Posts CRUD and Ownership
Goal
This snapshot advances Tidepool Notes by teaching you to create, edit, and delete posts with owner authorization.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use Node.js 20+, npm, and a terminal. You should recognize React components, TypeScript modules, and HTTP verbs.
Port 3004 must be free. Copy .env.example before starting database stages.
- Node.js and npm
- A code editor and terminal
- Docker from part 4 onward
Concepts
Authentication identifies a user; authorization compares that identity with post.authorId before mutations.
Keep the server boundary visible: Remix loaders read trusted data on the server; actions must validate input and re-check authorization before mutations.
Walkthrough
Create posts with the session user id and return 403 when another account attempts edit or delete.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
if (!user || user.id !== post.authorId) throw new Response("Forbidden", { status: 403 })
Run and verify
Enter 09-Posts-CRUD-And-Ownership, install dependencies, copy .env.example when present, and start Remix on port 3004.
Open http://127.0.0.1:3004. Watch the terminal for validation and database errors.
docker compose -f ../docker-compose.yml up -d
git clone https://github.com/michaeldunga1/fcc-remix-blog.git
cd fcc-remix-blog/09-Posts-CRUD-And-Ownership
npm install
cp .env.example .env
npm run db:push
npm run db:seed
npm run dev
Troubleshooting
Forgetting the ownership check is a security bug even if the UI hides edit links.
Missing-module errors usually mean npm install ran in another snapshot. For Postgres failures, confirm Docker and the tidepool_NN database name.
- Read the first error first
- Restart after environment changes
- Never commit .env or node_modules
Try this
Log in as Ada and confirm Grace's post returns 403 on delete.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.