CoachnestCoachnest
Sign InGet Started
Back to course

Mastering CRUD: Build Full-Stack Database Applications

…
—
Contents
1

What Is CRUD and Why It Matters

Reading12mFree
2

CRUD, REST, and HTTP Verbs

Reading14mFree
3

The Data Lifecycle of a Record

Reading11m
4

Course Project Tour: TaskFlow

Video9m
5

Chapter 1 — Quiz

Quiz8m
6

Tables, Rows, Columns & Types

Reading14m
7

Primary Keys & IDs (Auto-increment vs UUID)

Reading13m
8

Relationships: One-to-Many & Many-to-Many

Reading16m
9

Normalization & Schema Design Principles

Reading14m
10

Modeling TaskFlow with Prisma

Reading13m
11

Chapter 2 — Quiz

Quiz8m
12

INSERT — Creating Rows

Reading13m
13

SELECT — Reading & Filtering

Reading16m
14

UPDATE — Changing Rows Safely

Reading12m
15

DELETE — Removing Rows

Reading11m
16

Live SQL: A Full CRUD Session

Video15m
17

Chapter 3 — Quiz

Quiz9m
18

REST API Design for CRUD Resources

Reading14m
19

HTTP Status Codes That Tell the Truth

Reading12m
20

Scaffolding the API (Express & Next.js)

Reading16m
21

Connecting an ORM (Prisma) to Your Routes

Reading13m
22

Chapter 4 — Quiz

Quiz8m
23

Building the Create Endpoint End-to-End

Reading15m
24

Reading a Single Resource

Reading11m
25

Listing Collections

Reading13m
26

Live Coding: Create & Read

Video16m
27

Chapter 5 — Quiz

Quiz8m
28

PUT vs PATCH: Full vs Partial Updates

Reading13m

Authorization: Who Can Change This Row?

Reading12m
30

Soft Delete, Hard Delete & Restore

Reading14m
31

Idempotency & Concurrency Control

Reading13m
32

Chapter 6 — Quiz

Quiz9m
33

Input Validation with Zod

Reading14m
34

Mass Assignment & Over-Posting

Reading11m
35

SQL Injection & Safe Queries

Reading13m
36

Consistent Error Handling

Reading12m
37

Chapter 7 — Quiz

Quiz9m
38

Offset vs Cursor Pagination

Reading15m
39

Filtering & Dynamic WHERE Clauses

Reading13m
40

Safe Sorting & Full-Text Search

Reading14m
41

Indexing for Fast Reads

Reading13m
42

Chapter 8 — Quiz

Quiz9m
43

Forms & Creating Records from the UI

Reading14m
44

Fetching & Displaying Data

Reading13m
45

Optimistic Updates & Deletes

Reading14m
46

Building the TaskFlow UI

Video17m
47

Chapter 9 — Quiz

Quiz8m
48

Transactions & Data Integrity

Reading15m
49

Testing Your CRUD Endpoints

Reading14m
50

Caching, N+1 & Performance

Reading13m
51

Deploying & Migrating Safely

Reading14m
52

Chapter 10 — Final Quiz

Quiz10m
←→navigate lessons
Chapter 6 of 10·Chapter 6 — Update & Delete in Practice
Lesson 29 of 52Reading12 min

Authorization: Who Can Change This Row?

Authorization: Who Can Change This Row?¶

Validation asks "is the data well-formed?" Authorization asks "is this user allowed to do this to this row?" Update and Delete are where it bites hardest.

The Broken Access Control Trap¶

ts
2 lines
1// ❌ Anyone who knows the id can edit any task
2await prisma.task.update({ where: { id }, data });

Knowing /tasks/42 exists is trivial. Without an ownership check, any logged-in user can edit anyone's data. This is IDOR (Insecure Direct Object Reference) — one of the most common real-world API bugs.

Check Ownership Before Mutating¶

ts
5 lines
1const task = await prisma.task.findUnique({ where: { id } });
2if (!task || task.ownerId !== session.userId) {
3  return notFound(); // 404 hides existence; 403 also valid
4}
5// safe to update/delete

Do It in One Query (Scoped Mutation)¶

Even better, fold the ownership check into the write so there's no gap:

ts
5 lines
1const result = await prisma.task.updateMany({
2  where: { id, ownerId: session.userId },
3  data,
4});
5if (result.count === 0) return notFound();

updateMany/deleteMany with an ownerId filter changes the row only if it belongs to the caller, and tells you whether anything matched.

Roles & Policies¶

Beyond ownership, real apps add roles:

ts
4 lines
1const canEdit =
2  task.ownerId === session.userId ||
3  session.role === "ADMIN";
4if (!canEdit) return forbidden();

Centralize these rules in a can(user, action, resource) helper so authorization logic isn't scattered and inconsistent across endpoints.

Previous

PUT vs PATCH: Full vs Partial Updates

Next

Soft Delete, Hard Delete & Restore

Use ← → arrow keys to navigate between lessons