Login and Sessions

View saved

Goal

This snapshot advances Wavelength Daily by teaching you to implement login, logout, callbacks, and SSR sessions.

Each numbered folder is a complete app. Run it independently and compare adjacent snapshots to isolate the new responsibility.

Prerequisites

Use Node.js 20 or newer, npm, and a terminal. Basic TypeScript, HTML, and CSS familiarity will help.

The development server uses port 5173. Database snapshots also need Docker and the Supabase CLI.

  • Node.js and npm
  • A code editor
  • Docker from part 4 onward

Concepts

@supabase/ssr synchronizes auth cookies through SvelteKit hooks and verifies users on the server.

SvelteKit keeps route UI, server loading, and form actions close together while preserving a clear browser/server boundary.

Walkthrough

Create the server client per request, use getUser after getSession, and redirect protected routes to login.

Trace the example from request to rendered page, then inspect the complete matching snapshot for types, validation, and failure handling.

const { data: { user } } = await locals.supabase.auth.getUser();

Run and verify

Enter 07-Login-And-Sessions, install dependencies, and start the app. Supabase stages must start the local stack and copy the printed anon key into .env.

Open http://localhost:5173 and keep the terminal visible so browser actions can be matched to server errors.

git clone https://github.com/michaeldunga1/fcc-sveltekit-blog.git
cd fcc-sveltekit-blog/07-Login-And-Sessions
npm install
npx supabase start
cp .env.example .env
npm run dev

Troubleshooting

If login succeeds but the next request is anonymous, inspect cookie setAll handling and the callback URL.

A missing package usually means npm install ran in another snapshot. After changing environment variables, restart the SvelteKit process.

  • Read the first error first
  • Check the current snapshot path
  • Never commit .env or node_modules

Try this

Log in as Ada, reload, sign out, and verify the protected account page redirects.

Test one happy path and one invalid or unauthorized path before moving on.

  • Make one focused change
  • Verify it in the browser
  • Compare with the next snapshot after it works

Next: Profiles and Media

Comments

One comment per signed-in account. Comments are saved with this page’s URL.