Free course · Registered members · Lesson 2 / 10
From a brief to development increments
Set scope, acceptance criteria and an order of work that makes failures traceable.
Editorial team: Take Two · Published
Lesson preview
Separate readers from editors
Visitors read and search published articles; registered members access their account; editors and admins write and publish. The project uses these roles to demonstrate server-side access control. Payments, attachments and comments are unnecessary for this first workflow. Record what is missing from version one: email verification, password recovery and MFA need another increment before a public community launch.
An order with explicit dependencies
Define schema and routes first. Then build public reading, authentication and permissions, article management, search and finally imports. If the event agent writes posts, it needs the field names and constraints first. UI work can use fixtures while the backend stabilises, provided the JSON contract is agreed. Do not assign two agents to rewrite the same controller.
What to check as you practise
- Authorisation precedes publication.
- Every increment has a concrete check.
- Schema changes pass through the coordinator.
Continue with the full lesson
Register free to access the complete explanation, examples, exercise and commented answer. This preview stays open to everyone.
Workshop files · Version 1
The reference project
Download the complete blog, English and Italian instructions, SQL schema, agent contracts, fictional fixtures and tests. The sample blog interface is in English. This is a local learning project: password recovery, email verification and MFA remain extensions before opening it to a public community.
Free download. Full lessons require a free Take Two account. Codex access depends on your own plan.
Sources and further reading
- OpenAI · Codex CLI: setup and first task ↗
- OpenAI · Project instructions with AGENTS.md ↗
- OpenAI · Subagents and coordination ↗
- OpenAI · Non-interactive mode and structured output ↗
- Bootstrap · Getting started ↗
- Bootstrap · JavaScript and jQuery ↗
- jQuery · Official downloads ↗
- PHP · Password hashing ↗
- PHP · PDO prepared statements ↗
- PHP · Session security ↗
- OWASP · CSRF prevention ↗
- Turismo Roma · Roma Live calendar ↗
- Turismo Roma · Crawl rules ↗