Login and Sessions

View saved

Goal

This snapshot advances Redrock Wire by teaching you to authenticate with signed session cookies.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Rust 1.75+, Cargo, and a terminal. No Docker is required for SQLite stages.

Port 8082 must be free. Copy .env.example before starting database stages.

  • Rust and Cargo
  • A code editor and terminal
  • Optional Docker only if you prefer another database later

Concepts

tower-sessions / cookie sessions store an opaque cookie. Keep only the user id.

Keep handlers thin: extractors accept input, sqlx queries enforce rules, and Askama escapes output by default.

Walkthrough

Verify email/password, set session, clear on logout.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

session.insert("user_id", user.id).await?;

Run and verify

Enter 07-Login-And-Sessions, copy .env.example, run cargo run, and start on port 8082.

Open http://127.0.0.1:8082. Watch the terminal for validation and database errors.

git clone https://github.com/michaeldunga1/fcc-axum-blog.git
cd fcc-axum-blog/07-Login-And-Sessions
cp .env.example .env
cargo run

Troubleshooting

Changing SESSION_SECRET invalidates cookies.

For database failures, confirm Docker and the *.db name when applicable. Never commit .env or *.db.

  • Read the first error first
  • Restart after environment changes
  • Never commit secrets

Try this

Log in, restart, confirm session, then log out.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Profiles and Media

Comments

One comment per signed-in account. Comments are saved with this page’s URL.