This was one of my first projects at Zone01 Oujda. With a team of 4, we built a web forum where users can register, write posts in categories, comment, and like or dislike posts.
The rules were strict:
- Backend in Go, using only the standard library (plus
sqlite3,bcryptanduuid) - Database: SQLite
- No frontend frameworks, only HTML, CSS and vanilla JavaScript
- The app must run in Docker
At that time we were just starting out, so almost everything was new to us. Here are the main things I learned.
1. You don't need a framework for routing
Since Go 1.22, net/http supports HTTP methods and path parameters in routes:
http.HandleFunc("POST /login", handlers.Login)
http.HandleFunc("/post/{id}", handlers.GetPost)
Inside the handler, r.PathValue("id") gives you the id. For a small project, this was all we needed.
2. Sessions and cookies are simpler than they look
When a user logs in, we create a random token, save it in a sessions table, and send it to the browser in a cookie:
-
HttpOnly, so JavaScript can't read it - An expiration date of 1 hour
The subject also asked for one session per user. Instead of checking this in Go, we let SQLite handle it with a trigger:
CREATE TRIGGER one_session_per_user
BEFORE INSERT ON sessions
FOR EACH ROW
BEGIN
DELETE FROM sessions WHERE user_id = NEW.user_id;
END;
If you log in on a new device, the old session is deleted automatically. This was the moment I understood that a database can do much more than store data.
3. Passwords are never stored as plain text
We hashed passwords with bcrypt before saving them. At login, bcrypt.CompareHashAndPassword checks the password against the hash. It's simple, but it was my first real lesson in web security.
4. Vanilla JavaScript can do a lot
Without React, we used fetch to:
- Like and dislike posts without reloading the page
- Add comments
- Load more posts when you scroll (infinite scroll)
It was more code, but it showed me exactly what frameworks do for you.
5. Docker basics
We used a multi-stage Dockerfile. The first stage compiles the Go program. The second stage is a small Alpine image that only contains the binary, the templates and the database. The final image is much smaller than one with the whole Go toolchain.
6. Working as a team of 4
We made 149 commits, many merges, and a few painful conflicts. The biggest lesson: agree on the folder structure and naming before writing code. We changed our structure halfway through, and it cost us time.
What I would do differently
- Write tests from the start. We tested everything by hand, and some bugs came back more than once.
- Keep error handling in one place. We repeated the same error code in many handlers.
Conclusion
Building a forum without frameworks was slow, but it taught me how the web really works: HTTP, cookies, sessions, SQL and the DOM. Now when I use a framework, I understand what it does for me.
The code is on GitHub: github.com/twlmed212/Forum
What was the first project that made you understand how the web works?
Top comments (0)