Yevgeniy Sorokin

Case study 02 ยท Full-stack product

Secure Data Room

An independent MVP for sharing due-diligence PDFs with deliberate, read-only access. The browser is not the authorization authority: NestJS resolves owner, recipient, and public-token permissions before application data is returned.

Problem

Sharing a file is easy. Sharing exactly the intended scope is not.

The product needed a reviewer flow for private documents: organize PDFs, share only a room, folder, or file, let the recipient review that scope, and revoke access from the same place.

The difficult part is not the file picker. It is preserving a clear authority boundary across authentication, nested content, public links, recipient access, storage, and revocation.

Constraints

The MVP had to stay complete without pretending to be an enterprise compliance product.

  • Private by default; sharing happens only through an explicit action.
  • Public sharing is read-only and scoped to the selected subtree.
  • The storage bucket remains private; object keys are random identifiers rather than user filenames.
  • Public-link secrets are random values stored only as SHA-256 digests.
  • Revocation blocks new access, while an already issued signed PDF URL has a disclosed residual TTL of up to 60 seconds.
  • Search and file versioning are intentionally excluded from the MVP.
  • The project explicitly does not claim malware scanning, immutable audit logging, enterprise identity, or compliance certification.

Decisions

Keep policy on the server and storage narrowly delegated.

NestJS as application authorityAuthorization decisions and application reads/mutations pass through backend policy checks rather than trusting UI state.
PostgreSQL + PrismaApplication tables use one relational source of truth; Prisma is the application-table access path.
Private storage + short-lived capabilitiesSupabase Storage remains private. The browser receives narrowly scoped signed upload/read capabilities instead of broad storage authority.
Hierarchy-aware sharingA Share targets a room root, folder, or file. Server-side subtree resolution defines the readable scope.
Bounded scale choicesRecursive CTEs calculate subtree impact, and large rooms list one parent at a time with keyset pagination instead of rendering the whole tree.

Evidence

The flow is inspectable from UI to policy to deployment.

Reviewer walkthroughProduct walkthrough on YouTube
VerificationThe repository exposes architecture checks, formatting, the consolidated verify gate, and Playwright production journeys. It also includes a deployment identity check for comparing the live Web and API commit identities.
The repository describes 11 deployed production journeys used for release certification. The case study keeps that number tied to the repository's own release evidence rather than turning it into a generic quality claim.

Outcome

A small end-to-end system with explicit trust boundaries.

The MVP covers authentication, nested folders, multi-file upload, inline PDF review, public-link and recipient sharing, revoke, failure states, and responsive access. More important than the feature count is that each path has an explicit authority boundary and a documented limit.