Posts CRUD and Ownership

View saved

Goal

This snapshot advances Saltmarsh Daily by teaching you to create, edit, and delete posts with owner authorization.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Deno 2+ and a code editor. No Docker is required — each snapshot uses its own SQLite file.

Port 8003 must be free. Copy .env.example before starting database stages.

  • Deno runtime
  • A code editor and terminal

Concepts

Authorization compares session user id with post.author_id.

Keep handlers thin: routes present data, server logic enforces rules, and Fresh escapes JSX output by default.

Walkthrough

Return 403 when another account mutates.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

if (session.userId !== post.author_id) {
  return new Response('Forbidden', { status: 403 });
}

Run and verify

Enter 09-Posts-CRUD-And-Ownership, install deps, copy .env.example, and start Fresh on port 8003.

Open http://127.0.0.1:8003. Watch the terminal for validation and database errors.

git clone https://github.com/michaeldunga1/fcc-fresh-blog.git
cd fcc-fresh-blog/09-Posts-CRUD-And-Ownership
deno install
cp .env.example .env
deno task start

Troubleshooting

UI hiding is not authorization.

For SQLite failures, confirm DATABASE_PATH and write permissions. Never commit .env or the .db file.

  • Read the first error first
  • Restart after environment changes
  • Never commit secrets

Try this

Log in as Ada and confirm Grace's post returns 403 on delete.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Pagination and Search

Comments

One comment per signed-in account. Comments are saved with this page’s URL.