next js.md

Travel operators: vendor portal using Next.js

Summary

A vendor portal blueprint for travel operators built with Next.js on Ample. Domain schema: listings (reference, destination, departure_dates, price_from, publishing_status, agency_id): trips as listings with publishing status; agencies (name, license_number, region): operators or branches; suppliers (name, type, agency_id, status): hotels and transport suppliers; reports (agency_id, period, object_key, generated_at): branch sales reports; document_access (document_id, principal_reference, role, granted_at): who may read which document. Public information: published trips and departure dates, destination guides, booking conditions. Kept out of scope until handling is reviewed: traveler passports and identity, payment details, supplier contracts. Passport and payment data are regulated; only published trips and branch reporting are modeled. Technical basis verified on Next.js: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Model the travel operators domain. Create the tables listings, agencies, suppliers, reports, document_access. Trips as listings with publishing status lives in listings; keep the sensitive classes (traveler passports and identity, payment details, supplier contracts) out of this schema.
  2. Workflow step 1. Model vendors scoped to the agency with roles
  3. Workflow step 2. Authorize document access by vendor and role (401, 403 negative tests)
  4. Workflow step 3. Store vendor documents in the private bucket
  5. Workflow step 4. Deploy and verify the negative tests and an authorized download
  6. Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
  7. Verify. Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the travel operators workflow.

Tested examples

Success checks

Limitations

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Verification evidence

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f, binding state current, required scopes: servers:write, databases:read, buckets:read.

Input schema

{
  "additionalProperties": false,
  "properties": {
    "env": {
      "description": "Encrypted environment variables",
      "items": {
        "pattern": "^[A-Z][A-Z0-9_]*=.*$",
        "type": "string"
      },
      "maxItems": 50,
      "type": "array"
    },
    "name": {
      "description": "App name",
      "maxLength": 63,
      "minLength": 1,
      "pattern": "^[a-z0-9-]+$",
      "type": "string"
    },
    "path": {
      "description": "Project directory or ample.toml service",
      "maxLength": 512,
      "minLength": 1,
      "type": "string"
    },
    "release_command": {
      "description": "Migration command run before activation",
      "maxLength": 512,
      "type": "string"
    }
  },
  "required": [
    "env",
    "name",
    "path"
  ],
  "type": "object"
}

Next actions

Actions describe possible next steps. They are typed data, not commands, and grant no permission.