Posts CRUD and Ownership

View saved

Goal

This snapshot advances Wavelength Daily by teaching you to create, edit, and delete only owned posts.

Each numbered folder is a complete app. Run it independently and compare adjacent snapshots to isolate the new responsibility.

Prerequisites

Use Node.js 20 or newer, npm, and a terminal. Basic TypeScript, HTML, and CSS familiarity will help.

The development server uses port 5173. Database snapshots also need Docker and the Supabase CLI.

  • Node.js and npm
  • A code editor
  • Docker from part 4 onward

Concepts

Authentication supplies identity; RLS and author filters enforce authorization for every mutation.

SvelteKit keeps route UI, server loading, and form actions close together while preserving a clear browser/server boundary.

Walkthrough

Validate post forms, set author_id from the verified user, and constrain updates and deletes to that owner.

Trace the example from request to rendered page, then inspect the complete matching snapshot for types, validation, and failure handling.

await supabase.from('posts').update(values).eq('author_id', user.id);

Run and verify

Enter 09-Posts-CRUD-And-Ownership, install dependencies, and start the app. Supabase stages must start the local stack and copy the printed anon key into .env.

Open http://localhost:5173 and keep the terminal visible so browser actions can be matched to server errors.

git clone https://github.com/michaeldunga1/fcc-sveltekit-blog.git
cd fcc-sveltekit-blog/09-Posts-CRUD-And-Ownership
npm install
npx supabase start
cp .env.example .env
npm run dev

Troubleshooting

Hidden edit buttons are only presentation; inspect policies and affected rows when a mutation appears to succeed.

A missing package usually means npm install ran in another snapshot. After changing environment variables, restart the SvelteKit process.

  • Read the first error first
  • Check the current snapshot path
  • Never commit .env or node_modules

Try this

Create as Ada, log in as Grace, and verify cross-account edits are forbidden.

Test one happy path and one invalid or unauthorized path before moving on.

  • Make one focused change
  • Verify it in the browser
  • Compare with the next snapshot after it works

Next: Pagination and Search

Comments

One comment per signed-in account. Comments are saved with this page’s URL.