Cart, Checkout, and Ownership

View saved

Goal

This snapshot advances Gearcart Market by teaching you to check out orders and protect seller product mutations.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use JDK 17+, Maven, and Docker for MySQL stages.

Port 8084 must be free. Copy .env.example before database stages.

  • JDK 17+
  • Maven
  • Docker from part 4 onward

Concepts

Checkout creates an Order and OrderItems, clears the cart, and decrements stock. Product update/delete authorize against user ownership.

Thymeleaf renders server HTML; Spring Security owns the session; JPA repositories persist catalog and orders.

Walkthrough

Implement checkout and seller product create/edit/delete returning 403 for non-owners.

Read the example, then open the matching snapshot. The repository includes validation, CSRF, and the surrounding structure.

@Transactional
public Order checkout(User user, Map<Long,Integer> cart) { ... }

Run and verify

Enter 09-Cart-Checkout-And-Ownership, copy .env.example, start Docker MySQL, and run ./mvnw spring-boot:run on port 8084.

Open http://127.0.0.1:8084. From data lessons onward, Ada and Grace use password123.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-spring-ecommerce.git
cd fcc-spring-ecommerce/09-Cart-Checkout-And-Ownership
cp .env.example .env
./mvnw spring-boot:run

Troubleshooting

UI hiding is not authorization—POST as Grace against Ada's product must 403.

For database failures, confirm Docker and the gear_NN name. Never commit .env, target/, or secrets.

  • Read the first exception first
  • Rebuild assets after Tailwind class changes
  • Never commit secrets

Try this

Complete a checkout as Ada, then attempt to delete Grace's product and confirm 403.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Pagination and Search

Comments

One comment per signed-in account. Comments are saved with this page’s URL.