next js.md

Nonprofits: member portal using Next.js

Summary

A member portal blueprint for nonprofits built with Next.js on Ample. Domain schema: course_groups (program, cohort, start_at, end_at): programs and cohorts; memberships (course_group_id, participant_reference, role): participants, volunteers and staff; sessions (course_group_id, starts_at, title, location): program sessions and events; materials (course_group_id, title, object_key, visibility): program materials; document_access (document_id, principal_reference, role, granted_at): who may read which document. Public information: mission and programs, events, donation entry point. Kept out of scope until handling is reviewed: beneficiary identity and case notes, donor records. Beneficiary and donor data are sensitive; donations are handled by your payment provider and are not modeled here. Technical basis verified on Next.js: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Model the nonprofits domain. Create the tables course_groups, memberships, sessions, materials, document_access. Programs and cohorts lives in course_groups; keep the sensitive classes (beneficiary identity and case notes, donor records) out of this schema.

  2. Workflow step 1. Model groups, memberships and roles

  3. Workflow step 2. Authorize access to materials by membership and role (401, 403 negative tests)

  4. Workflow step 3. Store materials in the private bucket and stream them through the app

  5. Workflow step 4. Deploy and verify the negative tests and an authorized download

  6. Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.

    ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
    
  7. Verify. Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the nonprofits workflow.

    ample logs <deployment_id> --kind build
    

Tested examples

Success checks

Limitations