๐Ÿš€ Hands-On Lab Project ยท Flask + Cloud Firestore BaaS

Smart Campus Lab & IoT Asset Tracker

A full-stack, zero-paste student project built with Python Flask and Firebase Admin SDK. It lets computer science students track microcontrollers, single-board computers, and sensor hardware in real-time, demonstrating Firebase Authentication, Firestore NoSQL CRUD, and server-side token verification.

Total Lab Assets
--
Available on Shelf
--
Checked Out / In Use
--
Hardware Categories
--
BLUEPRINT Project Architecture & Starter Guide for Students

Click through the tabs below to view the architectural blueprint, data schema, and minimal starter code to guide students during their live build session:

// Firestore Collection: 'inventory_items'
// Each document represents a lab hardware asset or IoT component
{
  "name": "Raspberry Pi 4 Model B (4GB)",   // String: Asset name
  "category": "Single Board Computers",       // String: Microcontroller / Sensor / SBC
  "quantity": 8,                                // Integer: Stock count
  "status": "Available",                        // Enum: 'Available' | 'In Use' | 'Maintenance'
  "location": "IoT Lab Bench 3",               // String: Physical rack or lab room
  "added_by": "student@crescent.edu",           // String: Email of logged-in user
  "created_at": firestore.SERVER_TIMESTAMP     // Timestamp: Server-side timestamp
}
๐Ÿ’ก Key Teaching Point: Unlike MySQL, Firestore has no tables or rigid schemas. Documents can easily evolve. If students want to add a "serial_number" or "due_date" field tomorrow, they don't need any database migration scripts!
# app.py - Initializing Firebase Admin SDK on Flask Backend
import firebase_admin
from firebase_admin import credentials, firestore, auth

# Load the downloaded private key from Firebase Console
cred = credentials.Certificate("serviceAccountKey.json")
firebase_admin.initialize_app(cred)

# Get Firestore client reference
db = firestore.client()
print("๐Ÿ”ฅ Firebase Admin SDK connected successfully!")
๐Ÿ’ก Key Teaching Point: Highlight that serviceAccountKey.json lives strictly on the backend server. It has administrative privileges and is never exposed to the client browser!
# app.py - Creating user in Firebase Authentication
@app.route("/api/auth/signup", methods=["POST"])
def signup():
    data = request.get_json()
    email = data.get("email")
    password = data.get("password")

    # Create user in Google Cloud Console via Admin SDK
    user_record = auth.create_user(email=email, password=password)

    # Optionally store student profile in Firestore
    db.collection("users").document(user_record.uid).set({
        "email": email,
        "role": "Student",
        "created_at": firestore.SERVER_TIMESTAMP
    })

    return jsonify({"success": True, "uid": user_record.uid})
๐Ÿ’ก Key Teaching Point: Point out that auth.create_user() handles password salting and hashing behind the scenes. No raw passwords are ever stored in the database!
# app.py - Adding and Listing Items in Firestore
@app.route("/api/inventory", methods=["GET", "POST"])
def inventory_api():
    if request.method == "POST":
        item = request.get_json()
        item["created_at"] = firestore.SERVER_TIMESTAMP
        _, doc_ref = db.collection("inventory_items").add(item)
        return jsonify({"success": True, "id": doc_ref.id}), 201

    elif request.method == "GET":
        docs = db.collection("inventory_items").stream()
        results = [{"id": d.id, **d.to_dict()} for d in docs]
        return jsonify({"success": True, "items": results})
๐Ÿ’ก Key Teaching Point: Notice how clean Python list comprehension is for turning Firestore document streams into clean JSON responses for frontend clients.

๐ŸŽฏ Challenge Ideas for Students to Extend this Mini-Project:

  • 1. Due-Date Borrow Tracking: Add a due_date field and flag overdue items in red when status is "In Use".
  • 2. Role-Based Access: Only users with role "Teacher/Admin" can delete assets; students can only view and borrow.
  • 3. QR Code Asset Tagging: Generate QR codes linking to /api/inventory/<id> for scanning physical hardware bins.
  • 4. Low-Stock Alert: Show a toast notification when quantity < 5.
LIVE WORKBENCH Test & Demo the Mini-Project Features Live

1. Authenticate & Add Hardware Asset

SESSION USER: Not Logged In

2. Live Inventory Stream

All
Microcontrollers
SBCs
Sensors
Connecting to inventory stream...

๐Ÿ“ก Live Backend REST & Firebase Inspector

Every button click triggers a real Flask REST API call. Watch the HTTP request & Firebase Admin SDK response below:

// Ready. Trigger an action above to inspect backend & Firestore communication...