#FE: Account screens (from backend Phase 3)
Frontend spec for backend Phase 3: Account (requirements complete 2026-10-01, not built). V8 requirement Reached from the user menu, not the sidebar. All routes are logged-in only and not organization-scoped.
i18n namespace: account.*.
#A. Profile
| # | Feature | Screen / control | Rules from backend doc | Frontend notes |
|---|---|---|---|---|
| 3.1 | View profile | Profile page header + form | User details + organizations list | Organizations list links to the switcher |
| 3.2 | Update profile | Form: name, details, onboarding answers (one endpoint) | One endpoint | One Save button, dirty-state guard |
| 3.3 | Change email | Dialog: new email + current password | Confirm link to the new email. Notice to the old email | After submit: "Check |
| 3.4 | Change password | Dialog: current + new + confirm | Logs out other devices | Success toast says so. This device stays logged in |
| 3.5 | Email preferences | 3 switches: account updates, credentials, informative | On/off | Optimistic toggle, revert on error |
| 3.6 | Delete protection | Switch | Central checks it before sending any delete to OSS | Explain the effect. Delete actions everywhere show "Delete protection is on" when blocked |
| 3.7 | Delete account | Danger zone dialog: password + type "DELETE" Assumption | Password required. Negative balance must be paid first. "Servers removed first" check is added in the Servers phase | Show the backend refusal reason (balance / servers) with a link to fix it |
#B. Security
| # | Feature | Screen / control | Rules | Frontend notes |
|---|---|---|---|---|
| 3.8 | 2FA (email code) + backup codes | Switch + "View / regenerate / email backup codes" | Password required to turn off or view codes. Codes stored encrypted | Codes shown once in a dialog with copy/download. Regenerate warns that the old codes stop working |
| 3.9 | Google Authenticator | Setup dialog: QR + manual key + code field | Turns on only after one correct code | Two-step dialog. Off = switch + password Assumption |
| 3.10 | IP whitelist | Switch + list (IP, added) + add + delete | Turning on adds the current IP automatically | Warn: "Only these IPs can log in". Prevent deleting the current IP without a confirm Assumption |
| 3.11 | Login history | Paginated table: IP, browser, time | Paginated | Relative time + exact on hover |
| 3.12 | Account activity | Paginated list | Account activity only (login, password, 2FA, settings). Server/app activity from OSS. Organization activity in the Organizations phase | Different from the organization Audit log |
| 3.13 | API access | Switch only — no "create token" button | Simple on/off personal API token (same as V7). Existing V7 API tokens are migrated and keep working; users do not create new ones V8 requirement 2026-10-03 | Answered: the screen never issues a token, so no copy dialog is needed. Show the masked existing token (if the API returns one) with Copy; otherwise just the switch and one line: scripts using the old token keep working |
| 3.16 | Active sessions | Table: device/browser, IP, last used, "this device" badge | Log out one device or all other devices. New in V8 | Confirm dialogs. The current row can't be revoked from the list (use Log out) |
#C. Notifications
| # | Feature | Screen / control | Rules | Frontend notes |
|---|---|---|---|---|
| 3.14 | In-app notifications | Bell (unread badge) + /notifications list | Paginated, unread count, mark one / all read | Poll the unread count (no broadcasting in Phase 1) |
| 3.15 | Notification channels | /account/notifications: list + add/edit/delete + Send test | Email, Telegram, Pushover, Slack, Discord, Webhook V8 requirement 2026-10-03 | Per-type form fields: Telegram bot token + chat id, Pushover user/app key, Slack webhook URL, Discord webhook URL, Webhook: any URL (Central POSTs title + message as JSON, same as V7), email address (V7 fields as reference V7 only). The type picker drives which fields show; URL fields validated as https:// URLs. Secrets masked after save |
| 3.17 | Server alerts | Shown in the bell + sent to channels | Central calls the OSS API for alerts. Built with Servers | OSS has no alerts endpoint Missing. See Notifications |
#Not in this phase (backend doc)
Confirmation timer (ignored for now). Billing, referral/affiliate, support, AI assistant in their own phases. No account screens for them.
#Existing users
Profile, email preferences, delete protection, 2FA, Google Authenticator, IP whitelist, login history, notification channels and API tokens carry over from V7. The screens must handle pre-filled data (e.g. 2FA already on, existing IP list, existing Discord/Webhook channels, an API token that already exists) from the first load, and must never invalidate a migrated V7 API token. V8 requirement 2026-10-03