Posts CRUD and Ownership

View saved

Goal

This snapshot advances Meridian Notes by teaching you to create, edit, and delete only the signed-in author's posts.

Every numbered folder is a complete application. Run this stage on its own, then compare it with the previous snapshot to isolate the new responsibility.

Prerequisites

Use Node.js 20 or newer, npm, and a terminal. You should be comfortable with JavaScript functions, objects, modules, and basic HTML forms.

The development server uses port 3000. Data-backed snapshots use PostgreSQL on host port 5433 and keep their data in a database unique to that folder.

  • Node.js and npm installed
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Authentication identifies the caller; authorization compares that id with authorId before every mutation. Hidden buttons are presentation, not security.

Keep the server boundary visible: Server Components may read trusted data directly, while Server Actions and route handlers must validate all incoming values and re-check authorization.

Walkthrough

Build validated create, update, and delete Server Actions, scope the dashboard query to the session user, and reject cross-account changes.

Trace the example from request to rendered result, then inspect the matching snapshot for its surrounding types, validation, error handling, and configuration.

const post = await prisma.post.findUnique({ where: { id } });
if (!post || post.authorId !== session.user.id) throw new Error("403 Forbidden");

Run and verify

Enter 09-Posts-CRUD-And-Ownership, install its dependencies, and copy .env.example when the snapshot includes one.

Open http://localhost:3000. Keep the terminal visible so framework, Prisma, and authentication errors can be matched to the browser action that caused them.

git clone https://github.com/michaeldunga1/fcc-nextjs-blog.git
cd fcc-nextjs-blog/09-Posts-CRUD-And-Ownership
npm install
cp .env.example .env
docker compose -f ../docker-compose.yml up -d
npm run db:migrate
npm run db:seed
npm run dev

Troubleshooting

Always authorize against the current database record. Do not accept an author id from the form, and revalidate or redirect after mutations.

A missing-module error usually means npm ran in another snapshot. Database errors often mean Docker is stopped, the environment file is missing, or this folder points at the wrong numbered database.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or node_modules

Try this

Create one note as each seed user and attempt a cross-account edit and delete.

Test one expected path and one invalid or unauthorized path. A production-minded app gives useful feedback without exposing secrets or stack traces.

  • Make one focused change
  • Verify it in the browser
  • Continue only after this snapshot works

Next: Pagination and Search

Comments

One comment per signed-in account. Comments are saved with this page’s URL.