Login and Sessions

View saved

Goal

This snapshot advances Rivermouth Dispatch by teaching you to authenticate with signed session cookies.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Python 3.11+, a terminal, and Docker for Postgres stages. You should recognize functions, modules, and HTTP verbs.

Port 8001 must be free. Copy .env.example before starting database stages.

  • Python 3 and pip/venv
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Starlette SessionMiddleware stores an opaque session cookie. You keep only the user id in the session and load the user per request.

Keep request handling thin: routes accept input, services/models enforce rules, and Jinja templates escape output by default.

Walkthrough

Verify email/password, set request.session['user_id'], and clear the session on logout.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

request.session['user_id'] = user.id
return RedirectResponse('/', status_code=303)

Run and verify

Enter 07-Login-And-Sessions, create a virtualenv, install requirements, copy .env.example when present, and start Uvicorn on port 8001.

Open http://127.0.0.1:8001. Watch the terminal for validation and database errors.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-fastapi-blog.git
cd fcc-fastapi-blog/07-Login-And-Sessions
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
uvicorn main:app --reload --port 8001

Troubleshooting

SessionMiddleware must be added before routes that read the session. Changing SESSION_SECRET invalidates cookies.

Import errors usually mean the virtualenv is inactive or you installed packages in another snapshot. For Postgres failures, confirm Docker and the rivermouth_NN database name.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or .venv

Try this

Log in, restart Uvicorn, confirm the session persists, then log out.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Profiles and Media

Comments

One comment per signed-in account. Comments are saved with this page’s URL.