CheatLock is a full-stack, enterprise-grade automated exam proctoring and assessment platform. It combines a secure Android client app featuring AI-driven computer vision and OCR, a high-throughput Node.js/Socket.IO backend, and a feature-rich React proctoring web dashboard for educators.
Explore Features β’ Architecture β’ Getting Started β’ API & WebSockets
Important
- π₯ Download Android APK (Direct Link) β Get the secure exam kiosk app directly from this repository.
- π Download via Official Website β Access the landing page for app setup instructions, guides, and pricing.
- β¨ Overview
- ποΈ System Architecture
- π Key Features
- π Project Structure
- π Getting Started
- βοΈ Environment Variables
- π‘ API & WebSocket Events
- π Security & Integrity Mechanisms
- π License
Maintaining academic integrity in remote and digital examinations requires real-time vigilance without compromising user experience. CheatLock resolves this challenge by establishing an end-to-end ecosystem:
- Android Student Application: Serves as a secure exam kiosk enforcing anti-cheat rules, real-time face detection, background screen streaming, and instant OCR paper digitization.
- Node.js & Express API Server: Manages authentication, exam state machines, integrity event processing, and live WebSocket streaming.
- React Educator Dashboard: Gives instructors live monitoring powers with video/screen feeds, AI anomaly alerts, replay timelines, attendance tracking, and automated reporting.
graph TD
subgraph "Student Device (Android App)"
A[Android Client Kiosk] -->|Jetpack Compose UI| B(Exam Security Controller)
B -->|Face Embedding & Detection| C[Camera Preview]
B -->|Screen Capture Stream| D[Screen Manager]
B -->|ML Kit Camera Scanner| E[OCR Engine]
end
subgraph "Cloud & Backend Infrastructure"
F[Node.js / Express Server] <-->|REST API / JWT| A
G[Socket.IO Gateway] <-->|Real-Time WebSockets| A
H[(MongoDB Database)] <-->|Mongoose ODM| F
end
subgraph "Educator Console (Web Dashboard)"
I[React 18 Dashboard] <-->|HTTP API| F
I <-->|Socket.IO Live Feed| G
end
G -->|Stream Alerts & Feeds| I
A -->|Emit Proctoring Events| G
- π Kiosk Security Mode: Locks screen navigation, detects tab/app switches, blocks screenshots, and records security violations.
- π€ Real-Time AI Face Verification: Tracks head pose, multi-face presence, and candidate absence using on-device face embeddings.
- π· ML Kit OCR Scanner: Allows candidates to scan handwritten physical answer sheets and digitize text seamlessly into digital answers.
- πΉ Live Screen & Camera Streaming: Transmits continuous proctoring metrics and screen frames back to proctors via WebSockets.
- π² Quick QR Login: Supports scanning QR codes generated from the web dashboard for instant candidate authentication and exam entry.
- π‘οΈ Offline Resiliency & Crash Recovery: Saves local state periodically to restore active sessions in case of network drops or app restarts.
- πΊ Live Grid Proctoring: Multi-student video/screen grid showing real-time candidate connection status and live AI risk levels.
- β±οΈ Event Replay Timeline: Detailed post-exam audit trail displaying every flagged security incident with exact timestamps and snapshot evidence.
- π Exam & Question Bank Builder: Create time-bounded exams with multiple question types, automated scoring rules, and student assignment lists.
- π Analytics & Integrity Reports: Interactive data visualization powered by Recharts (class performance averages, flag distributions, attendance stats).
- π« Classroom & Community Hub: Manage student rosters, generate registration tokens, and interact on teacher community boards.
- π Role-Based Access Control (RBAC): JWT authentication for Student, Teacher, and Admin roles.
- β‘ Bi-Directional Socket.IO Streaming: Ultra-low latency event distribution for
proctoring_event,session_start,cheat_flag, andnotification. - π Mongo Database Models: Production-ready schemas for
User,Exam,ExamSession,Submission,ProctoringEvent,IntegrityReview, andTeacherClass. - π‘οΈ Automated Risk Scoring Engine: Calculates integrity risk indices dynamically based on event severity and violation frequency.
