Skip to content
Achraf Abderrazik
All work
Internship · ONDACase study 04 / 05

AeroManager

Institutional web platform

Flights, hotels, transport, recruitment and public tenders, brought together in one platform for Morocco’s national airports authority.

Organisation
ONDA · Office National Des Aéroports
Role
Software Engineering Intern · Sole developer
Timeline
July – August 2025 · 1 month

An internship project, not ONDA’s public website. Internal screens and data are not shown here.

Interfaces
11
Screens built as the only developer, across the platform’s five domains.
Use cases
20
Identified in the UML analysis. Each one is covered by role-based access control.
Access levels
3
Permission tiers that set what each kind of user can see and do.
Airports in scope
25
The airports the platform covers.

01Context

During a one-month software engineering internship at ONDA, Morocco’s national airports authority, I was the sole developer of AeroManager, an institutional web platform built for the authority.

02Problem

Five business domains, several kinds of users and one shared platform: every screen needed clear data, and every action the right permissions.

03Architecture

  1. 01Client

    React SPA

    Vite

  2. 02API

    Flask REST API

    Flights · Hotels · Transport · Recruitment · Tenders

  3. 03Security

    JWT + role-based access

    Stateless sessions

  4. 04ORM

    SQLAlchemy

  5. 05Data

    MySQL

Decoupled architecture: single-page app, REST API, ORM and relational database.

04My contribution

Sole developer: the complete UML analysis, the decoupled architecture, every interface, the REST API, stateless JWT authentication, role-based access control and the administration dashboard.

05Technical decisions

  • 01

    Decoupled front and back end

    A React (Vite) single-page app consumes a Flask REST API, so the interface and the business logic can evolve independently.

  • 02

    Stateless authentication

    JWT tokens carry the session, so the API keeps no server-side session state.

  • 03

    Role-based access across every use case

    Access rules are defined per role and applied to every use case identified in the UML analysis.

  • 04

    One relational model

    SQLAlchemy maps the five business domains onto MySQL.

06Results

  • Five business domains served by one REST API
  • Every use case gated by the user’s role
  • Administration dashboard and complete UML analysis delivered

07Stack

  • React
  • Vite
  • Flask
  • SQLAlchemy
  • MySQL
  • JWT
  • UML

The source code isn’t public: it was written during an internship and stays private. Other projects are on GitHub.