A premium, light-themed (white / black / orange) disaster evacuation platform: a marketing landing page, a panel picker, role-aware login, and a live-map "command center" — with an AI engine (Flask + scikit-learn + A* + CSP) underneath.
index.php (landing: features, "How it works", footer)
│ Get Started
▼
select-panel.php ("Continue as User" / "Continue as Admin")
│
▼
login.php?panel=user|admin (log in, or register — user panel only)
│ on success, role is checked against the chosen panel
▼
dashboard.php (the live map command center — role-based content)
| Layer | Files | Role |
|---|---|---|
| Marketing / entry | index.php, select-panel.php, login.php |
Landing page, panel picker, login/register |
| App shell | dashboard.php, app.js |
Light command-center UI, Leaflet map, forms, admin panel (auto-hidden for non-admins) |
| PHP backend | auth.php, admin_actions.php, responder_actions.php, map_data.php, sos.php, api_proxy.php, db_connect.php |
Sessions, auth (incl. forgot/reset password), CRUD, secure proxy to the AI engine |
| AI engine | app.py |
Logistic regression (flood risk), A* search (safe routes), CSP solver (shelter matching) |
| Database | schema.sql |
MySQL schema + seed data |
Road blockages, shelter updates, and flood readings are stored in MySQL, so
every user sees the same data. The dashboard also polls map_data.php every
10 seconds in the background, so if an admin blocks a road while a citizen
already has the map open, that citizen's map updates on its own within ~20
seconds — no manual refresh needed.
dashboard.phprequires login — visiting it while logged out redirects tologin.php.login.php?panel=user: for Citizen / Volunteer / Responder accounts. Registration is available here. Logging in with an admin account on this screen is rejected with a message pointing to the Admin panel.login.php?panel=admin: for Admin accounts only (no self-registration). Logging in with a non-admin account here is rejected with a message pointing to the User panel.- Citizen / Volunteer / Responder, once on
dashboard.php: flood prediction, route planning, shelter finder, and Emergency SOS tied to their account. - Admin, once on
dashboard.php: everything above, plus an Admin Controls panel appears in the sidebar automatically — live SOS dispatch feed with Acknowledge → Dispatch → Resolve actions, and "Edit roads on map" to click-toggle road blockages directly on the map.
This is handled by auth.php's session + require_role('admin') guards on the
server, and by role checks in login.php / updateAdminVisibility() in
app.js on the client — so it's not just hidden UI, the admin-only endpoints
actually reject non-admins too.
- PHP 8.1+ with PDO MySQL extension, and a web server (Apache/Nginx) or just
php -S - MySQL 8.0+
- Python 3.10+ (for the AI engine)
- Copy this folder into
C:\xampp\htdocs\AquaEvac_DisasterEvacuationPlanner\. - Start Apache and MySQL from the XAMPP Control Panel.
- New database: import
schema.sqlthroughhttp://localhost/phpmyadmin/. Existing AquaEvac database: selectaquaevac_dband importupgrade_xampp.sqlinstead. The upgrade script is safe to run repeatedly and does not drop your database. - From a terminal in the project folder, run:
C:\xampp\php\php.exe seed_demo_users.php- Run
setup_xampp_ai.batonce to create the Python virtual environment and install dependencies. - Run
run_ai.batin a VS Code terminal and keep it running. The AI engine listens onhttp://127.0.0.1:5000. - Open
http://localhost/AquaEvac_DisasterEvacuationPlanner/in your browser.
The PHP app uses api_proxy.php to communicate with the local Flask AI engine.
The default database configuration is compatible with a standard XAMPP MySQL
installation: host 127.0.0.1, port 3306, user root, blank password, database
aquaevac_db. Environment variables can override these defaults.
For the full Windows setup and troubleshooting guide, see XAMPP_VSCODE_SETUP.md.
This build is intended to run locally with XAMPP (Apache + MySQL) and the Flask AI engine from VS Code/Python. Docker is not required.
After running seed_demo_users.php:
| Role | Password | |
|---|---|---|
| Admin | admin@aquaevac.local |
Admin@12345 |
| Citizen | citizen@aquaevac.local |
Citizen@12345 |
| Responder | responder@aquaevac.local |
Responder@12345 |
Log in as admin to see the Admin Controls panel and SOS dispatch feed. Log in as citizen (or just register a new account from the UI) to see the regular user view — no admin panel, but full access to flood prediction, route planning, shelter finder, and sending SOS.
Click "Forgot password?" next to the password field on any login panel.
- The account's password is stored as a bcrypt hash — it can never be looked up or displayed, only reset to something new.
- Requesting a reset creates a random, single-use token (only its SHA-256
hash is stored in
password_resets) that expires after 30 minutes. - This project ships with no email/SMTP server configured, so in demo
mode (
APP_DEMO_MODEunset ortrue, the default) the reset link is handed straight back in the response and shown on screen instead of being emailed. SetAPP_DEMO_MODE=falseonce real email sending is wired up — the endpoint then behaves like a normal production forgot-password flow (same response whether or not the email exists, link goes out by email only). - The link opens
reset-password.php?token=..., where a new password (8+ characters) can be set. The token is consumed on first use.
- Flood risk prediction —
POST /api/predict-flood: a logistic regression model trained onflood_data, features scaled withStandardScaler. Enter rainfall/river level/elevation manually, or click "Use live weather for my location" to auto-fill rainfall and elevation from real data (see below). - Live weather (real data) —
GET /api/live-weather?latitude=..&longitude=..: pulls current rainfall from OpenWeatherMap and elevation from Open-Elevation (a free service, no key needed) for the browser's current location. River level has no standard free public API, so that field always stays manual. To enable live rainfall:- Get a free API key at https://openweathermap.org/api.
- Set it as an environment variable before running
app.py:# macOS/Linux export OPENWEATHER_API_KEY=your_key_here # Windows PowerShell $env:OPENWEATHER_API_KEY="your_key_here"
- Safe route planner —
POST /api/safe-route: A* search over the road graph inroads_graph, where edge cost blends distance, flood hazard, and traffic — and blocked roads are excluded entirely. - Smart shelter finder —
POST /api/recommend-shelter: a constraint satisfaction solver (python-constraint) that filters shelters by capacity, max distance, and route safety, then ranks what's left.
- Passwords are hashed with PHP's
password_hash()(bcrypt) — never stored in plaintext, and never recoverable, only resettable (see "Forgot / reset password" above). - Admin accounts are never self-registerable through the public form; only
citizen/volunteer/respondercan sign up from the UI, matching how a real deployment should work. - If you already had the database set up before this build, use
upgrade_xampp.sql. It checks for existing columns/indexes and upgrades the database without dropping your existing data. Do not re-importschema.sqlunless you intentionally want a fresh database.
The supported local setup is XAMPP (Apache + MySQL) plus the Flask AI engine from VS Code. Docker is not required for this build; run it with XAMPP + VS Code/Python.