Posts CRUD and Ownership

View saved

Goal

This snapshot advances Ironwharf Gazette by teaching you to create, edit, and delete posts with owner authorization.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use .NET 8 SDK, a terminal, and Docker for Postgres stages. You should recognize C#, HTTP verbs, and basic HTML.

Port 5081 must be free. Copy .env.example and review appsettings.json before database stages.

  • .NET 8 SDK
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Authentication identifies a user; authorization compares that identity with post.AuthorId before mutations.

Keep components focused: Razor components present data, form handlers and EF Core enforce rules, and Blazor escapes output by default.

Walkthrough

Create posts with the signed-in user id and return 403 when another account attempts edit or delete.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

if (uid is null || int.Parse(uid) != post.AuthorId) { HttpContext.Response.StatusCode = 403; return; }

Run and verify

Enter 09-Posts-CRUD-And-Ownership, restore packages, and run on port 5081.

Open http://127.0.0.1:5081. Watch the terminal for validation and database errors.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-blazor-blog.git
cd fcc-blazor-blog/09-Posts-CRUD-And-Ownership
cp .env.example .env
dotnet restore
dotnet run --urls http://127.0.0.1:5081

Troubleshooting

Forgetting the ownership check is a security bug even if the UI hides edit links.

Restore errors usually mean the SDK is missing or you opened the wrong folder. For Postgres failures, confirm Docker is running and the ironwharf_NN database name matches the snapshot.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or production secrets

Try this

Log in as Ada and confirm Grace's post returns 403 on delete.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Pagination and Search

Comments

One comment per signed-in account. Comments are saved with this page’s URL.