transaction history
- Dark Mode Ready: Prepared for theme switching (future enhancement)
- Flask 3.0.0 - Modern Python web framework
- SQLAlchemy 2.0 - ORM for database interactions
- PostgreSQL/SQLite - Flexible database support
- Bcrypt - Password hashing and security
- Flask-Login - Session management
- Flask-WTF - Form validation and CSRF protection
- Tailwind CSS 3.x - Utility-first CSS framework
- Font Awesome 6 - Icon library
- Vanilla JavaScript - Interactive UI components
- Jinja2 - Server-side templating engine
- Python 3.11+ - Modern Python features
- pip - Package management
- Virtual Environment - Isolated dependencies
Flask-Banking-App/
βββ π start.py # Unified initialization & startup script
βββ π run.py # Flask application entrypoint
βββ π config.py # Configuration management
βββ π create_db.py # Database creation script
βββ π tables.py # Database table inspector
βββ π requirements.txt # Python dependencies
βββ π README.md # This file
β
βββ π app/
β βββ π __init__.py # Flask app initialization
β βββ π decorators.py # Custom decorators (@approved_required, @admin_required)
β β
β βββ π models/
β β βββ π user/
β β βββ π user.py # User model (account_number, card_number, balance)
β β βββ π transaction.py # Transaction model (transfers, deposits, etc.)
β β βββ π beneficiary.py # Beneficiary model (saved recipients)
β β
β βββ π routes/
β β βββ π root/ # Public routes
β β β βββ π index.py # Homepage
β β β βββ π login.py # User login
β β β βββ π register.py # User registration
β β β βββ π about.py # About page
β β β βββ π contact.py # Contact page
β β β βββ π services.py # Services page
β β β
β β βββ π user/ # Protected user routes
β β β βββ π dashboard.py # Main dashboard with insights
β β β βββ π deposit.py # Add funds
β β β βββ π transfer.py # Money transfers
β β β βββ π withdraw.py # Cash withdrawals
β β β βββ π recharge.py # Mobile recharges
β β β βββ π transaction_history.py # Transaction logs
β β β βββ π receipt.py # Receipt generation
β β β βββ π beneficiaries.py # Manage beneficiaries
β β β βββ π profile.py # User profile management
β β β
β β βββ π admin/ # Admin-only routes
β β βββ π dashboard.py # Admin overview
β β βββ π users.py # User management
β β βββ π profile_changes.py # Profile approval system
β β βββ π transactions.py # Transaction monitoring
β β
β βββ π static/
β β βββ π root/assets/ # Public assets (CSS, JS, images)
β β βββ π user/assets/ # User dashboard assets
β β
β βββ π templates/
β βββ π root/ # Public templates
β β βββ π default.html # Base layout
β β βββ π index.html
β β βββ π login.html
β β βββ π register.html
β β
β βββ π user/ # User templates
β β βββ π default.html # User base layout
β β βββ π index.html # Dashboard
β β βββ π transfer.html
β β βββ π ...
β β
β βββ π admin/ # Admin templates
β βββ π default.html # Admin base layout
β βββ π dashboard.html
β βββ π ...
β
βββ π instance/
βββ π banking.db # SQLite database (auto-generated)
- Python 3.11 or higher
- pip (Python package manager)
- Git (optional)
# Clone the repository (or download ZIP)
git clone <repository-url>
cd Flask-Banking-App
# Run the unified startup script
python start.pyThat's it! The script will:
- β Install all dependencies from requirements.txt
- β Create the database and tables
- β
Create default admin user (
admin@bwavebank.com/admin123) - β Start the Flask development server
Open your browser to: http://127.0.0.1:5000
# 1. Clone the repository
git clone <repository-url>
cd Flask-Banking-App
# 2. Create virtual environment (optional but recommended)
python -m venv venv
# Windows
venv\Scripts\activate
# macOS/Linux
source venv/bin/activate
# 3. Install dependencies
pip install -r requirements.txt
# 4. Create database and tables
python create_db.py
# 5. Run the application
python3 start.pyEmail: admin@bwavebank.com
Password: admin123
β οΈ Security Note: Change the admin password immediately after first login in production environments.
