Case study 02 ยท Full-stack product
Secure Data Room
An independent MVP for sharing due-diligence PDFs with deliberate, read-only access. The browser is not the authorization authority: NestJS resolves owner, recipient, and public-token permissions before application data is returned.
Problem
Sharing a file is easy. Sharing exactly the intended scope is not.
The product needed a reviewer flow for private documents: organize PDFs, share only a room, folder, or file, let the recipient review that scope, and revoke access from the same place.
The difficult part is not the file picker. It is preserving a clear authority boundary across authentication, nested content, public links, recipient access, storage, and revocation.
Constraints
The MVP had to stay complete without pretending to be an enterprise compliance product.
- Private by default; sharing happens only through an explicit action.
- Public sharing is read-only and scoped to the selected subtree.
- The storage bucket remains private; object keys are random identifiers rather than user filenames.
- Public-link secrets are random values stored only as SHA-256 digests.
- Revocation blocks new access, while an already issued signed PDF URL has a disclosed residual TTL of up to 60 seconds.
- Search and file versioning are intentionally excluded from the MVP.
- The project explicitly does not claim malware scanning, immutable audit logging, enterprise identity, or compliance certification.
Decisions
Keep policy on the server and storage narrowly delegated.
Evidence
The flow is inspectable from UI to policy to deployment.
Outcome
A small end-to-end system with explicit trust boundaries.
The MVP covers authentication, nested folders, multi-file upload, inline PDF review, public-link and recipient sharing, revoke, failure states, and responsive access. More important than the feature count is that each path has an explicit authority boundary and a documented limit.