Posts CRUD and Ownership
Goal
This snapshot advances Marlowe Gazette by teaching you to create, edit, and delete stories with owner authorization.
Every numbered folder is complete and independently runnable, so you can inspect this stage without rebuilding earlier lessons.
Prerequisites
Use PHP 8.2 or newer, Composer, Docker, and a terminal. Basic PHP, HTML, and SQL familiarity will help.
The Laravel development server uses port 8000. Root Docker Compose exposes MySQL 8 on port 3307 and each snapshot has a separate database.
- PHP and Composer
- Docker
- A code editor and terminal
Concepts
Authentication identifies the user; Gate authorization compares that identity with the post owner before every mutation.
Laravel keeps HTTP routes, controllers, Eloquent models, validation, authorization, and Blade presentation in explicit layers.
Walkthrough
Create stories through the relationship, validate updates, authorize edit/delete server-side, and show controls only to owners.
Inspect the matching snapshot around the example. The repository includes validation, errors, CSRF protection, and the surrounding application structure.
Gate::authorize('update', $post);
$post->update($data);
Run and verify
Start MySQL from the repository root, enter 09-Posts-CRUD-And-Ownership, install dependencies, copy the environment file, generate an application key, migrate, seed, and serve.
Open http://localhost:8000. From data lessons onward, Ada and Grace are deterministic accounts with password password123.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-laravel-blog.git
cd fcc-laravel-blog/09-Posts-CRUD-And-Ownership
composer install
cp .env.example .env
php artisan key:generate
php artisan migrate --seed
php artisan storage:link
php artisan serve --host=0.0.0.0 --port=8000
Troubleshooting
Hiding a button does not secure a route. A direct cross-account request must still receive HTTP 403.
If MySQL fails, verify Docker is healthy, port 3307 is free, and this snapshot's DB_DATABASE matches its unique marlowe_XX database.
- Read the first exception
- Clear cached config after environment changes
- Never commit .env, vendor, or node_modules
Try this
Create as Ada and attempt to edit as Grace, then verify Ada can update and delete.
Exercise both a successful request and a validation or authorization failure before moving to the next snapshot.
- Make one focused change
- Test it in the browser
- Compare the next snapshot after it works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.