Posts CRUD and Ownership

Create, edit, and delete posts with owner authorization.

Goal

This snapshot advances Copperline Journal by teaching you to create, edit, and delete posts with owner authorization.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder to see the new responsibility clearly.

Prerequisites

Use Node.js 20 or newer, npm, and a terminal. You should recognize basic JavaScript functions, objects, and HTTP requests.

Port 3000 must be available. MongoDB snapshots use Docker locally; copy the example environment file before starting them.

  • Node.js and npm installed
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Authentication identifies a user; authorization compares that identity with the post author before every update or delete.

Keep responsibilities visible: middleware prepares requests, routes choose handlers, models protect data rules, and EJS views present escaped values.

Walkthrough

Create posts with req.user._id, load detail pages, and return 403 when another account attempts a mutation.

Read the example from input to output, then inspect the matching snapshot. The repository includes the surrounding setup and error handling.

if (String(post.author) !== String(req.user._id)) return res.sendStatus(403);
await post.deleteOne();

Run and verify

Enter 09-Posts-CRUD-And-Ownership, install its dependencies, copy .env.example when present, and start the server.

Open http://localhost:3000. Keep the terminal visible so route, validation, and database errors can be connected to the browser action that caused them.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-express-blog.git
cd fcc-express-blog/09-Posts-CRUD-And-Ownership
npm install
cp .env.example .env
npm start
# optional: npm run seed

Troubleshooting

Hiding controls in EJS improves the UI but does not secure direct requests. Ownership checks must remain server-side.

A missing-module error usually means npm install ran in another snapshot. For database failures, check the container and that this folder uses its own Copperline database name.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or node_modules

Try this

Create one post as Ada and one as Grace, then attempt cross-account edits.

Test a happy path and one invalid or unauthorized request. Useful applications return clear feedback without exposing secrets or stack traces.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works