Posts CRUD and Ownership
Goal
This snapshot advances Meridian Notes by teaching you to create, edit, and delete only the signed-in author's posts.
Every numbered folder is a complete application. Run this stage on its own, then compare it with the previous snapshot to isolate the new responsibility.
Prerequisites
Use Node.js 20 or newer, npm, and a terminal. You should be comfortable with JavaScript functions, objects, modules, and basic HTML forms.
The development server uses port 3000. Data-backed snapshots use PostgreSQL on host port 5433 and keep their data in a database unique to that folder.
- Node.js and npm installed
- A code editor and terminal
- Docker from part 4 onward
Concepts
Authentication identifies the caller; authorization compares that id with authorId before every mutation. Hidden buttons are presentation, not security.
Keep the server boundary visible: Server Components may read trusted data directly, while Server Actions and route handlers must validate all incoming values and re-check authorization.
Walkthrough
Build validated create, update, and delete Server Actions, scope the dashboard query to the session user, and reject cross-account changes.
Trace the example from request to rendered result, then inspect the matching snapshot for its surrounding types, validation, error handling, and configuration.
const post = await prisma.post.findUnique({ where: { id } });
if (!post || post.authorId !== session.user.id) throw new Error("403 Forbidden");
Run and verify
Enter 09-Posts-CRUD-And-Ownership, install its dependencies, and copy .env.example when the snapshot includes one.
Open http://localhost:3000. Keep the terminal visible so framework, Prisma, and authentication errors can be matched to the browser action that caused them.
git clone https://github.com/michaeldunga1/fcc-nextjs-blog.git
cd fcc-nextjs-blog/09-Posts-CRUD-And-Ownership
npm install
cp .env.example .env
docker compose -f ../docker-compose.yml up -d
npm run db:migrate
npm run db:seed
npm run dev
Troubleshooting
Always authorize against the current database record. Do not accept an author id from the form, and revalidate or redirect after mutations.
A missing-module error usually means npm ran in another snapshot. Database errors often mean Docker is stopped, the environment file is missing, or this folder points at the wrong numbered database.
- Read the first error first
- Restart after environment changes
- Never commit .env or node_modules
Try this
Create one note as each seed user and attempt a cross-account edit and delete.
Test one expected path and one invalid or unauthorized path. A production-minded app gives useful feedback without exposing secrets or stack traces.
- Make one focused change
- Verify it in the browser
- Continue only after this snapshot works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.