Login and Sessions
Goal
This snapshot advances Rivermouth Dispatch by teaching you to authenticate with signed session cookies.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Python 3.11+, a terminal, and Docker for Postgres stages. You should recognize functions, modules, and HTTP verbs.
Port 8001 must be free. Copy .env.example before starting database stages.
- Python 3 and pip/venv
- A code editor and terminal
- Docker from part 4 onward
Concepts
Starlette SessionMiddleware stores an opaque session cookie. You keep only the user id in the session and load the user per request.
Keep request handling thin: routes accept input, services/models enforce rules, and Jinja templates escape output by default.
Walkthrough
Verify email/password, set request.session['user_id'], and clear the session on logout.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
request.session['user_id'] = user.id
return RedirectResponse('/', status_code=303)
Run and verify
Enter 07-Login-And-Sessions, create a virtualenv, install requirements, copy .env.example when present, and start Uvicorn on port 8001.
Open http://127.0.0.1:8001. Watch the terminal for validation and database errors.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-fastapi-blog.git
cd fcc-fastapi-blog/07-Login-And-Sessions
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
uvicorn main:app --reload --port 8001
Troubleshooting
SessionMiddleware must be added before routes that read the session. Changing SESSION_SECRET invalidates cookies.
Import errors usually mean the virtualenv is inactive or you installed packages in another snapshot. For Postgres failures, confirm Docker and the rivermouth_NN database name.
- Read the first error first
- Restart after environment changes
- Never commit .env or .venv
Try this
Log in, restart Uvicorn, confirm the session persists, then log out.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Profiles and Media
Comments
One comment per signed-in account. Comments are saved with this page’s URL.