Login and Sessions
Goal
This snapshot advances Cedarline Post by teaching you to authenticate with signed session cookies.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Go 1.22+, a terminal, and a code editor. You should recognize packages, functions, and HTTP verbs.
Port 8081 must be free. Copy .env.example before starting. Stages from the data layer use a per-snapshot SQLite file (no Docker required).
- Go 1.22 or newer
- A code editor and terminal
- Optional: Docker only if you prefer another database later
Concepts
gorilla/sessions stores an opaque session cookie. Keep only the user id in the session and load the user per request.
Keep handlers thin: routes accept input, SQL and helpers enforce rules, and html/template escapes output by default.
Walkthrough
Verify email/password, set user_id in the session, and clear the session on logout.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
s, _ := store.Get(r, "cedarline")
s.Values["user_id"] = id
_ = s.Save(r, w)
Run and verify
Enter 07-Login-And-Sessions, copy .env.example, run go mod tidy, and start the server on port 8081.
Open http://127.0.0.1:8081. Watch the terminal for validation and database errors.
git clone https://github.com/michaeldunga1/fcc-go-blog.git
cd fcc-go-blog/07-Login-And-Sessions
cp .env.example .env
go mod tidy
go run .
Troubleshooting
Changing SESSION_SECRET invalidates cookies. Confirm Secure cookie settings match HTTP vs HTTPS.
Missing module errors usually mean go mod tidy was not run in this snapshot. For SQLite failures, delete a corrupt *.db file and restart so migrate/seed can recreate it.
- Read the first error first
- Restart after environment changes
- Never commit .env or *.db
Try this
Log in, restart the server, confirm the session persists, then log out.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Profiles and Media
Comments
One comment per signed-in account. Comments are saved with this page’s URL.