Login and Sessions
Goal
This snapshot advances Beaconrock Digest by teaching you to authenticate with signed session cookies.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Node.js 20+, npm, and Docker for Postgres stages.
Port 3005 must be free. Copy .env.example before starting database stages.
- Node.js and npm
- A code editor and terminal
- Docker from part 4 onward
Concepts
Keep only the user id in the session and load the user per request.
Keep the server boundary visible: routeLoader$ reads trusted data; routeAction$ validates input and re-checks authorization before mutations.
Walkthrough
Verify credentials, set the session cookie, and clear it on logout.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
setSessionCookie(cookie, user.id)
throw redirect(303, '/')
Run and verify
Enter 07-Login-And-Sessions, install dependencies, copy .env.example, and start Qwik City on port 3005.
Open http://127.0.0.1:3005. Watch the terminal for validation and database errors.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-qwik-blog.git
cd fcc-qwik-blog/07-Login-And-Sessions
npm install
cp .env.example .env
npm run dev
Troubleshooting
Changing SESSION_SECRET invalidates cookies.
For database failures, confirm Docker is running and the beaconrock_NN name matches the snapshot. Never commit .env or node_modules.
- Read the first error first
- Restart after environment changes
- Never commit secrets
Try this
Log in, restart, confirm session, then log out.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Profiles and Media
Comments
One comment per signed-in account. Comments are saved with this page’s URL.