Login and Sessions

View saved

Goal

This snapshot advances Stellar Press by teaching you to authenticate with signed session cookies.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Node.js 20+, npm, and a terminal. No Docker is required for SQLite stages.

Port 4321 must be free. Copy .env.example before starting database stages.

  • Node.js and npm
  • A code editor and terminal

Concepts

Keep only the user id in the session and load the user per request.

Keep server endpoints thin: pages present data, API routes enforce rules, and Astro escapes output by default.

Walkthrough

Verify credentials, set the session, and clear it on logout.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

cookies.set('session', String(userId), { httpOnly: true, path: '/' })
return redirect('/')

Run and verify

Enter 07-Login-And-Sessions, install dependencies, copy .env.example, and start Astro on port 4321.

Open http://127.0.0.1:4321. Watch the terminal for validation and database errors.

git clone https://github.com/michaeldunga1/fcc-astro-blog.git
cd fcc-astro-blog/07-Login-And-Sessions
npm install
cp .env.example .env
npm run dev -- --port 4321

Troubleshooting

Changing SESSION_SECRET invalidates cookies.

For database failures, confirm Docker/Wrangler and the *.db name when applicable. Never commit .env, *.db, or node_modules.

  • Read the first error first
  • Restart after environment changes
  • Never commit secrets

Try this

Log in, restart, confirm session, then log out.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Profiles and Media

Comments

One comment per signed-in account. Comments are saved with this page’s URL.