Why concatenated SQL is risky
The Staff Management System includes staff accounts, attendance, leave, payroll, timesheets and role-based workflows backed by an API. That makes server validation and authorization essential: hiding an admin action in Flutter is not enough if the PHP endpoint itself accepts an unauthorized request. When I work on why concatenated sql is risky, I first decide which layer owns the responsibility. Flutter should handle presentation and interaction, while protected business decisions are checked by the server or platform configuration that actually controls them. This separation prevents a UI workaround from hiding a backend or release problem.
I deliberately test failure paths for why concatenated sql is risky. Network timeout, empty data, invalid input, cancelled authentication, unavailable advertising, or a rejected API request should result in a controlled screen state. The application should not show an endless loader or silently save incomplete information simply because the successful path was the only one tested.
Prepared SELECT
For prepared select, I capture the exact state before editing code: input values, user identifier, date range, HTTP status or native error, raw response where safe, and whether the failure happens in debug, locally signed release, or a build installed from Google Play. That evidence usually narrows the problem much faster than changing several files at once.
Another important check is consistency. If the backend calculates a salary period one way but a Flutter history screen sends another month range, both pieces of code may be individually valid while the user sees the wrong result. I therefore compare the parameters and business rules end to end before changing the visual layer.
$stmt = $conn->prepare(
'INSERT INTO attendance (user_id,duty_date,status) VALUES (?,?,?)'
);
$stmt->bind_param('iss', $userId, $date, $status);Prepared INSERT and UPDATE
I deliberately test failure paths for prepared insert and update. Network timeout, empty data, invalid input, cancelled authentication, unavailable advertising, or a rejected API request should result in a controlled screen state. The application should not show an endless loader or silently save incomplete information simply because the successful path was the only one tested.
After a fix, I repeat the original failing workflow rather than accepting a successful compilation as proof. For Play-specific behavior I test the Play-delivered artifact; for API problems I verify the real production endpoint; and for data problems I compare the returned JSON with the model used by the screen.
Input validation
Another important check is consistency. If the backend calculates a salary period one way but a Flutter history screen sends another month range, both pieces of code may be individually valid while the user sees the wrong result. I therefore compare the parameters and business rules end to end before changing the visual layer.
The Staff Management System includes staff accounts, attendance, leave, payroll, timesheets and role-based workflows backed by an API. That makes server validation and authorization essential: hiding an admin action in Flutter is not enough if the PHP endpoint itself accepts an unauthorized request. When I work on input validation, I first decide which layer owns the responsibility. Flutter should handle presentation and interaction, while protected business decisions are checked by the server or platform configuration that actually controls them. This separation prevents a UI workaround from hiding a backend or release problem.
Authorization
After a fix, I repeat the original failing workflow rather than accepting a successful compilation as proof. For Play-specific behavior I test the Play-delivered artifact; for API problems I verify the real production endpoint; and for data problems I compare the returned JSON with the model used by the screen.
For authorization, I capture the exact state before editing code: input values, user identifier, date range, HTTP status or native error, raw response where safe, and whether the failure happens in debug, locally signed release, or a build installed from Google Play. That evidence usually narrows the problem much faster than changing several files at once.
Production error handling
The Staff Management System includes staff accounts, attendance, leave, payroll, timesheets and role-based workflows backed by an API. That makes server validation and authorization essential: hiding an admin action in Flutter is not enough if the PHP endpoint itself accepts an unauthorized request. When I work on production error handling, I first decide which layer owns the responsibility. Flutter should handle presentation and interaction, while protected business decisions are checked by the server or platform configuration that actually controls them. This separation prevents a UI workaround from hiding a backend or release problem.
I deliberately test failure paths for production error handling. Network timeout, empty data, invalid input, cancelled authentication, unavailable advertising, or a rejected API request should result in a controlled screen state. The application should not show an endless loader or silently save incomplete information simply because the successful path was the only one tested.
My troubleshooting workflow
Another important check is consistency. If the backend calculates a salary period one way but a Flutter history screen sends another month range, both pieces of code may be individually valid while the user sees the wrong result. I therefore compare the parameters and business rules end to end before changing the visual layer.
After a fix, I repeat the original failing workflow rather than accepting a successful compilation as proof. For Play-specific behavior I test the Play-delivered artifact; for API problems I verify the real production endpoint; and for data problems I compare the returned JSON with the model used by the screen.
What this project taught me
The main lesson from Staff Management System is that production behavior depends on more than Dart code. Signing certificates, package names, API endpoints, database filters, SDK configuration and store settings are all part of the application. I keep those values in a release checklist and verify the distribution that users will actually install.