Exercise 2: An Author Page — Possible Solution ================================================ app.get("/authors/:email", async (req, res) => { const author = await prisma.user.findUnique({ where: { email: req.params.email }, select: { name: true, profile: { select: { bio: true } }, posts: { where: { published: true }, orderBy: { viewCount: "desc" }, take: 5, select: { title: true, slug: true, viewCount: true }, }, }, }); if (!author) return res.status(404).json({ error: "Author not found" }); res.json(author); }); Example response: { "name": "Alan", "profile": { "bio": "Codebreaker" }, "posts": [ { "title": "...", "slug": "...", "viewCount": 42 }, ... ] } Why the email stays private: The email is used to find the user (in where), but it isn't listed in select, so it isn't returned. select also bounds the posts list with take: 5 and returns only published posts, so drafts don't leak either. (In a real site you'd use a public username or ID in the URL rather than an email address, so the address doesn't appear in links or server logs at all.) WHY THIS WORKS AS AN ANSWER ------------------------------ It shows the difference between using a field to find a record and returning it, combines a one-to-one and a filtered, sorted, limited one-to-many select, and points out a real privacy improvement.