Projects

Not a tile gallery. Each project is part of a larger story about what I've learned, where I struggled, and how my thinking has evolved over the course of this bachelor.

Filter:
MoveWise application landing page
Frontend
↕
API + Auth
↕
Security Layer
↕
Database
Docker · Auth cookies · CSRF · Rate limiting
02 SKIL2 Semester 1 Completed ECTS: 6

MoveWise secure quiz platform

Context & Objective

MoveWise was a SKIL project week group proof of concept: a browser-based quiz application that helps road users refresh traffic knowledge. The objective was to deliver a working demo with clear user/admin role separation, secure authentication, quiz flow, scoring, and reliability measures that could be defended to a stakeholder.

My Contribution

This was group work, but I fully owned the security features. I implemented authentication cookie handling, CSRF protection, rate limiting against brute-force behavior, safer error responses, input validation, and other security controls around the API. I also set up the containers for both the API and the frontend so the application could run as a separated, repeatable environment.

System Implementation

The application was split into a frontend, backend API, and database. The API handled login, role checks, quiz logic, scoring, and protected data access. Sensitive configuration was kept out of source code through environment variables, passwords were handled securely, and the security layer focused on preventing common web application issues such as CSRF, brute-force login attempts, unsafe input, and information leakage through error messages.

Technical Takeaways

This project developed my ability to think about security as part of the application architecture, not as something added at the end. I learned how authentication, cookies, CSRF tokens, rate limits, validation, and container boundaries work together to make a demo defensible instead of only functional.

Failures & Corrections

The main challenge was making security controls fit the team project without blocking the quiz features. I corrected this by treating security requirements as acceptance criteria: login had to use protected cookies, repeated requests had to be limited, state-changing requests needed CSRF protection, and API errors had to stay useful without exposing sensitive implementation details.

Next Iteration Improvements

A next iteration would add automated security tests, stronger logging and monitoring, HTTPS deployment, and a clearer admin audit trail for content changes and reward assignment.

Skills Developed
Technical
Authentication cookies CSRF protection Rate limiting Input validation Safe error handling Docker containers Environment variables
Soft skills
Security ownership in a team Requirement translation Clear technical communication Working under project week pressure
IoT thermostat hardware build
BMP280 Temp
→
Orange Pi
→
Relay/Transistor
↕
MQTT Broker
↕
RPi Pico + LCD
·
ThingSpeak
Orange Pi · MQTT · ThingSpeak
03 IoT Essentials Completed ECTS: 6

IoT thermostat system

Context & Objective

Year 1 IoT Essentials project designed as a multi-device thermostat system. The objective was to make sensing, control, messaging, and visualization operate as one reliable pipeline instead of separate demos.

System Implementation

Implemented an Orange Pi controller that read BMP280 sensor data, evaluated setpoint logic, and switched the heating circuit through transistor/relay control. A Raspberry Pi Pico handled local LCD output and user input. MQTT connected components with publish/subscribe messaging, and ThingSpeak received telemetry for cloud dashboarding and trend history.

Technical Takeaways

This project developed my ability to reason about distributed systems where hardware and software fail differently. I applied MQTT and Python skills to trace data flow from device to broker to dashboard and confirm message integrity at each hop. This directly strengthened my understanding of end-to-end system behavior across sensor acquisition, edge logic, and cloud telemetry.

Failures & Corrections

The first integration had inconsistent MQTT topic names, which caused intermittent control behavior despite healthy individual modules. I corrected this by enforcing topic contracts, standardizing payload formats, and logging publish/subscribe events on each component to verify delivery order and stale retained messages.

Next Iteration Improvements

Next iteration would define versioned message schemas, split control and telemetry topics, and add broker-side monitoring plus watchdog logic to handle disconnected nodes safely.

Skills Developed
Technical
MQTT protocol Python (embedded) Sensor integration (I2C) GPIO control Multi-device debugging Cloud telemetry
Soft skills
Solo project planning Systematic integration testing End-to-end system thinking
Pentesting project security assessment report cover
Burp Suite
↕HTTP intercept
Web Application
↕
SQLi
·
XSS · CSRF
↓
Cmd Injection → RCE
Burp Suite · OWASP · Exploit chaining
04 Application Security Completed ECTS: 3

Pentesting project

Context & Objective

Year 2 Application Security project focused on identifying and exploiting real web vulnerabilities with OWASP-driven methodology. The objective was to move from isolated findings to full attack chains with measurable system impact.

System Implementation

Executed reconnaissance and request interception with Burp Suite, manipulated HTTP traffic to test trust boundaries, and validated exploitable paths for SQL Injection, XSS, CSRF, and Command Injection. Findings were documented with payload evidence, privilege level reached, and affected components.

Technical Takeaways

This project developed my ability to think like an attacker and prioritize exploit paths by impact instead of novelty. I applied Burp Suite and HTTP manipulation skills to chain low-severity weaknesses into account takeover and command execution scenarios. This directly strengthened my understanding of how input validation, session handling, and server-side execution controls fail under adversarial pressure.

Failures & Corrections

Early testing was too vulnerability by vulnerability and missed exploit chaining opportunities. I corrected this by mapping trust transitions between endpoints, reusing authenticated context where relevant, and sequencing payloads to escalate from reflected XSS and CSRF weaknesses toward broader compromise.

Skills Developed
Technical
Burp Suite HTTP manipulation SQL Injection XSS / CSRF Command Injection OWASP methodology
Soft skills
Attacker mindset Structured methodology Risk prioritization
Web design portfolio screenshot
HTML structure
↕
CSS / Flexbox
·
Bootstrap
↕
Responsive layout
·
Floats
HTML · CSS · Flexbox · Bootstrap
05 Web Design Essentials Completed ECTS: 6

Web design portfolio

Context & Objective

Year 1 Web Design Essentials and my first real front-end project. The objective was to build a structured multi-section portfolio and make layout behavior stable across desktop and mobile breakpoints.

System Implementation

Implemented semantic HTML structure, CSS layout rules, Flexbox alignment, float-based fallback sections, and Bootstrap utilities where they accelerated responsive spacing and component consistency. The focus was page structure, readable hierarchy, and predictable reflow behavior.

Technical Takeaways

This project developed my ability to translate static page ideas into maintainable layout systems. I applied HTML and CSS skills to build section hierarchy first, then used Flexbox and Bootstrap selectively to control alignment and responsiveness. This directly strengthened my understanding of browser layout calculation, box model side effects, and why small CSS conflicts create large visual regressions.

Failures & Corrections

Initial versions mixed float and Flexbox rules in ways that produced collapse and overflow at breakpoint edges. I corrected this by isolating layout contexts, reducing utility class overuse, and debugging computed styles in browser dev tools before changing global rules.

Skills Developed
Technical
HTML semantics CSS layout Flexbox Bootstrap Responsive design Browser DevTools
Soft skills
Self-directed learning Iteration from feedback Structured problem solving

Want to know more?

The full story behind these projects is on the About page, where they came from, what broke, and what they changed about how I work.

End of the tour Back to start→ Or skip the loop — the email button above goes straight to me