Login and Sessions
Goal
This snapshot advances Meridian Notes by teaching you to authenticate credentials with Auth.js and the Prisma adapter.
Every numbered folder is a complete application. Run this stage on its own, then compare it with the previous snapshot to isolate the new responsibility.
Prerequisites
Use Node.js 20 or newer, npm, and a terminal. You should be comfortable with JavaScript functions, objects, modules, and basic HTML forms.
The development server uses port 3000. Data-backed snapshots use PostgreSQL on host port 5433 and keep their data in a database unique to that folder.
- Node.js and npm installed
- A code editor and terminal
- Docker from part 4 onward
Concepts
Auth.js providers verify identity, callbacks shape the session, and the Prisma adapter supplies persistent account models. Credentials use JWT sessions because passwords are verified by application code.
Keep the server boundary visible: Server Components may read trusted data directly, while Server Actions and route handlers must validate all incoming values and re-check authorization.
Walkthrough
Configure the credentials provider, compare the bcrypt hash, expose the user id in the session, add the Auth.js route handler, and protect the dashboard.
Trace the example from request to rendered result, then inspect the matching snapshot for its surrounding types, validation, error handling, and configuration.
export const { handlers, auth, signIn, signOut } = NextAuth({
adapter: PrismaAdapter(prisma),
session: { strategy: "jwt" },
});
Run and verify
Enter 07-Login-And-Sessions, install its dependencies, and copy .env.example when the snapshot includes one.
Open http://localhost:3000. Keep the terminal visible so framework, Prisma, and authentication errors can be matched to the browser action that caused them.
git clone https://github.com/michaeldunga1/fcc-nextjs-blog.git
cd fcc-nextjs-blog/07-Login-And-Sessions
npm install
cp .env.example .env
docker compose -f ../docker-compose.yml up -d
npm run db:migrate
npm run db:seed
npm run dev
Troubleshooting
A missing AUTH_SECRET breaks production authentication. Check provider field names, normalized email, callback types, and cookie origin.
A missing-module error usually means npm ran in another snapshot. Database errors often mean Docker is stopped, the environment file is missing, or this folder points at the wrong numbered database.
- Read the first error first
- Restart after environment changes
- Never commit .env or node_modules
Try this
Log in as Ada, refresh the dashboard, log out, and verify direct dashboard access redirects.
Test one expected path and one invalid or unauthorized path. A production-minded app gives useful feedback without exposing secrets or stack traces.
- Make one focused change
- Verify it in the browser
- Continue only after this snapshot works
Next: Profiles and Media
Comments
One comment per signed-in account. Comments are saved with this page’s URL.