Posts CRUD and Ownership
Goal
This snapshot advances Keystone Gazette by teaching you to create, edit, and delete posts with owner authorization.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use PHP 8.2+, Composer, and Docker for MySQL stages.
Port 8002 must be free. Copy .env.example before starting database stages.
- PHP 8.2+ and Composer
- A code editor and terminal
- Docker from part 4 onward
Concepts
Authorization compares the Security user with post.author.
Keep controllers thin: forms accept input, Doctrine entities enforce rules, and Twig escapes output by default.
Walkthrough
Return 403 when another account mutates.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
if ($this->getUser() !== $post->getAuthor()) { throw $this->createAccessDeniedException(); }
Run and verify
Enter 09-Posts-CRUD-And-Ownership, install Composer deps, copy .env.example, and start the Symfony server on port 8002.
Open http://127.0.0.1:8002. Watch the terminal for validation and database errors.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-symfony-blog.git
cd fcc-symfony-blog/09-Posts-CRUD-And-Ownership
composer install
cp .env.example .env
symfony server:start --port=8002 --no-tls
# or: php -S 127.0.0.1:8002 -t public
Troubleshooting
UI hiding is not authorization.
For database failures, confirm Docker and the keystone_NN name when applicable. Never commit .env or vendor.
- Read the first error first
- Restart after environment changes
- Never commit secrets
Try this
Log in as Ada and confirm Grace's post returns 403 on delete.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Pagination and Search
Comments
One comment per signed-in account. Comments are saved with this page’s URL.