Create a .env file in the root directory (optional, defaults work for development):
# Database Configuration
DB_URI=sqlite:///instance/banking.db
# For PostgreSQL:
# DB_URI=postgresql+psycopg2://user:password@localhost:5432/banking_db
# Flask Configuration
SECRET_KEY=your-secret-key-here-change-in-production
DEBUG=True
# Optional Settings
AUTO_CREATE_TABLES=True
FLASK_ENV=development| Variable | Description | Default |
|---|---|---|
DB_URI |
Database connection string | sqlite:///instance/banking.db |
SECRET_KEY |
Flask session encryption key | Auto-generated |
DEBUG |
Enable debug mode | True |
AUTO_CREATE_TABLES |
Auto-create missing tables | True |
SQLite (Default - Development)
DB_URI = "sqlite:///instance/banking.db"PostgreSQL (Production)
DB_URI = "postgresql+psycopg2://username:password@localhost:5432/banking_db"- View personal dashboard with financial insights
- Perform transactions (deposit, transfer, withdraw, recharge)
- Manage beneficiaries
- View transaction history
- Generate transaction receipts
- Update profile (requires admin approval)
- Access admin dashboard with system statistics
- Manage all users (view, search, delete)
- Approve/reject profile change requests
- Monitor all transactions system-wide
- View pending approvals and alerts
GET / - Homepage
GET /about - About page
GET /services - Services page
GET /contact - Contact page
GET /login - Login page
POST /login - Process login
GET /register - Registration page
POST /register - Process registration
GET /logout - Logout user
GET /dashboard - Main dashboard with insights
GET /deposit - Deposit page
POST /deposit - Process deposit
GET /transfer - Transfer money page
POST /transfer - Process transfer
GET /withdraw - Withdrawal page
POST /withdraw - Process withdrawal
GET /recharge - Recharge page
POST /recharge - Process recharge
GET /transaction-history - View all transactions
GET /receipt/<id> - Generate transaction receipt
GET /beneficiaries - Manage beneficiaries
POST /beneficiaries/add - Add new beneficiary
POST /beneficiaries/delete/<id> - Remove beneficiary
GET /profile - User profile
POST /profile - Update profile
GET /admin/dashboard - Admin overview
GET /admin/users - User management
GET /admin/profile-changes - Profile approval queue
POST /admin/approve/<id> - Approve profile change
POST /admin/reject/<id> - Reject profile change
GET /admin/transactions - Transaction monitoring
POST /admin/delete-user/<id> - Delete user
CREATE TABLE users (
id INTEGER PRIMARY KEY,
full_name VARCHAR(100) NOT NULL,
email VARCHAR(120) UNIQUE NOT NULL,
password_hash VARCHAR(255) NOT NULL,
account_number VARCHAR(16) UNIQUE, -- ACC1234567890123
card_number VARCHAR(16) UNIQUE, -- 16-digit card
balance NUMERIC(12, 2) DEFAULT 0.00,
is_admin BOOLEAN DEFAULT FALSE,
is_approved BOOLEAN DEFAULT TRUE,
-- Onboarding Fields
business_name VARCHAR(150),
pan_card VARCHAR(10),
gst_number VARCHAR(15),
aadhaar_number VARCHAR(12),
address TEXT,
created_at DATETIME DEFAULT NOW
);CREATE TABLE transactions (
id INTEGER PRIMARY KEY,
user_id INTEGER NOT NULL,
recipient_id INTEGER,
recipient_name VARCHAR(100),
recipient_card_number VARCHAR(16), -- Stores account_number
amount NUMERIC(12, 2) NOT NULL,
type VARCHAR(25) NOT NULL, -- transfer, deposit, withdrawal, recharge
description TEXT,
timestamp DATETIME DEFAULT NOW,
FOREIGN KEY (user_id) REFERENCES users(id)
);CREATE TABLE beneficiaries (
id INTEGER PRIMARY KEY,
user_id INTEGER NOT NULL,
beneficiary_name VARCHAR(100) NOT NULL,
beneficiary_card_number VARCHAR(16) NOT NULL, -- Stores account_number
nickname VARCHAR(50),
is_favorite BOOLEAN DEFAULT FALSE,
last_used DATETIME,
total_transactions INTEGER DEFAULT 0,
created_at DATETIME DEFAULT NOW,
FOREIGN KEY (user_id) REFERENCES users(id)
