The problem
Most document editors hide things the easy way: the whole document is sent to your browser, and the parts you shouldn't see are covered up. Anyone who opens the developer tools can read them. Permissions are checked when you open the document, and rarely again.
Redacted asks for something harder. In a multi-tenant system where documents are shared between people with different clearance levels, the text you aren't cleared for should never reach your browser at all, even while several people edit the same document in real time. And when someone loses access, that should take effect before their next keystroke, not when they next reload the page.
How it works
Redacted is the live demo of RBAC-API, a multi-tenant access-control service. A NestJS API and a Hocuspocus collaboration server share one PostgreSQL database. Every tenant table has forced row-level security, and the API connects as a role that owns nothing, so a query that forgets its tenant filter still can't see another organization's rows.
Hiding is part of the document's structure. Each section of a briefing is its own collaborative document on the server; a member who isn't cleared for a section is never connected to it, and the API sends a redaction bar in its place. Words inside a sentence are classified with a formatting mark, and readers below that mark get a copy the server writes for their level.
Permission changes reach connections that are already open. Every change announces itself with a PostgreSQL notification inside its own transaction, and every server re-checks its live connections when it arrives.
“The black bars aren't a disguise laid over the text. The text itself never reaches your browser, and a test reads every network frame to prove it.”