Posts CRUD and Ownership

Create, edit, and delete posts with owner authorization.

Goal

This snapshot advances Mossbank Post by teaching you to create, edit, and delete posts with owner authorization.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Go 1.22+, and Docker for Postgres stages.

Port 8083 must be free. Copy .env.example before starting database stages.

  • Go toolchain
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Authorization compares session user id with post.AuthorID.

Keep handlers thin: templates present data, handlers enforce rules, and html/template escapes by default.

Walkthrough

Return 403 when another account mutates.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

if sessionUserID != post.AuthorID {
  c.String(403, "forbidden"); return
}

Run and verify

Enter 09-Posts-CRUD-And-Ownership, copy .env.example, and start Gin on port 8083.

Open http://127.0.0.1:8083. Watch the terminal for validation and database errors.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-gin-blog.git
cd fcc-gin-blog/09-Posts-CRUD-And-Ownership
cp .env.example .env
go run .

Troubleshooting

UI hiding is not authorization.

For database failures, confirm Docker and the mossbank_NN name. Never commit .env.

  • Read the first error first
  • Restart after environment changes
  • Never commit secrets

Try this

Log in as Ada and confirm Grace's post returns 403 on delete.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works