Login and Sessions
Goal
This snapshot advances Driftwood Daily by teaching you to authenticate with signed session cookies.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Node.js 20+, npm, and the Wrangler CLI. You should recognize async functions and HTTP verbs.
Port 8787 must be free. Copy .env.example before starting database stages.
- Node.js and npm
- A code editor and terminal
- Wrangler from part 4 onward
Concepts
Signed cookies store an opaque user id. Keep only the id in the cookie payload.
Keep handlers thin: routes accept input, D1 queries enforce rules, and Hono JSX escapes output by default.
Walkthrough
Verify email/password, set signed cookie, clear on logout.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
await setSignedCookie(c, 'user_id', String(user.id), c.env.SESSION_SECRET);
Run and verify
Enter 07-Login-And-Sessions, install dependencies, copy .env.example when present, and start Wrangler on port 8787.
Open http://127.0.0.1:8787. Watch the terminal for validation and database errors.
git clone https://github.com/michaeldunga1/fcc-hono-blog.git
cd fcc-hono-blog/07-Login-And-Sessions
npm install
cp .env.example .env
npm run dev
Troubleshooting
Changing SESSION_SECRET invalidates cookies.
For D1 failures, confirm Wrangler is running and the driftwood_NN binding matches this folder. Never commit .env or .wrangler secrets.
- Read the first error first
- Restart after environment changes
- Never commit secrets
Try this
Log in, restart Wrangler, confirm session, then log out.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Profiles and Media
Comments
One comment per signed-in account. Comments are saved with this page’s URL.