Bank System

A secure and modern web-based banking platform

Project Overview

The Bank System is a full-stack web application designed to simulate a modern online banking platform. It provides users with secure account management, fund transfers, transaction history, and administrative controls. Built with a focus on security and usability, the project integrates advanced features like two-factor authentication (2FA) and encrypted data storage.

Developed as a proof-of-concept, the platform supports user registration, login, and real-time transaction processing using Stripe Sandbox for payments and Twilio for 2FA. An admin panel allows managing users and transactions, making it suitable for both customers and bank employees.

"Delivering a secure, user-friendly banking experience with modern web technologies."

Technical Details

The application is built using Flask as the backend framework, with SQLite for data storage. The database schema includes tables for users, accounts, transactions, and admin logs, ensuring efficient data management. User passwords and sensitive data are encrypted using AES-256 with a secure key stored in environment variables.

Stripe Sandbox handles payment processing, enabling secure fund transfers and deposits. API requests are authenticated with Stripe’s secret keys, and transactions are logged in real-time. Twilio provides SMS-based 2FA, sending verification codes to users during login or high-value transactions.

The frontend uses Jinja2 templates styled with Tailwind CSS for a responsive, modern interface. JavaScript enhances interactivity, such as dynamic form validation and transaction updates. The application implements CSRF protection and input sanitization to prevent common vulnerabilities.

# Example: AES encryption for passwords
from Crypto.Cipher import AES
import base64

def encrypt_data(data, key):
    cipher = AES.new(key, AES.MODE_EAX)
    nonce = cipher.nonce
    ciphertext, tag = cipher.encrypt_and_digest(data.encode('utf-8'))
    return base64.b64encode(nonce + ciphertext + tag)
                    

AES-256 encryption ensures secure storage of sensitive user data.

Key Metrics

  • Response Time: ~200ms for API requests
  • Database Size: Supports up to 10,000 users
  • Transaction Speed: ~1–2 seconds per transfer
  • Security Level: AES-256, 2FA, CSRF protection

Key Features

User Management

Secure registration and login with AES-encrypted passwords and 2FA via SMS.

Fund Transfers

Real-time transfers between accounts using Stripe Sandbox for secure payments.

Admin Panel

Manage users, transactions, and accounts with a dedicated admin interface (login: admin/admin).

Transaction History

View detailed transaction logs with timestamps and amounts.

Challenges & Solutions

  • Challenge: SQLite OperationalError due to missing columns in database schema.
    Solution: Updated schema to include required fields and implemented database migrations.
  • Challenge: Stripe API rate limits during high transaction volumes.
    Solution: Added retry logic and cached API responses for efficiency.
  • Challenge: Ensuring 2FA reliability across different regions.
    Solution: Configured Twilio with fallback SMS providers and error handling.

Security Measures

Security is a core focus of the Bank System:

  • AES-256 Encryption: Encrypts passwords and transaction data to protect against unauthorized access.
  • Two-Factor Authentication: SMS-based 2FA via Twilio for login and sensitive operations.
  • CSRF Protection: Flask-WTF tokens prevent cross-site request forgery attacks.
  • Input Sanitization: Escapes user inputs to mitigate SQL injection and XSS risks.
  • Secure API Keys: Stripe and Twilio keys are stored in environment variables.

The platform adheres to best practices for web security, ensuring a safe environment for users and administrators.

Visualizations

The application includes visualizations to enhance user experience:

  • Transaction History Chart: Displays transaction amounts over time using Chart.js.
  • Account Balance Trend: Tracks balance changes with a line graph.
  • Transfer Summary: Pie chart showing distribution of transfers by recipient.
Placeholder for Transaction History Chart

Transaction History Chart

Placeholder for Account Balance Trend

Account Balance Trend

Placeholder for Transfer Summary

Transfer Summary

Technologies Used

  • Python
  • Flask
  • SQLite
  • Stripe Sandbox
  • Twilio
  • Tailwind CSS
  • JavaScript
  • Jinja2
  • Chart.js
  • Crypto (PyCryptodome)

Explore the Code

Visit the GitHub repository to explore the implementation details and try the banking system yourself.

View Repository