Posts CRUD and Ownership
Goal
This snapshot advances Copperline Journal by teaching you to create, edit, and delete posts with owner authorization.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder to see the new responsibility clearly.
Prerequisites
Use Node.js 20 or newer, npm, and a terminal. You should recognize basic JavaScript functions, objects, and HTTP requests.
Port 3000 must be available. MongoDB snapshots use Docker locally; copy the example environment file before starting them.
- Node.js and npm installed
- A code editor and terminal
- Docker from part 4 onward
Concepts
Authentication identifies a user; authorization compares that identity with the post author before every update or delete.
Keep responsibilities visible: middleware prepares requests, routes choose handlers, models protect data rules, and EJS views present escaped values.
Walkthrough
Create posts with req.user._id, load detail pages, and return 403 when another account attempts a mutation.
Read the example from input to output, then inspect the matching snapshot. The repository includes the surrounding setup and error handling.
if (String(post.author) !== String(req.user._id)) return res.sendStatus(403);
await post.deleteOne();
Run and verify
Enter 09-Posts-CRUD-And-Ownership, install its dependencies, copy .env.example when present, and start the server.
Open http://localhost:3000. Keep the terminal visible so route, validation, and database errors can be connected to the browser action that caused them.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-express-blog.git
cd fcc-express-blog/09-Posts-CRUD-And-Ownership
npm install
cp .env.example .env
npm start
# optional: npm run seed
Troubleshooting
Hiding controls in EJS improves the UI but does not secure direct requests. Ownership checks must remain server-side.
A missing-module error usually means npm install ran in another snapshot. For database failures, check the container and that this folder uses its own Copperline database name.
- Read the first error first
- Restart after environment changes
- Never commit .env or node_modules
Try this
Create one post as Ada and one as Grace, then attempt cross-account edits.
Test a happy path and one invalid or unauthorized request. Useful applications return clear feedback without exposing secrets or stack traces.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.