Login and Sessions
Goal
This snapshot advances Tidepool Notes by teaching you to authenticate with Remix cookie session storage.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Node.js 20+, npm, and a terminal. You should recognize React components, TypeScript modules, and HTTP verbs.
Port 3004 must be free. Copy .env.example before starting database stages.
- Node.js and npm
- A code editor and terminal
- Docker from part 4 onward
Concepts
Remix createCookieSessionStorage signs an httpOnly cookie with SESSION_SECRET. You store only the user id and load the user per request.
Keep the server boundary visible: Remix loaders read trusted data on the server; actions must validate input and re-check authorization before mutations.
Walkthrough
Verify email/password, commit the session cookie, and destroy it on logout.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
session.set("userId", user.id)
return redirect("/", { headers: { "Set-Cookie": await commitSession(session) } })
Run and verify
Enter 07-Login-And-Sessions, install dependencies, copy .env.example when present, and start Remix on port 3004.
Open http://127.0.0.1:3004. Watch the terminal for validation and database errors.
docker compose -f ../docker-compose.yml up -d
git clone https://github.com/michaeldunga1/fcc-remix-blog.git
cd fcc-remix-blog/07-Login-And-Sessions
npm install
cp .env.example .env
npm run db:push
npm run db:seed
npm run dev
Troubleshooting
Changing SESSION_SECRET invalidates cookies. SESSION_HTTPS_ONLY must be true behind HTTPS in production.
Missing-module errors usually mean npm install ran in another snapshot. For Postgres failures, confirm Docker and the tidepool_NN database name.
- Read the first error first
- Restart after environment changes
- Never commit .env or node_modules
Try this
Log in, restart Remix, confirm the session persists, then log out.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Profiles and Media
Comments
One comment per signed-in account. Comments are saved with this page’s URL.