Free course · Registered members · Lesson 4 / 10
Design data, articles and public access
Connect the MySQL schema, PDO queries and visibility rules before building the editorial area.
Editorial team: Take Two · Published
Lesson preview
Essential data
users stores email, password hash and role. posts stores title, text, status, author and version; events add a source URL, fingerprint, dates and unique key. import_runs records job results and mode. rate_limits holds temporary counters. Status is draft or published; the mere presence of a date is not permission to display an article.
One rule on every public path
The listing, detail page and public search must all filter status=published. A homepage-only check does not protect /post?id=... and /search. The project returns 404 for visitor requests for drafts, without exposing their title or body. Editorial routes are separate and check the role. A member can access an account, but that does not automatically grant access to drafts.
What to check as you practise
- Author foreign key present.
- Drafts absent from public HTML and JSON.
- Parameterised queries and escaped output.
Continue with the full lesson
Register free to access the complete explanation, examples, exercise and commented answer. This preview stays open to everyone.
Workshop files · Version 1
The reference project
Download the complete blog, English and Italian instructions, SQL schema, agent contracts, fictional fixtures and tests. The sample blog interface is in English. This is a local learning project: password recovery, email verification and MFA remain extensions before opening it to a public community.
Free download. Full lessons require a free Take Two account. Codex access depends on your own plan.
Sources and further reading
- OpenAI · Codex CLI: setup and first task ↗
- OpenAI · Project instructions with AGENTS.md ↗
- OpenAI · Subagents and coordination ↗
- OpenAI · Non-interactive mode and structured output ↗
- Bootstrap · Getting started ↗
- Bootstrap · JavaScript and jQuery ↗
- jQuery · Official downloads ↗
- PHP · Password hashing ↗
- PHP · PDO prepared statements ↗
- PHP · Session security ↗
- OWASP · CSRF prevention ↗
- Turismo Roma · Roma Live calendar ↗
- Turismo Roma · Crawl rules ↗