V8 Central — Product & Technical Spec
  1. Docs
  2. Frontend spec (from backend doc)
  3. FE: Foundation (Phase 1)

#FE: Foundation (from backend Phase 1)

What the backend's Phase 1: Foundation Setup (prepared by Pair 1, flow defined 2026-10-01, not built) means for the frontend, and the frontend foundation that has to exist before any feature screen. V8 requirement

#Backend Phase 1 → frontend consequences

Backend stepBackend ruleFrontend consequence
1.1 MariaDBsv_central_2 for Pair 2None directly. Our base URL must stay sa-central-api-2 (each pair has its own database)
1.2 RedisCache, sessions, queue on RedisNone directly
1.3 HorizonQueues default, notifications, emailsEmails (verification, reset, invites, IP approval) are queued. Screens say "We've sent an email" right away and offer resend after a cooldown, not "sending…"
1.4 PassportAccess 15 d, refresh 30 d, personal token 6 months. Central issues the access + refresh token itself after all login checks pass (2.9), not through Passport's OAuth password flow; the exact method is decided in the backend's Phase 2 plan V8 requirement 2026-10-03Token handling (see D-1 below). The frontend is unaffected by how the token is made — it only needs the login/refresh response fields below. Personal token = "API access" (3.13); migrated V7 tokens keep working
1.5 TelescopeLocal onlyNever linked from the frontend
1.6 CORSOnly the configured frontend URL. api/* + oauth/*. Authorization header allowed. No wildcardsThe backend must list https://sa-central-2.167-233-229-184.nip.io. If we use the BFF (server-to-server), CORS only matters for any direct browser calls
1.7 Mail & loggingMAIL_MAILER=log in developmentIn development, emails go to the backend log. Testers need the backend team to share links from it
1.8 SecurityHTTPS URLs, secure cookies, trusted proxyThe frontend is served over HTTPS. Cookies Secure
1.9 Final checkProtected Passport route worksFirst frontend smoke test: call that route through the BFF
Not in phase"Next.js login flow (how the frontend gets and stores the Passport token): decided later"Decision D-1 is needed before frontend Phase 1

#D-1: Passport token in Next.js (frontend proposal for the backend team)

  • Tokens live only in httpOnly; Secure; SameSite=Lax cookies set by Next.js route handlers.
  • Server components and route handlers add Authorization: Bearer when calling sa-central-api-2.
  • On 401: one refresh (2.9) in the route handler, then retry once. If that fails, clear the cookies → login.
  • What the frontend needs from the backend: the login/refresh responses must return access_token, refresh_token, expires_in in the body (not only as cookies), plus a refresh endpoint that rotates and revokes (2.9).

#Frontend foundation (frontend Phase 0)

ItemDetailDependency status
i18nnext-intl, app/[locale], middleware (cookie → URL → Accept-Language), messages/{en,es,de,fr,pt,ja,ru,hi}.jsonnext-intl to be added (required by project rules)
App shellSidebar groups, top bar, mobile drawer, breadcrumbs, organization switcher slotshadcn primitives present
Themenext-themes, light/dark/systempresent
API layerlib/api/ axios instance (server side) + route handlers (BFF). Error normaliser, GET retry, abort, Accept-Languageaxios present
Formsreact-hook-form + zod resolversreact-hook-form to be added
TablesTanStack Table v8to be added
Statesloading.js / error.js / not-found.js per group, skeletons, empty-state component—
TestsVitest + Testing Library. Playwright + axeto be added
Env.env.local: CENTRAL_API_URL (server only). No secrets in NEXT_PUBLIC_*—

Every new dependency is justified in the Phase 0 plan and needs approval before it's added.

ServerAvatar V8 Central · prepared by central-app-2 (Pair 2 frontend) for Bhavik Jethwa · nothing in this spec is implemented yet · Built 2026-10-03 12:35 UTC