A comprehensive, enterprise-grade pharmacy management system built with FastAPI and PostgreSQL. Designed to automate pharmacy operations including inventory management, sales, purchases, batch tracking, and analytics.
- JWT-based authentication with refresh tokens
- Role-based access control (Admin, Pharmacist, Cashier, Accountant)
- Rate limiting (60 req/min globally, 5 login attempts/min)
- Protection against XSS, CSRF, SQL injection, and brute force attacks
- Comprehensive request logging and audit trails
- Secure password hashing with bcrypt
- Real-time stock tracking
- Batch/lot management with FIFO (First In, First Out)
- Expiry date tracking and alerts
- Low stock notifications
- Stock adjustment capabilities
- Barcode support
- Fast medicine search
- Multi-item cart management
- Automatic price fetching
- Discount support (flat or percentage)
- Multiple payment methods (cash, card, digital)
- Professional invoice generation (PDF)
- Automatic stock deduction by batch
- Purchase invoice creation
- Multi-medicine purchase entries
- Batch details tracking
- Automatic stock updates
- Supplier assignment
- Purchase history and returns
- Supplier database
- Contact information tracking
- Purchase history per supplier
- Supplier performance analytics
- Daily/monthly sales reports
- Top selling items
- Profit analysis
- Inventory reports (current stock, low stock, expired items)
- Purchase reports by supplier
- Export to PDF and CSV
- Total medicines overview
- Low stock alerts
- Near-expiry items
- Daily sales summary
- Top selling items visualization
- Real-time analytics
- Python 3.8+
- PostgreSQL 12+
- pip or uv package manager
- Clone the repository
git clone <repository-url>
cd pharmacy-management-system- Create virtual environment
python -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate- Install dependencies
pip install -r requirements.txt- Configure environment variables
cp .env.example .env
# Edit .env with your configuration- Set up the database
# Run migrations
alembic upgrade head
# Create admin user
python create_admin.py- Start the application
uvicorn app.main:app --reload --host 0.0.0.0 --port 8000The API will be available at http://localhost:8000
- Start all services
docker-compose up -d- Run migrations
docker-compose exec app alembic upgrade head- Create admin user
docker-compose exec app python create_admin.pyThe application will be available at http://localhost:8000
docker-compose downOnce the application is running, access the interactive API documentation:
- Swagger UI: http://localhost:8000/docs
- ReDoc: http://localhost:8000/redoc
- OpenAPI JSON: http://localhost:8000/openapi.json
pharmacy-management-system/
βββ alembic/ # Database migrations
β βββ versions/ # Migration files
βββ app/
β βββ api/ # API endpoints
β βββ core/ # Core configuration
β βββ db/ # Database setup
β βββ middleware/ # Custom middleware
β βββ models/ # SQLAlchemy models
β βββ schemas/ # Pydantic schemas
β βββ services/ # Business logic
β βββ utils/ # Utility functions
β βββ main.py # Application entry point
βββ data/ # Sample data files
βββ docs/ # Documentation
βββ .env.example # Environment variables template
βββ docker-compose.yml # Docker composition
βββ Dockerfile # Docker image definition
βββ requirements.txt # Python dependencies
βββ create_admin.py # Admin user creation script
Key configuration options in .env:
# Application
APP_NAME=Pharmacy Management System
APP_ENV=development
# Database
DATABASE_URL=postgresql://user:password@localhost:5432/pharmacy_db
# Security
SECRET_KEY=your-secret-key-here
ACCESS_TOKEN_EXPIRE_MINUTES=10
REFRESH_TOKEN_EXPIRE_DAYS=30
# Rate Limiting
RATE_LIMIT_PER_MINUTE=60
RATE_LIMIT_PER_HOUR=1000
LOGIN_RATE_LIMIT_PER_MINUTE=5
# Password Policy
PASSWORD_MIN_LENGTH=8
MAX_LOGIN_ATTEMPTS=5
LOCKOUT_DURATION_MINUTES=15| Role | Permissions |
|---|---|
| Admin | Full system access, user management, settings configuration |
- Authentication: JWT tokens with automatic refresh
- Authorization: Role-based access control (RBAC)
- Rate Limiting: Prevents brute force and DDoS attacks
- Security Headers: CORS, CSP, X-Frame-Options, etc.
- Input Validation: Pydantic schemas for all inputs
- SQL Injection Protection: SQLAlchemy ORM
- Password Security: Bcrypt hashing with salt
- Request Logging: All requests logged for audit
Main entities:
- Users: Authentication and role management
- Medicines: Medicine catalog with details
- Batches: Batch/lot tracking with expiry dates
- Suppliers: Supplier information
- Purchases: Purchase transactions and items
- Sales: Sales transactions and items
- Inventory: Real-time stock tracking
- Settings: System configuration
- Handles 10k-50k medicine records efficiently
- Fast search operations (<200ms)
- Optimized database queries with proper indexing
- Connection pooling for database
- 99% uptime target
# Create a new migration
alembic revision --autogenerate -m "description"
# Apply migrations
alembic upgrade head
# Rollback one migration
alembic downgrade -1
# View migration history
alembic history- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
This project is proprietary software. All rights reserved.
For issues and questions:
- Check the API Documentation
- Review the Requirements Document
- Check application logs in
security.log
- β Core pharmacy operations
- β Inventory management
- β Sales and purchase tracking
- β Batch management
- β Reports and analytics
Single pharmacy operations with plans to scale to multi-pharmacy chains. Suitable for:
- Independent pharmacies
- Hospital pharmacies
- Retail pharmacy chains
- Medical stores
Version: 1.0.0
Last Updated: November 2025