Login and Sessions

View saved

Goal

This snapshot advances Copperline Journal by teaching you to authenticate with Passport Local and Mongo-backed sessions.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder to see the new responsibility clearly.

Prerequisites

Use Node.js 20 or newer, npm, and a terminal. You should recognize basic JavaScript functions, objects, and HTTP requests.

Port 3000 must be available. MongoDB snapshots use Docker locally; copy the example environment file before starting them.

  • Node.js and npm installed
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Passport verifies credentials. express-session gives the browser an opaque id while connect-mongo keeps session state outside the process.

Keep responsibilities visible: middleware prepares requests, routes choose handlers, models protect data rules, and EJS views present escaped values.

Walkthrough

Configure the local strategy, serialize the user id, deserialize each request, and provide login and logout routes.

Read the example from input to output, then inspect the matching snapshot. The repository includes the surrounding setup and error handling.

passport.use(new LocalStrategy({ usernameField: "email" }, verify));
passport.serializeUser((user, done) => done(null, user.id));

Run and verify

Enter 07-Login-And-Sessions, install its dependencies, copy .env.example when present, and start the server.

Open http://localhost:3000. Keep the terminal visible so route, validation, and database errors can be connected to the browser action that caused them.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-express-blog.git
cd fcc-express-blog/07-Login-And-Sessions
npm install
cp .env.example .env
npm start
# optional: npm run seed

Troubleshooting

Session middleware must run before Passport session support. A changing session secret invalidates existing cookies.

A missing-module error usually means npm install ran in another snapshot. For database failures, check the container and that this folder uses its own Copperline database name.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or node_modules

Try this

Log in, restart the app, verify the session persists, then log out.

Test a happy path and one invalid or unauthorized request. Useful applications return clear feedback without exposing secrets or stack traces.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Profiles and Media

Comments

One comment per signed-in account. Comments are saved with this page’s URL.