page:blueprints:publishing:client portal:next js

Publishing: client portal using Next.js

A client portal blueprint for publishing built with Next.js on Ample. Domain schema:

Public information: title catalog and author pages, release schedules, rights and permissions contact. Kept out of scope until handling is reviewed: unreleased manuscripts, royalty statements, customer license keys. Manuscripts and royalty data are confidential; licensed files are authorized per customer workspace.

Technical basis verified on Next.js: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Representative Queries

Resource Requirements

Infrastructure Requirements

Prerequisites

Tested Configuration

Workflow Steps

  1. Model the publishing domain: Create the tables titles, editions, customer_workspaces, customer_assets, document_access. The catalog of titles lives in titles; keep the sensitive classes (unreleased manuscripts, royalty statements, customer license keys) out of this schema.

  2. Model client entities and engagement periods; every document belongs to one engagement.

  3. Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client).

  4. Store documents in the private bucket and stream them through the app.

  5. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.

    Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...

  6. Verify: Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the publishing workflow.

    Command: ample logs --kind build

Success Checks

Limitations