Part 6 of this project

Registration

Validate customer accounts and store password hashes.

Goal

This snapshot advances Stonequay Market by teaching you to validate customer accounts and store password hashes.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use PHP 8.2+, Composer, Node.js 20+, and Docker for MySQL stages.

Port 8005 must be free. Copy .env.example before database stages.

  • PHP and Composer
  • Node.js and npm
  • Docker from part 4 onward

Concepts

Registration normalizes email, enforces uniqueness, hashes passwords, signs the user in, and regenerates the session.

Twig escapes output by default; Tailwind styles the storefront; Doctrine owns persistence and voters enforce ownership.

Walkthrough

Build a registration form with CSRF-safe posts and validation errors.

Read the example, then open the matching snapshot. The repository includes validation, CSRF, and the surrounding structure.

$user->setPassword($hasher->hashPassword($user, $plain));
$em->persist($user); $em->flush();
return $this->redirectToRoute('home');

Run and verify

Enter 06-Registration, composer install, copy .env, migrate, seed, build assets, and serve on port 8005.

Open http://127.0.0.1:8005. From data lessons onward, Ada and Grace use password123.

docker compose up -d
git clone https://github.com/michaeldunga1/fcc-symfony-ecommerce.git
cd fcc-symfony-ecommerce/06-Registration
composer install
npm install
cp .env.example .env
php bin/console doctrine:migrations:migrate -n
php bin/console app:seed
npm run build
symfony server:start --port=8005 --no-tls
# or: php -S 0.0.0.0:8005 -t public

Troubleshooting

Duplicate email and password confirmation failures should redisplay field errors.

For database failures, confirm Docker and the stone_NN name. Never commit .env, vendor, or node_modules.

  • Read the first exception first
  • Rebuild assets after Tailwind class changes
  • Never commit secrets

Try this

Try a short password, mismatched confirmation, and a duplicate email.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works