Posts CRUD and Ownership
Goal
This snapshot advances Junction Almanac by teaching you to create, update, and delete only the signed-in author's posts.
Every numbered folder is a complete Rails application. Run this stage independently, then compare it with the previous snapshot to isolate the new responsibility.
Prerequisites
Use Ruby 3.1 or newer, Bundler, PostgreSQL through Docker, and a terminal. Basic Ruby, HTML, and SQL vocabulary will make the framework conventions easier to recognize.
The app listens on port 3000. PostgreSQL is exposed on host port 5434, and every snapshot names a different database so lesson data never leaks between stages.
- Ruby and Bundler
- Docker with Compose
- A code editor and terminal
Concepts
Authentication answers who is making a request; authorization decides whether that user owns the record targeted by each mutation.
Keep the Rails request path visible: the router selects a controller action, Active Record handles data rules, and an ERB view renders the response inside the shared layout.
Walkthrough
Build posts through Current.user.posts, load member records, compare ownership before edit/update/delete, and return 403 for direct cross-account requests.
Read the focused example, then inspect the matching repository snapshot for the surrounding configuration, validation, failure paths, and accessible markup.
def require_owner
head :forbidden unless @post.user == Current.user
end
Run and verify
Enter 09-Posts-CRUD-And-Ownership, install its bundle, prepare its database when this stage uses one, and start Rails on port 3000.
Open http://localhost:3000. Keep the server log visible so you can connect each browser action to its route, SQL query, rendered view, redirect, or validation error.
git clone https://github.com/michaeldunga1/fcc-rails-blog.git
cd fcc-rails-blog/09-Posts-CRUD-And-Ownership
docker compose -f ../docker-compose.yml up -d
bundle install
bin/rails db:prepare db:seed
bin/rails server -p 3000
Troubleshooting
Hiding Edit and Delete links improves presentation but provides no security. Keep the ownership check in the controller before every mutation.
If Rails reports a missing table, run bin/rails db:prepare db:seed in the current snapshot. Connection failures usually mean PostgreSQL is stopped or port 5434 is already occupied.
- Read the first exception first
- Confirm the current numbered folder
- Never commit secrets or config/master.key
Try this
Create posts as Ada and Grace, then attempt a cross-account PATCH and DELETE.
Test one successful request and one invalid or unauthorized request. A production-minded Rails app must preserve data rules even when someone bypasses the visible links and submits a direct request.
- Make one focused change
- Verify it in the browser
- Move on only after the checkpoint works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.