Posts CRUD and Ownership

View saved

Goal

This snapshot advances Copperline Journal by teaching you to create, edit, and delete posts with owner authorization.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder to see the new responsibility clearly.

Prerequisites

Use Node.js 20 or newer, npm, and a terminal. You should recognize basic JavaScript functions, objects, and HTTP requests.

Port 3000 must be available. MongoDB snapshots use Docker locally; copy the example environment file before starting them.

  • Node.js and npm installed
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Authentication identifies a user; authorization compares that identity with the post author before every update or delete.

Keep responsibilities visible: middleware prepares requests, routes choose handlers, models protect data rules, and EJS views present escaped values.

Walkthrough

Create posts with req.user._id, load detail pages, and return 403 when another account attempts a mutation.

Read the example from input to output, then inspect the matching snapshot. The repository includes the surrounding setup and error handling.

if (String(post.author) !== String(req.user._id)) return res.sendStatus(403);
await post.deleteOne();

Run and verify

Enter 09-Posts-CRUD-And-Ownership, install its dependencies, copy .env.example when present, and start the server.

Open http://localhost:3000. Keep the terminal visible so route, validation, and database errors can be connected to the browser action that caused them.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-express-blog.git
cd fcc-express-blog/09-Posts-CRUD-And-Ownership
npm install
cp .env.example .env
npm start
# optional: npm run seed

Troubleshooting

Hiding controls in EJS improves the UI but does not secure direct requests. Ownership checks must remain server-side.

A missing-module error usually means npm install ran in another snapshot. For database failures, check the container and that this folder uses its own Copperline database name.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or node_modules

Try this

Create one post as Ada and one as Grace, then attempt cross-account edits.

Test a happy path and one invalid or unauthorized request. Useful applications return clear feedback without exposing secrets or stack traces.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Pagination and Search

Comments

One comment per signed-in account. Comments are saved with this page’s URL.