V8 Central — Product & Technical Spec
  1. Docs
  2. Frontend spec (from backend doc)
  3. FE: Account screens (Phase 3)

#FE: Account screens (from backend Phase 3)

Frontend spec for backend Phase 3: Account (requirements complete 2026-10-01, not built). V8 requirement Reached from the user menu, not the sidebar. All routes are logged-in only and not organization-scoped.

i18n namespace: account.*.

#A. Profile

#FeatureScreen / controlRules from backend docFrontend notes
3.1View profileProfile page header + formUser details + organizations listOrganizations list links to the switcher
3.2Update profileForm: name, details, onboarding answers (one endpoint)One endpointOne Save button, dirty-state guard
3.3Change emailDialog: new email + current passwordConfirm link to the new email. Notice to the old emailAfter submit: "Check to confirm". Email shows "pending: x" until confirmed Assumption
3.4Change passwordDialog: current + new + confirmLogs out other devicesSuccess toast says so. This device stays logged in
3.5Email preferences3 switches: account updates, credentials, informativeOn/offOptimistic toggle, revert on error
3.6Delete protectionSwitchCentral checks it before sending any delete to OSSExplain the effect. Delete actions everywhere show "Delete protection is on" when blocked
3.7Delete accountDanger zone dialog: password + type "DELETE" AssumptionPassword required. Negative balance must be paid first. "Servers removed first" check is added in the Servers phaseShow the backend refusal reason (balance / servers) with a link to fix it

#B. Security

#FeatureScreen / controlRulesFrontend notes
3.82FA (email code) + backup codesSwitch + "View / regenerate / email backup codes"Password required to turn off or view codes. Codes stored encryptedCodes shown once in a dialog with copy/download. Regenerate warns that the old codes stop working
3.9Google AuthenticatorSetup dialog: QR + manual key + code fieldTurns on only after one correct codeTwo-step dialog. Off = switch + password Assumption
3.10IP whitelistSwitch + list (IP, added) + add + deleteTurning on adds the current IP automaticallyWarn: "Only these IPs can log in". Prevent deleting the current IP without a confirm Assumption
3.11Login historyPaginated table: IP, browser, timePaginatedRelative time + exact on hover
3.12Account activityPaginated listAccount activity only (login, password, 2FA, settings). Server/app activity from OSS. Organization activity in the Organizations phaseDifferent from the organization Audit log
3.13API accessSwitch only — no "create token" buttonSimple on/off personal API token (same as V7). Existing V7 API tokens are migrated and keep working; users do not create new ones V8 requirement 2026-10-03Answered: the screen never issues a token, so no copy dialog is needed. Show the masked existing token (if the API returns one) with Copy; otherwise just the switch and one line: scripts using the old token keep working
3.16Active sessionsTable: device/browser, IP, last used, "this device" badgeLog out one device or all other devices. New in V8Confirm dialogs. The current row can't be revoked from the list (use Log out)

#C. Notifications

#FeatureScreen / controlRulesFrontend notes
3.14In-app notificationsBell (unread badge) + /notifications listPaginated, unread count, mark one / all readPoll the unread count (no broadcasting in Phase 1)
3.15Notification channels/account/notifications: list + add/edit/delete + Send testEmail, Telegram, Pushover, Slack, Discord, Webhook V8 requirement 2026-10-03Per-type form fields: Telegram bot token + chat id, Pushover user/app key, Slack webhook URL, Discord webhook URL, Webhook: any URL (Central POSTs title + message as JSON, same as V7), email address (V7 fields as reference V7 only). The type picker drives which fields show; URL fields validated as https:// URLs. Secrets masked after save
3.17Server alertsShown in the bell + sent to channelsCentral calls the OSS API for alerts. Built with ServersOSS has no alerts endpoint Missing. See Notifications

#Not in this phase (backend doc)

Confirmation timer (ignored for now). Billing, referral/affiliate, support, AI assistant in their own phases. No account screens for them.

#Existing users

Profile, email preferences, delete protection, 2FA, Google Authenticator, IP whitelist, login history, notification channels and API tokens carry over from V7. The screens must handle pre-filled data (e.g. 2FA already on, existing IP list, existing Discord/Webhook channels, an API token that already exists) from the first load, and must never invalidate a migrated V7 API token. V8 requirement 2026-10-03

ServerAvatar V8 Central · prepared by central-app-2 (Pair 2 frontend) for Bhavik Jethwa · nothing in this spec is implemented yet · Built 2026-10-03 12:35 UTC