Building a Secure Banking & Shopping System in Python
The story behind my Python desktop application featuring transaction processing, user authentication, and inventory management with security at its core.
The Banking Shopping System is a desktop application I built in Python that combines banking operations with a shopping experience. Users can create accounts, deposit and withdraw funds, browse products, and make purchases, all with security features baked in from the start.
Core Features
- User Authentication, Account creation with hashed passwords and secure login.
- Banking Operations, Deposit, withdraw, check balance, and view transaction history.
- Shopping System, Browse an inventory catalog, add items to cart, and checkout using account balance.
- Transaction Logging, Every financial operation is logged with timestamps for audit trails.
Security Implementation
Password Hashing
User passwords are never stored in plain text. I use Python's hashlib library to hash passwords before storage:
import hashlib
def hash_password(password):
return hashlib.sha256(password.encode()).hexdigest()
def verify_password(input_pw, stored_hash):
return hash_password(input_pw) == stored_hash
Input Validation
Every user input is validated before processing. Withdrawal amounts are checked against the current balance, and negative values are rejected:
def withdraw(account, amount):
if amount <= 0:
print("Invalid amount.")
return False
if amount > account['balance']:
print("Insufficient funds.")
return False
account['balance'] -= amount
log_transaction(account['id'], 'WITHDRAW', amount)
return True
Transaction Integrity
Each transaction is recorded with a unique ID, timestamp, type (deposit/withdraw/purchase), and amount. This creates a complete audit trail that can be reviewed at any time.
Architecture
- auth.py, Handles user registration, login, and password management.
- banking.py, Manages accounts, deposits, withdrawals, and balance inquiries.
- shop.py, Handles the product catalog, cart, and checkout flow.
- main.py, The entry point with a menu-driven interface.
Challenges
- Data persistence, Without a database, I used JSON files to store account data. This required careful file handling to prevent corruption during concurrent writes.
- Menu flow, Designing an intuitive CLI menu that guides users through banking and shopping without confusion took multiple iterations.
- Edge cases, Handling scenarios like insufficient funds during checkout, empty cart submissions, and invalid product IDs required thorough testing.
What I Learned
This was my first significant Python project. It taught me about modular code design, secure data handling, and the importance of thinking about edge cases and error handling from the beginning, not as an afterthought.