take two.

Free course · Registered members · Lesson 4 / 10

Design data, articles and public access

Connect the MySQL schema, PDO queries and visibility rules before building the editorial area.

30 minutes including practiceAll courses

Editorial team: Take Two · Published

Lesson preview

Essential data

users stores email, password hash and role. posts stores title, text, status, author and version; events add a source URL, fingerprint, dates and unique key. import_runs records job results and mode. rate_limits holds temporary counters. Status is draft or published; the mere presence of a date is not permission to display an article.

One rule on every public path

The listing, detail page and public search must all filter status=published. A homepage-only check does not protect /post?id=... and /search. The project returns 404 for visitor requests for drafts, without exposing their title or body. Editorial routes are separate and check the role. A member can access an account, but that does not automatically grant access to drafts.

What to check as you practise

  • Author foreign key present.
  • Drafts absent from public HTML and JSON.
  • Parameterised queries and escaped output.

Continue with the full lesson

Register free to access the complete explanation, examples, exercise and commented answer. This preview stays open to everyone.

Workshop files · Version 1

The reference project

Download the complete blog, English and Italian instructions, SQL schema, agent contracts, fictional fixtures and tests. The sample blog interface is in English. This is a local learning project: password recovery, email verification and MFA remain extensions before opening it to a public community.

Download the blog project (ZIP) →

Free download. Full lessons require a free Take Two account. Codex access depends on your own plan.

Sources and further reading