GEO draft: prompt-shaped Express, Next.js and FastAPI quickstarts (JWT, org-scoped, resource-level) - #668
Draft
orweis wants to merge 2 commits into
Draft
GEO draft: prompt-shaped Express, Next.js and FastAPI quickstarts (JWT, org-scoped, resource-level)#668orweis wants to merge 2 commits into
orweis wants to merge 2 commits into
Conversation
…s (JWT, org-scoped, resource-level)
✅ Deploy Preview for permitio-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft for Or / R&D review. Do not merge until reviewed. Part of the GEO/AEO docs answer-ready pass (plan: Action 1,
geo-aeo-plan-2026-10-05). Opened by Content Bot on behalf of Or Weis.Pages (URLs, slugs and sidebar labels unchanged; only frontmatter
titleanddescriptionchange)quick-start/express: "Add role-based authorization to an Express API with JWT (Node.js)". Answer block, facts table, new section 6 (JWTauthenticatemiddleware,authorize(),/api/postsroutes, per-post Author role via a resource instance, signed-token test), FAQ including an honest "use an in-process library such as CASL when..." answer.quick-start/nextjs: "Add organization-scoped authorization to a Next.js App Router app". Answer block, facts table, new section 6 (verified session helper withjose, tenant per organization, create and update route handlers withtenant: orgId, Server Actions note), FAQ.quick-start/fastapi: "Add RBAC and resource-level permissions to a FastAPI app". Answer block, facts table, new section 6 (PyJWT dependency,require()dependency, routes returning plain dicts, resource-level Author role), FAQ.Verification
permitio2.7.6,jsonwebtoken9): the code blocks in the doc were assembled and run against a mock PDP and API. Results: create201, update by non-author403, update by author200, missing token401, bad token401.permit3.0.0 on Python 3.13, PyJWT): same sequence passed with the doc blocks.@/alias) passnext buildwith TypeScript 6.Pricing facts and re-check
Free-tier values are copied from the live https://www.permit.io/pricing page (Community column of Compare Plans, labeled "Free Forever"), fetched 2026-10-05:
MAU 1000, Tenants 20, Authorization Queries No Limit, Environments 3, PDP Instances No Limit (also in the pages that say so: Roles 25, Resource Types 50, Logs Retention 14 days).
{/* GEO pass: ... */}next to the table naming the source and fetch date.R&D, please double check
quick-start/fastapi.mdxanddjango.mdx(Python 3.x updates and a pydantic fix). My changes are the frontmatter, a block after the imports, and a new section before Next steps.permit3.0.0 requires Python 3.10 or later (PyPI). The existing page still says "Python 3". Update the Python SDK docs for permit 3.0 and 3.1 #662 lists Python 3.1.0 insdk/sdks-overview.mdx, but PyPI has only 3.0.0 and master's overview says 2.8.3. Please reconcile.blogging-platformtemplate has top-level Admin (Post create/update/delete/read) and Author (create/read), and aPost#Authorinstance role with update/read/create/delete. Instance checks also evaluate top-level roles (stated in the ReBAC docs). The new text tells readers to clear delete on the instance Author role if they want admin-only delete. Please confirm the UI wording.submust equal the Permit user key (the tutorials use the email address). The Next.js example reads anorg_idclaim, which is an assumption about the identity provider, and says so.Style and checks
npm run build(redirect-lint, relative links, private paths, Docusaurus build, hyperlink anchors, routes check, sidebar coverage) passed on a temporary branch with all six GEO branches merged.