Posts CRUD and Ownership

View saved

Goal

This snapshot advances Cedarline Post by teaching you to create, edit, and delete posts with owner authorization.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Go 1.22+, a terminal, and a code editor. You should recognize packages, functions, and HTTP verbs.

Port 8081 must be free. Copy .env.example before starting. Stages from the data layer use a per-snapshot SQLite file (no Docker required).

  • Go 1.22 or newer
  • A code editor and terminal
  • Optional: Docker only if you prefer another database later

Concepts

Authentication identifies a user; authorization compares that identity with post.AuthorID before mutations.

Keep handlers thin: routes accept input, SQL and helpers enforce rules, and html/template escapes output by default.

Walkthrough

Create posts with the session user id and return 403 when another account attempts edit or delete.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

if u == nil || u.ID != post.AuthorID {
	http.Error(w, "Forbidden", http.StatusForbidden); return
}

Run and verify

Enter 09-Posts-CRUD-And-Ownership, copy .env.example, run go mod tidy, and start the server on port 8081.

Open http://127.0.0.1:8081. Watch the terminal for validation and database errors.

git clone https://github.com/michaeldunga1/fcc-go-blog.git
cd fcc-go-blog/09-Posts-CRUD-And-Ownership
cp .env.example .env
go mod tidy
go run .

Troubleshooting

Forgetting the ownership check is a security bug even if the UI hides edit links.

Missing module errors usually mean go mod tidy was not run in this snapshot. For SQLite failures, delete a corrupt *.db file and restart so migrate/seed can recreate it.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or *.db

Try this

Log in as Ada and confirm Grace's post returns 403 on delete.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Pagination and Search

Comments

One comment per signed-in account. Comments are saved with this page’s URL.