Start here · Explore the projects · Try the playground · Cedarling docs
Learn to turn business rules into authorization policies with Cedarling. Explore fifteen runnable Node.js applications, most with React interfaces: task boards, AI assistants, shared documents, file sharing, and more.
Each project gives you a working application, sample users or workloads, an exercise, and tests. Start with P1 to learn the core pattern, or choose an application that matches what you build. The projects run independently; you do not need to complete them in order.
Note
This checkout contains the tutorial starting applications. Marked authorization
checks currently return FAKE ALLOW; the tutorials replace them with Cedarling
decisions. Use these applications locally with sample data, not as production
deployments.
P1 is a small React task board backed by a Node.js API. It introduces a practical question: who can read or change a task?
With Git and Docker Desktop, or Docker Engine with Compose, installed:
git clone https://github.com/GluuFederation/cedarling-tutorials.git
cd cedarling-tutorials/p1-task-manager
docker compose up --buildOpen http://localhost:17001. The stack starts both the application and its identity provider; you do not need to configure hostnames or install Node.js on your computer for this Docker quick start.
- Sign in as Mina, the tenant owner, and explore the task board.
- Compare access with Alex, a contributor, and Sam, a user from another tenant.
- Follow P1's Exercise to identify the rules that Cedarling will enforce.
To stop, press Ctrl+C, then run docker compose down in the same directory.
This keeps the project's stored data for your next session.
Prefer working directly with Node.js? Follow P1's native instructions.
Choose a familiar application, then explore the authorization problem behind it. Each project title opens its own setup guide, architecture, exercise, and commands. The publication column will link to the written tutorial when it is published on Cedarling.dev.
| Project | Stack | What you'll learn | Publication |
|---|---|---|---|
| P1 - Protecting a Node.js REST API with Cedarling | Node.js, Fastify, React, SQLite | Keep tenants' tasks separate and control who can read or change them. | Not published |
| P2 - Preventing Cross-Tenant RAG Data Leaks with Cedarling | Node.js, Fastify, Orama, Voyage, OpenRouter | Check access to search results before documents reach AI generation. | Not published |
| P3 - Authorizing MCP Incident Operations with Cedarling | Node.js, MCP, Express, OpenRouter | Control an assistant's access to incident tools, runbooks, and triage prompts. | Not published |
| P4 - Securing Editorial Publishing with Cedarling | Node.js, Next.js App Router, React, SQLite | Tie publishing approval to the reviewed revision and current reviewer authority. | Not published |
| P5 - Protecting Sensitive Fields and Data Exports with Cedarling | Node.js, Hono, React, SQLite | Protect individual records, sensitive fields, aggregates, and data exports. | Not published |
| P6 - Reauthorizing Offline Field Inspections with Cedarling | Node.js, Fastify, React, SQLite, IndexedDB | Check current assignments before accepting work saved while offline. | Not published |
| P7 - Securing Real-Time Collaborative Documents with Cedarling | Node.js, Fastify, React, SQLite, SSE | Apply changing permissions to document edits, comments, sharing, and live updates. | Not published |
| P8 - Securing File Sharing and Blocking Path Traversal with Cedarling | Node.js, Express, React, SQLite | Combine file-access decisions with application-owned filesystem safeguards. | Not published |
| P9 - Securing Realtime Chat Rooms and Events with Cedarling | Node.js, Express, Socket.IO, React, SQLite | Recheck access when people join, reconnect, receive messages, or moderate a room. | Not published |
| P10 - Authorizing Warehouse Workloads with Cedarling | Node.js, Fastify, React, SQLite, OAuth Client Credentials | Authorize machine-to-machine transfers using warehouse relationships and current state. | Not published |
| P11 - Securing Active-Tenant Switching in a SaaS Workspace with Cedarling | Node.js, React Router Framework Mode, Express, PostgreSQL | Reevaluate access as users switch tenants, accept invitations, or receive support access. | Not published |
| P12 - Governing Employee Record Access with Cedarling | Node.js, Express, React, SQLite | Grant and revoke employee-record access while separating requesters from approvers. | Not published |
| P13 - Protecting Grade Publication and Guardian Access with Cedarling | Node.js, Express, React, SQLite | Separate grade editing, publication, student access, and guardian access. | Not published |
| P14 - Governing an AI Scheduling Assistant with Cedarling | Node.js, Fastify, React, SQLite | Authorize each scheduling action an assistant proposes before it changes anything. | Not published |
| P15 - Authorizing a Multi-Party Marketplace Refund with Cedarling | Node.js, Express, React, SQLite | Give buyers, sellers, support, and fraud reviewers the right views and refund actions. | Not published |
All fifteen projects include a Compose stack. Read the chosen project's
Prerequisites, enter its directory, then run docker compose up --build.
P2 needs Voyage and OpenRouter credentials. P3's interactive chat runs in a
host terminal and needs Node.js, pnpm, and an OpenRouter key even when its
services run in Docker.
Use Node.js 24.21 or newer within 24.x and pnpm 10. Follow the project's Run section for dependency installation, setup, and startup. P11 also needs PostgreSQL: use the Compose-managed default or your own local database.
Each project generates its private application configuration in .env and its
identity-provider configuration in .local/idp/.env. Some development commands
start both processes; others use a separate identity-provider terminal.
The same localhost addresses work in native and Docker mode. Project PN
uses application port 17000 + N and identity-provider port 18000 + N:
P1 uses 17001 / 18001, and P15 uses 17015 / 18015.
Each project README gives its exact URL; P3 exposes an MCP service rather than a web interface.
You can run different projects together. Stop a project's Docker stack before running that same project natively. Each project runs its own identity provider from shared source code, with separate registrations and cookie names.
These stacks assume a trusted local machine. Ports do not isolate browser cookies, and a project's Docker application services share its IdP's network namespace. Never commit generated credentials or local data.
Each pN-project-name/ directory owns its source, dependencies, lockfile,
configuration, and tests. Shared identity-provider code lives in
shared/identity-provider/. Install dependencies
inside the package you are working on; there is no root pnpm workspace.
From that package directory:
pnpm install --frozen-lockfile
pnpm check
pnpm audit --audit-level lowpnpm check runs the package's quality checks. Also run pnpm test:e2e when
listed separately in the project's Verify section.
- Cedarling Playground — experiment in your browser.
- Cedarling Learn — read the published learning material.
- Cedarling documentation — explore configuration and reference guides.
- Cedarling source — explore the engine behind the tutorials.
