next js.md
Law firms: client portal using Next.js
Summary
A client portal blueprint for law firms built with Next.js on Ample. Domain schema: client_entities (name, entity_type, conflict_check_reference): clients with conflict-check status; matters (client_entity_id, practice_area, opened_at, closed_at, status): engagement periods as matters; document_requests (matter_id, title, due_at, status, uploaded_object_key): documents requested from the client; shared_documents (matter_id, title, object_key, authorized_role): documents released to authorized client contacts; document_access (document_id, principal_reference, role, granted_at): who may read which document. Public information: practice areas and attorney profiles, intake process and fee structure overview, office locations. Kept out of scope until handling is reviewed: privileged communications and case files, identity and financial documents, opposing-party information. Matter documents are privileged; the portal models per-matter authorization only. Professional-conduct and confidentiality obligations are not established here. Technical basis verified on Next.js: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
Prerequisites
- A Next.js project (next build then next start -H 0.0.0.0 -p $PORT on the node-22 template)
- A PostgreSQL driver reading DATABASE_URL (auto-provisioned when omitted)
- Bucket credentials from
ample bucket createpassed as encrypted S3_* environment variables - A review of which law firms data classes may be handled at all; this blueprint models public information only
Exact tested configuration
- template:
node-22 - runtime:
node - size:
s-1vcpu-1gb - install:
npm install - build:
npm run build --if-present - start:
npm run start
Steps
Model the law firms domain. Create the tables client_entities, matters, document_requests, shared_documents, document_access. Clients with conflict-check status lives in client_entities; keep the sensitive classes (privileged communications and case files, identity and financial documents, opposing-party information) out of this schema.
Workflow step 1. Model client entities and engagement periods; every document belongs to one engagement.
Workflow step 2. Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client).
Workflow step 3. Store documents in the private bucket and stream them through the app.
Workflow step 4. Deploy and verify the negative authorization tests and an authorized download.
Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...Verify. Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the law firms workflow.
ample logs <deployment_id> --kind build
Tested examples
- Next.js pattern fixture (tests/deploy-canaries/next-js-patterns): Verified private document library basis for this blueprint.
Success checks
- app responds on its public URL (
/on the live URL, expect ample canary next js patterns) - private-document-library self-test from the example (
/p/private-document-libraryon the live URL, expect see the pattern fixture checks)
Limitations
- The technical basis (private document library on Next.js) was verified with the pattern fixture; the law firms schema and workflow are an original design for this blueprint and were not executed as a separate application.
- No health, financial, privacy or other compliance claim is made. Matter documents are privileged; the portal models per-matter authorization only. Professional-conduct and confidentiality obligations are not established here.
- Public content and synthetic examples only until actual data-handling requirements have been reviewed.
- Verified on the node-22 template at s-1vcpu-1gb; region, request-duration limits and other sizes are unknown or unverified.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified.
- PutObject and GetObject with path-style addressing are verified; other S3 operations and CDN cache rules are not.