);CREATE TABLE profile_change_log (
id INTEGER PRIMARY KEY,
user_id INTEGER NOT NULL,
field_name VARCHAR(50) NOT NULL,
old_value TEXT,
new_value TEXT,
status VARCHAR(20) DEFAULT 'pending', -- pending, approved, rejected
requested_at DATETIME DEFAULT NOW,
reviewed_at DATETIME,
reviewed_by INTEGER,
FOREIGN KEY (user_id) REFERENCES users(id)
);- β Bcrypt Password Hashing - Industry-standard password encryption
- β Session Management - Secure Flask sessions with secret key
- β
Login Required Decorator - Protected routes with
@login_required - β
Approved User Decorator - Additional layer with
@approved_required - β
Admin Only Decorator - Admin route protection with
@admin_required
- β Balance Validation - Prevents overdrafts and negative balances
- β Account Verification - Validates recipient accounts exist
- β Atomic Transactions - Database commits ensure consistency
- β Amount Validation - Decimal precision and minimum checks
- β CSRF Protection - Form tokens prevent cross-site attacks
- β SQL Injection Prevention - SQLAlchemy ORM parameterized queries
- β XSS Protection - Jinja2 auto-escaping
- β Unique Constraints - Email, account_number, card_number uniqueness
- β Audit Logging - Profile change tracking with timestamps
- Environment variables for sensitive data
- Separate admin and user permissions
- Profile change approval workflow
- Transaction history immutability
- Password strength requirements (implemented in forms)
# Unit tests
python -m pytest tests/
# Coverage report
python -m pytest --cov=app tests/View Tables
python tables.pyReset Database
# Delete database file
rm instance/banking.db
# Recreate
python create_db.pyMigrations (Recommended for Production)
# Install Flask-Migrate
pip install Flask-Migrate
# Initialize migrations
flask db init
# Create migration
flask db migrate -m "Initial migration"
# Apply migration
flask db upgrade# Format with Black
black app/
# Lint with Flake8
flake8 app/
# Type checking with MyPy
mypy app/- Change
SECRET_KEYto a strong random value - Set
DEBUG=False - Use PostgreSQL instead of SQLite
- Configure proper WSGI server (Gunicorn, uWSGI)
- Set up reverse proxy (Nginx, Apache)
- Enable HTTPS with SSL certificate
- Configure environment variables securely
- Set up database backups
- Change default admin password
- Configure logging and monitoring
# Install Gunicorn
pip install gunicorn
# Run with 4 workers
gunicorn -w 4 -b 0.0.0.0:5000 run:appFROM python:3.11-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
CMD ["gunicorn", "-w", "4", "-b", "0.0.0.0:5000", "run:app"]- Heroku: Add
Procfilewithweb: gunicorn run:app - AWS Elastic Beanstalk: Use
application.pyentrypoint - Google Cloud Run: Containerize with Docker
- Azure App Service: Use Python 3.11 runtime
Contributions are welcome! Please follow these steps:
- Fork the repository
- Create a feature branch (
git checkout -b feature/AmazingFeature) - Commit your changes (
git commit -m 'Add some AmazingFeature') - Push to the branch (
git push origin feature/AmazingFeature) - Open a Pull Request
- Follow PEP 8 style guide
- Write descriptive commit messages
- Add tests for new features
- Update documentation as needed
- Keep code modular and reusable
This project is licensed under the MIT License - see the LICENSE file for details.
- Flask - Excellent Python web framework
- Tailwind CSS - Utility-first CSS framework
- Font Awesome - Beautiful icon library
- SQLAlchemy - Powerful ORM
- Community - All contributors and users
For questions, issues, or feature requests:
- π Report Bug
- π‘ Request Feature
- π§ Email: support@bharatpay.com
- π¬ Discord: Join our community
Made with β€οΈ by Your Team
Website β’ Documentation β’ Changelog β’ FAQ



