Cart, Checkout, and Ownership

Check out orders and protect seller product mutations.

Goal

This snapshot advances Cobblecart Market by teaching you to check out orders and protect seller product mutations.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Ruby 3.2+, Bundler, Node.js 20+, and Docker for Postgres stages.

Port 3010 must be free. Copy .env.example before database stages.

  • Ruby and Bundler
  • Node.js and npm
  • Docker from part 4 onward

Concepts

Checkout creates an Order and OrderItems, clears the cart, and decrements stock. Product update/delete authorize against user ownership.

Turbo keeps interactive UI on the server; Tailwind styles the storefront; Active Record owns persistence and authorization checks.

Walkthrough

Implement checkout and seller product create/edit/delete returning 403 for non-owners.

Read the example, then open the matching snapshot. The repository includes validation, CSRF, and the surrounding structure.

ApplicationRecord.transaction do
  # create order + items, decrement stock, clear session[:cart]
end

Run and verify

Enter 09-Cart-Checkout-And-Ownership, bundle install, copy .env.example, migrate, seed, and boot Puma on port 3010.

Open http://127.0.0.1:3010. From data lessons onward, Ada and Grace use password123.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-rails-ecommerce.git
cd fcc-rails-ecommerce/09-Cart-Checkout-And-Ownership
bundle install
npm install
cp .env.example .env
bin/rails db:prepare
bin/rails server -b 0.0.0.0 -p 3010

Troubleshooting

UI hiding is not authorization—POST as Grace against Ada's product must 403.

For database failures, confirm Docker and the cobble_NN name. Never commit .env, vendor/bundle, or node_modules.

  • Read the first exception first
  • Rebuild assets after Tailwind class changes
  • Never commit secrets

Try this

Complete a checkout as Ada, then attempt to delete Grace's product and confirm 403.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works