page:guides:react router:private file access

Enforce private-file authorization for React Router

Summary

Private file access for a React Router app on Ample. Verified on React Router: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: react-router build then react-router-serve on the node-22 template.

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute

    • Status: verified
    • Summary: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres

    • Status: verified
    • Summary: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage

    • Status: verified
    • Summary: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.

Prerequisites

Tested Configuration

Workflow Steps

  1. Build and start

    • Body: react-router build then react-router-serve on the node-22 template; the server must bind 0.0.0.0 on PORT.
  2. Create the bucket and pass its credentials

    • Body: Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.
    • Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  3. Authorize before touching storage

    • Body: Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.
  4. Verify

    • Body: Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.
    • Command: ample logs --kind build

Examples

Success Checks

  1. App responds on its public URL

    • Kind: http_get
    • Path: /
    • Expect: ample canary react router patterns
  2. Private-document-library check from the example

    • Kind: http_get
    • Path: /p/private-document-library
    • Expect: see the pattern fixture checks.

Limitations

Cost Estimate

Evidence Summary

Last Verified At

2026-09-20T03:31:44Z

Unknowns

Formats

Next Actions

  1. Action ID: browse-catalog

    • Label: Browse the catalog index
    • Operation ID: catalog_index
    • Method: GET
    • Relative Path: /v1/catalog
    • Requires Authentication: false
    • Requires Approval: false
  2. Action ID: search-recipes

    • Label: Search published recipes by intent, stack and constraints.
    • Operation ID: search_recipes
    • Method: POST
    • Relative Path: /v1/catalog/search
    • Parameters: {"body":{"limit":5,"query":"Enforce private-file authorization for React Router"}}
    • Requires Authentication: false
    • Requires Approval: false
  3. Action ID: plan:page:guides:react-router:private-file-access

    • Label: Prepare a side-effect-free deployment plan for an authorized project
    • Operation ID: plan_deployment
    • Method: POST
    • Relative Path: /v1/catalog/plan
    • Parameters: {"body":{"inputs":{},"projectId":"","recipeId":"page:guides:react-router:private-file-access","recipeRevision":"r1"}}
    • Requires Authentication: true
    • Requires Approval: false
  4. Action ID: auth-setup

    • Label: Read the existing agent authentication setup
    • Operation ID: existing_auth_setup
    • Method: GET
    • Relative Path: /mcp/setup
    • Requires Authentication: false
    • Requires Approval: false
  5. Action ID: browse:stack:framework-react-router

    • Label: Browse React Router
    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/stack%3Aframework-react-router
    • Parameters: {"nodeId":"stack:framework-react-router"}
    • Requires Authentication: false
    • Requires Approval: false
  6. Action ID: browse:intent:connect-app-to-storage

    • Label: Browse Connect app to storage
    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/intent%3Aconnect-app-to-storage
    • Parameters: {"nodeId":"intent:connect-app-to-storage"}
    • Requires Authentication: false
    • Requires Approval: false
  7. Action ID: browse:pattern:private-document-library

    • Label: Browse Private document library
    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/pattern%3Aprivate-document-library
    • Parameters: {"nodeId":"pattern:private-document-library"}
    • Requires Authentication: false
    • Requires Approval: false