Posts CRUD and Ownership
Goal
This snapshot advances Beaconrock Digest by teaching you to create, edit, and delete posts with owner authorization.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Node.js 20+, npm, and Docker for Postgres stages.
Port 3005 must be free. Copy .env.example before starting database stages.
- Node.js and npm
- A code editor and terminal
- Docker from part 4 onward
Concepts
Authorization compares session user id with post.authorId.
Keep the server boundary visible: routeLoader$ reads trusted data; routeAction$ validates input and re-checks authorization before mutations.
Walkthrough
Return 403 when another account mutates.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
if (userId !== post.authorId) {
fail(403, { message: 'Forbidden' })
}
Run and verify
Enter 09-Posts-CRUD-And-Ownership, install dependencies, copy .env.example, and start Qwik City on port 3005.
Open http://127.0.0.1:3005. Watch the terminal for validation and database errors.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-qwik-blog.git
cd fcc-qwik-blog/09-Posts-CRUD-And-Ownership
npm install
cp .env.example .env
npm run dev
Troubleshooting
UI hiding is not authorization.
For database failures, confirm Docker is running and the beaconrock_NN name matches the snapshot. Never commit .env or node_modules.
- Read the first error first
- Restart after environment changes
- Never commit secrets
Try this
Log in as Ada and confirm Grace's post returns 403 on delete.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.