Skip to content

GEO draft: prompt-shaped Express, Next.js and FastAPI quickstarts (JWT, org-scoped, resource-level) - #668

Draft
orweis wants to merge 2 commits into
masterfrom
geo/answer-ready-quickstarts-d1-d3
Draft

orweis wants to merge 2 commits into
masterfrom
geo/answer-ready-quickstarts-d1-d3

Conversation

@orweis

@orweis orweis commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Draft for Or / R&D review. Do not merge until reviewed. Part of the GEO/AEO docs answer-ready pass (plan: Action 1, geo-aeo-plan-2026-10-05). Opened by Content Bot on behalf of Or Weis.

Pages (URLs, slugs and sidebar labels unchanged; only frontmatter title and description change)

  • quick-start/express: "Add role-based authorization to an Express API with JWT (Node.js)". Answer block, facts table, new section 6 (JWT authenticate middleware, authorize(), /api/posts routes, per-post Author role via a resource instance, signed-token test), FAQ including an honest "use an in-process library such as CASL when..." answer.
  • quick-start/nextjs: "Add organization-scoped authorization to a Next.js App Router app". Answer block, facts table, new section 6 (verified session helper with jose, tenant per organization, create and update route handlers with tenant: orgId, Server Actions note), FAQ.
  • quick-start/fastapi: "Add RBAC and resource-level permissions to a FastAPI app". Answer block, facts table, new section 6 (PyJWT dependency, require() dependency, routes returning plain dicts, resource-level Author role), FAQ.

Verification

  • Express (permitio 2.7.6, jsonwebtoken 9): the code blocks in the doc were assembled and run against a mock PDP and API. Results: create 201, update by non-author 403, update by author 200, missing token 401, bad token 401.
  • FastAPI (permit 3.0.0 on Python 3.13, PyJWT): same sequence passed with the doc blocks.
  • Next.js 15.5 App Router: the doc blocks (with the @/ alias) pass next build with TypeScript 6.
  • None of this ran against a live Permit environment.

Pricing facts and re-check

Free-tier values are copied from the live https://www.permit.io/pricing page (Community column of Compare Plans, labeled "Free Forever"), fetched 2026-10-05:
MAU 1000, Tenants 20, Authorization Queries No Limit, Environments 3, PDP Instances No Limit (also in the pages that say so: Roles 25, Resource Types 50, Logs Retention 14 days).

  • TODO (reviewer): re-open the pricing page before merging and confirm these values still match. Each page has an MDX comment {/* GEO pass: ... */} next to the table naming the source and fetch date.

R&D, please double check

  • Conflict risk: open PR Update the Python SDK docs for permit 3.0 and 3.1 #662 also edits quick-start/fastapi.mdx and django.mdx (Python 3.x updates and a pydantic fix). My changes are the frontmatter, a block after the imports, and a new section before Next steps.
  • permit 3.0.0 requires Python 3.10 or later (PyPI). The existing page still says "Python 3". Update the Python SDK docs for permit 3.0 and 3.1 #662 lists Python 3.1.0 in sdk/sdks-overview.mdx, but PyPI has only 3.0.0 and master's overview says 2.8.3. Please reconcile.
  • Policy assumptions to confirm in a live environment: the blogging-platform template has top-level Admin (Post create/update/delete/read) and Author (create/read), and a Post#Author instance role with update/read/create/delete. Instance checks also evaluate top-level roles (stated in the ReBAC docs). The new text tells readers to clear delete on the instance Author role if they want admin-only delete. Please confirm the UI wording.
  • The JWT sub must equal the Permit user key (the tutorials use the email address). The Next.js example reads an org_id claim, which is an assumption about the identity provider, and says so.
  • CASL fit statement is editorial.

Style and checks

  • No em or en dashes, no curly quotes, no filler words in added text. Answer-first blocks are 40 to 70 words (counted).
  • Existing technical content and existing code samples are unchanged. New content is added under the answer block, in new sections, or before the Next steps section.
  • npm run build (redirect-lint, relative links, private paths, Docusaurus build, hyperlink anchors, routes check, sidebar coverage) passed on a temporary branch with all six GEO branches merged.
  • Fit statements ("use X when / don't use X when") are editorial. Please confirm they are acceptable.

@netlify

netlify Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for permitio-docs ready!

Name Link
🔨 Latest commit e7adb66
🔍 Latest deploy log https://app.netlify.com/projects/permitio-docs/deploys/6ac2cd6b9f966b000862e369
😎 Deploy Preview https://deploy-preview-668--permitio-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant