Worked case: protected enterprise training
Learn to: separate asynchronous ingestion from tenant-authorized playback.
Prerequisites: 07-mux-player, 12-case-portal
Asynchronous asset lifecycle
On a narrow screen, swipe the diagram horizontally to keep its labels readable.
Playback authorization boundary
On a narrow screen, swipe the diagram horizontally to keep its labels readable.
Scenario and stack synthesis
Proposed design: employees watch private training in a multi-tenant SaaS. React + Mux Player handles playback; NestJS checks session, tenant and enrollment; PostgreSQL stores asset state and entitlements. Managed media processing reduces operational work. An AWS pipeline is an alternative, but would require its own encoding, CDN access and telemetry design.
[S14] [S17] [S37]Upload and ready flow synthesis
The backend requests a direct upload URL. Upload completion leads to processing; an asset-ready event updates the catalog. Verify webhook authenticity, handle repeated events idempotently, and preserve processing/failed states. Keep media service credentials out of the browser.
[S37] [S38]Playback flow and expiration verified
The backend authorizes the requested asset before signing playback. The client receives only the necessary identifiers/tokens. Mux’s guidance says expiration must cover the viewing duration or later portions may become unplayable; a renewal policy must account for the client’s actual behavior.
[S17]Trade-off, failure and improvement synthesis
Managed delivery reduces infrastructure ownership but adds vendor coupling and usage costs. A signed URL is not DRM and can be shared while valid. For stricter rights requirements, add a verified DRM/device matrix. Improve access-denied UX and audit server authorization decisions without logging usable bearer tokens.
[S17] [S27] [S32]Check yourself: Can the frontend mint its own playback JWT safely?
No. It would need a signing secret or private key. A trusted backend must authorize the viewer and sign the constrained capability.