Part 7 of this project

Login and Sessions

Authenticate with Remix cookie session storage.

Goal

This snapshot advances Tidepool Notes by teaching you to authenticate with Remix cookie session storage.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Node.js 20+, npm, and a terminal. You should recognize React components, TypeScript modules, and HTTP verbs.

Port 3004 must be free. Copy .env.example before starting database stages.

  • Node.js and npm
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Remix createCookieSessionStorage signs an httpOnly cookie with SESSION_SECRET. You store only the user id and load the user per request.

Keep the server boundary visible: Remix loaders read trusted data on the server; actions must validate input and re-check authorization before mutations.

Walkthrough

Verify email/password, commit the session cookie, and destroy it on logout.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

session.set("userId", user.id)
return redirect("/", { headers: { "Set-Cookie": await commitSession(session) } })

Run and verify

Enter 07-Login-And-Sessions, install dependencies, copy .env.example when present, and start Remix on port 3004.

Open http://127.0.0.1:3004. Watch the terminal for validation and database errors.

docker compose -f ../docker-compose.yml up -d
git clone https://github.com/michaeldunga1/fcc-remix-blog.git
cd fcc-remix-blog/07-Login-And-Sessions
npm install
cp .env.example .env
npm run db:push
npm run db:seed
npm run dev

Troubleshooting

Changing SESSION_SECRET invalidates cookies. SESSION_HTTPS_ONLY must be true behind HTTPS in production.

Missing-module errors usually mean npm install ran in another snapshot. For Postgres failures, confirm Docker and the tidepool_NN database name.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or node_modules

Try this

Log in, restart Remix, confirm the session persists, then log out.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works