Part 6 of this project

Registration

Validate accounts and store bcrypt password hashes.

Goal

This snapshot advances Rivermouth Dispatch by teaching you to validate accounts and store bcrypt password hashes.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Python 3.11+, a terminal, and Docker for Postgres stages. You should recognize functions, modules, and HTTP verbs.

Port 8001 must be free. Copy .env.example before starting database stages.

  • Python 3 and pip/venv
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Registration normalizes email, checks uniqueness, and stores a one-way hash with passlib—never a raw password.

Keep request handling thin: routes accept input, services/models enforce rules, and Jinja templates escape output by default.

Walkthrough

Accept a form POST, validate password length, hash with bcrypt, and save the user.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

user = User(..., password_hash=hash_password(password))
db.add(user)
db.commit()

Run and verify

Enter 06-Registration, create a virtualenv, install requirements, copy .env.example when present, and start Uvicorn on port 8001.

Open http://127.0.0.1:8001. Watch the terminal for validation and database errors.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-fastapi-blog.git
cd fcc-fastapi-blog/06-Registration
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
uvicorn main:app --reload --port 8001

Troubleshooting

Duplicate username/email should return a clear form error instead of a 500.

Import errors usually mean the virtualenv is inactive or you installed packages in another snapshot. For Postgres failures, confirm Docker and the rivermouth_NN database name.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or .venv

Try this

Try a short password and a duplicate email.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works