cheatLock_App/
βββ app/ # π± Android Native App (Kotlin, Jetpack Compose)
β βββ src/main/java/com/jubayer/cheatlock/
β β βββ ocr/ # ML Kit Image Processing & Answer Extraction
β β βββ proctoring/ # Face Embedding, Screen Capture & Security Control
β β βββ security/ # Kiosk Security Controller & Violation Handlers
β β βββ ui/ # Jetpack Compose Screens (Exam, Login, Student/Teacher Dashboards)
β β βββ util/ # Backend Connection Probes & Dynamic URL Resolvers
β βββ build.gradle.kts
β
βββ backend/ # β‘ Node.js & Express REST / WebSocket Server
β βββ src/
β β βββ middleware/ # JWT Auth & Role Validation
β β βββ models/ # Mongoose Schemas (User, Exam, Session, ProctoringEvent)
β β βββ routes/ # Express API Endpoints (Auth, Exams, Submissions, Classes)
β β βββ socket/ # Socket.IO Proctoring Room Handlers
β β βββ server.js # Main Entry Point & HTTP/WS Bootstrapper
β βββ package.json
β
βββ web-dashboard/ # π₯οΈ Web Proctoring Console (React 18, Vite, TypeScript, Tailwind)
βββ src/
β βββ components/ # Reusable UI Components & Navigation Shell
β βββ lib/ # Axios Client, Auth Helpers & Socket.IO Listener
β βββ pages/ # Live Proctoring, Exam Details, Reports, Replay Timeline
βββ package.json
βββ vite.config.ts
Ensure you have the following installed on your machine:
- Node.js:
v18.0.0or higher - npm:
v9.0.0or higher - MongoDB: Local instance or MongoDB Atlas URI
- JDK: Version 17+ (for Android compilation)
- Android Studio: Ladybug / Hedgehog or newer (Android SDK API Level 34+)
# Navigate to the backend directory
cd backend
# Install dependencies
npm install
# Create environment configuration file
cp .env.example .envEdit your .env file with appropriate credentials (see Environment Variables).
# Start the development server with live reload
npm run devThe backend server will run on http://localhost:5000 (or your configured PORT).
# Open a new terminal and navigate to web-dashboard
cd web-dashboard
# Install dependencies
npm install
# Start the Vite development server
npm run devAccess the Web Dashboard in your browser at http://localhost:5173.
If you just want to run the application, you can download the pre-compiled APK directly:
- Open Android Studio.
- Select Open and choose the
appor rootcheatLock_Appdirectory. - Allow Gradle to sync dependencies (
Jetpack Compose,ML Kit,Socket.IO Client,CameraX). - Ensure your local backend IP is set in
BackendUrlStore.ktor test against your local server address (e.g.,http://10.0.2.2:5000for Android Emulator or your LAN IP for physical device). - Build and run on an Emulator or connected Android physical device (Android 8.0+ / API 26+).
| Variable | Description | Default / Example |
|---|---|---|
PORT |
HTTP & WebSocket server port | 5000 |
MONGODB_URI |
Connection string for MongoDB database | mongodb://localhost:27017/cheatlock |
JWT_SECRET |
Secret key for signing JSON Web Tokens | your_super_secret_jwt_key |
CLIENT_ORIGIN |
Allowed CORS origin for Web Dashboard | http://localhost:5173 |
| Variable | Description | Default / Example |
|---|---|---|
VITE_API_BASE_URL |
Base HTTP and Socket.IO origin for the backend | http://localhost:3000 |
VITE_ENABLE_PROCTORING_TEST_TOOLS |
Enables local-only live-proctoring simulator controls | false |
| Method | Endpoint | Description | Auth Required |
|---|---|---|---|
POST |
/api/auth/register |
Register new user (Student / Teacher) | β |
POST |
/api/auth/login |
Authenticate & retrieve JWT token | β |
GET |
/api/exams |
Fetch all exams (filtered by role) | β |
POST |
/api/exams |
Create a new exam with questions | β (Teacher) |
POST |
/api/sessions/start |
Start an active exam session | β (Student) |
POST |
/api/submissions |
Submit exam answers & digitized OCR text | β (Student) |
GET |
/api/proctoring/events/:sessionId |
Get security event logs for replay timeline | β (Teacher) |
- Client β‘οΈ Server:
join_exam_session: Candidate joins live proctoring room.proctoring_event: Transmits detected anomalies (e.g.,LOOKING_AWAY,MULTIPLE_FACES,TAB_SWITCH).screen_frame: Sends live compressed screen stream.
- Server β‘οΈ Client:
student_flagged: Emits real-time warning to proctor dashboard when a violation occurs.session_terminated: Forces candidate app closure upon proctor revocation.
- Dynamic Token Verification: All socket connections & HTTP requests require valid JWT headers.
- On-Device Machine Learning: Face detection and OCR execute locally on client hardware to preserve candidate privacy and minimize latency.
- Session-Scoped Logs: Event snapshots are timestamped and associated with active exam session IDs for instructor review.
The canonical backend source tree is backend/src. The root-level src tree is deprecated and must not be used for new backend work. See DEPLOYMENT_PRODUCTION_READINESS.md for the source-of-truth map, environment inventory, Docker/Kubernetes notes, health endpoints, release checklist, and smoke-test plan.
Distributed under the MIT License. See LICENSE for more information.