Posts CRUD and Ownership
Goal
This snapshot advances Wavelength Daily by teaching you to create, edit, and delete only owned posts.
Each numbered folder is a complete app. Run it independently and compare adjacent snapshots to isolate the new responsibility.
Prerequisites
Use Node.js 20 or newer, npm, and a terminal. Basic TypeScript, HTML, and CSS familiarity will help.
The development server uses port 5173. Database snapshots also need Docker and the Supabase CLI.
- Node.js and npm
- A code editor
- Docker from part 4 onward
Concepts
Authentication supplies identity; RLS and author filters enforce authorization for every mutation.
SvelteKit keeps route UI, server loading, and form actions close together while preserving a clear browser/server boundary.
Walkthrough
Validate post forms, set author_id from the verified user, and constrain updates and deletes to that owner.
Trace the example from request to rendered page, then inspect the complete matching snapshot for types, validation, and failure handling.
await supabase.from('posts').update(values).eq('author_id', user.id);
Run and verify
Enter 09-Posts-CRUD-And-Ownership, install dependencies, and start the app. Supabase stages must start the local stack and copy the printed anon key into .env.
Open http://localhost:5173 and keep the terminal visible so browser actions can be matched to server errors.
git clone https://github.com/michaeldunga1/fcc-sveltekit-blog.git
cd fcc-sveltekit-blog/09-Posts-CRUD-And-Ownership
npm install
npx supabase start
cp .env.example .env
npm run dev
Troubleshooting
Hidden edit buttons are only presentation; inspect policies and affected rows when a mutation appears to succeed.
A missing package usually means npm install ran in another snapshot. After changing environment variables, restart the SvelteKit process.
- Read the first error first
- Check the current snapshot path
- Never commit .env or node_modules
Try this
Create as Ada, log in as Grace, and verify cross-account edits are forbidden.
Test one happy path and one invalid or unauthorized path before moving on.
- Make one focused change
- Verify it in the browser
- Compare with the next snapshot after it works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.