Cart, Checkout, and Ownership

Check out orders and protect seller product mutations.

Goal

This snapshot advances Quaycart Market by teaching you to check out orders and protect seller product mutations.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use PHP 8.2+, Composer, Node.js 20+, npm, and Docker for MySQL stages.

Port 8004 must be free. Copy .env.example before database stages.

  • PHP and Composer
  • Node.js and npm
  • Docker from part 4 onward

Concepts

Checkout creates an Order and OrderItems, clears the cart, and decrements stock. Product update/delete authorize against user_id.

Livewire keeps interactive UI on the server with components; Tailwind styles the storefront; Eloquent owns persistence and authorization checks.

Walkthrough

Implement Livewire checkout and seller product create/edit/delete with Gate policies returning 403 for non-owners.

Read the example, then open the matching snapshot. The repository includes validation, CSRF, and the surrounding structure.

Gate::authorize('update', $product);
DB::transaction(function () use ($cart, $user) {
    // create order + items, decrement stock, clear session cart
});

Run and verify

Enter 09-Cart-Checkout-And-Ownership, install PHP and Node dependencies, copy .env.example, migrate, seed, build assets, and serve on port 8004.

Open http://127.0.0.1:8004. From data lessons onward, Ada and Grace use password123.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-laravel-ecommerce.git
cd fcc-laravel-ecommerce/09-Cart-Checkout-And-Ownership
composer install
npm install
cp .env.example .env
php artisan key:generate
php artisan migrate --seed
php artisan storage:link
npm run build
php artisan serve --host=0.0.0.0 --port=8004

Troubleshooting

UI hiding is not authorization—POST as Grace against Ada's product must 403.

For database failures, confirm Docker and the quaycart_NN name. Never commit .env, vendor, or node_modules.

  • Read the first exception first
  • Rebuild assets after Tailwind class changes
  • Never commit secrets

Try this

Complete a checkout as Ada, then attempt to delete Grace's product and confirm 403.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works