| R1 V7 functional reference only | No V7 code reuse | Frontend is new too. V7 is used only for flows/UX | Sources |
| R2 Build from V8 requirements | V8 doc wins | Every frontend page cites the backend item | this page |
| R3 Code standards | Laravel standards, Passport, per-pair DB | Base URL = own pair's API only. Paginated lists | API architecture |
| R4 Working method | Phase by phase, nothing built until approved | Frontend phases follow backend phases | Implementation phases |
| R5 Central stores minimum, OSS live | Server/app data from the OSS API | Server Details = live proxy views, offline states | Architecture, Server details |
| §2.2 Common OSS client | One client, consistent errors. Built with the Servers phase, not the Foundation phase (2026-10-03) | Frontend maps a small set of server error codes. Server Details screens cannot start before the Servers phase | Global states, Architecture |
| Phase 1 1.1–1.9 Foundation | MariaDB, Redis, Horizon, Passport, Telescope, CORS, mail/log, security | CORS origin = frontend URL. HTTPS + secure cookies. "Next.js login flow decided later" | FE: Foundation |
| 2.1 Register | Name, email, password ≥ 8, Turnstile, optional codes + onboarding | Register screen | FE: Auth screens |
| 2.2 Email verification | Inactive until verified, resend, 24 h | Check-inbox + verify-result screens | FE: Auth screens |
| 2.3 Login | Email + password, unverified/banned messages, token + user + organizations, login history | Login screen | FE: Auth screens |
| 2.4 Google / GitHub | Redirect → callback, auto-link, same 2FA/IP checks | OAuth buttons + callback page | FE: Auth screens |
| 2.5 Forgot / reset | 60 min link, logs out all devices | Forgot + reset screens | FE: Auth screens |
| 2.6 Invitation password | Set password from the invite link | Invitation screen | FE: Auth screens |
| 2.7 2FA at login | Email code 10 min / 5 tries / resend, authenticator, backup code | 2FA step | FE: Auth screens |
| 2.8 IP whitelist at login | Block + approval email 24 h | IP-approval notice + result | FE: Auth screens |
| 2.9 Tokens | Bearer 15 d + refresh 30 d, rotation. Central issues both tokens itself after password → 2FA → IP checks, for email and Google/GitHub login (2026-10-03) | BFF cookies, refresh once. One login response carries both tokens; the OAuth callback is handled like a password login | FE: Auth screens, FE: Foundation |
| 2.10 Logout | Revoke current token | Logout action | FE: Auth screens |
| 2.11 Security | Rate limits, middleware | 429 handling on every auth form | FE: Auth screens |
| Phase 2 settings | Mail/Turnstile/OAuth keys from admin panel (DB until then) | Turnstile site key must come from the API, not a frontend env file Open question | FE: Auth screens |
| Phase 2 "not in this phase" | Orgs not auto-created; dropped V7 sign-up checks; migration later | Create-organization screen after the first login | Organizations |
| 3.1–3.7 Profile | View, update (+ onboarding answers), change email, change password, email preferences, delete protection, delete account | Account → Profile | FE: Account screens |
| 3.8–3.13, 3.16 Security | 2FA + backup codes, Google Authenticator, IP whitelist, login history, account activity, API access, active sessions. V7 API tokens are migrated and keep working; users do not create new ones (2026-10-03) | Account → Security. The API screen is an on/off switch with no "create token" button — this answers the old Open question about a copy dialog | FE: Account screens, V7 migration |
| 3.14, 3.15, 3.17 Notifications | In-app list, channels (Email, Telegram, Pushover, Slack, Discord, Webhook — both added 2026-10-03) + test, server alerts from OSS | Bell + Account → Notifications. Two more channel types in the type picker: Discord (Discord webhook URL) and Webhook (any URL, JSON POST) | FE: Account screens, Notifications |
| Phase 3 "not in this phase" | Confirmation timer ignored. Billing, referral, support, AI later | Not built | Open questions |
| Phase 3 existing users | Profile, preferences, 2FA, IP whitelist, login history, channels and API tokens carry over from V7 | Every account screen must load pre-filled data and never invalidate a migrated API token | FE: Account screens, V7 migration |
| Phase 4 Organization & Members | Requirements complete 2026-10-03 09:39 (Pair 1) V8 requirement: organizations with a default and letter avatar, delete rules, invites that must be accepted (7-day links, resend, cancel), one role per member, fixed Owner + Admin and custom view / manage roles, share one server, ownership transfer, organization activity log | Full screen spec written. Closes D-25, and answers D-7 (view/manage), D-9 (accept always) and D-8 (sharing stays — against our recommendation) | FE: Organization & Members, Organizations, Members, Roles & permissions, Audit log |
| 4.1–4.2 Organizations | Creator is owner; first one is the default; letter avatar when no logo; delete is owner-only, not the default, not with servers | List + settings + danger zone; the delete button shows the blocking reason instead of failing | FE: Organization & Members |
| 4.3, 4.4, 4.6 Members & sharing | Invite (email, designation, role), every invite accepted, 7-day links, resend/cancel; one role per member; owner untouchable; leave; share one server by invite with no create/delete/share | Single-select role picker, pending rows with "expires in N days", shared people listed apart from members | FE: Organization & Members, Members |
| 4.5 Roles | Owner and Admin fixed; custom roles view / manage; parents ticked automatically; no delete while members hold it | Read-only system roles, auto-ticking matrix built from the API catalog (names still unpublished), Delete disabled with "N members use this role" | FE: Organization & Members, Roles & permissions |
| 4.7 Ownership transfer | Owner only, to an existing member. Both sides confirm with their own password (or email code) + their own 2FA, accept within 48 h, old owner becomes admin, blocked on unpaid charges or a plan that doesn't fit. Subscriptions move in the billing phase | New two-sided flow: start dialog, pending state with "expires in N hours" for both people, accept dialog, expired and blocked states | FE: Organization & Members |
| 4.8 Organization activity | Organization, member, role, share and transfer actions | The organization-level log, separate from the account activity in 3.12 | Audit log |
| Phase 5 Integrations | Requirements drafted 2026-10-03 V8 requirement: cloud providers in Central (organization level); Git accounts and backup storage live in each server's OSS with Central keeping only a note ("Option B"); create a server on a provider with automatic OSS install; organization Integrations page | Full screen spec written: provider list/connect/reconnect/disconnect, create-server wizard + live progress (Creating → Installing OSS → Ready / Failed), Git / storage modal with "add to other or all servers" and a result per server, replace-token-everywhere, remove from one or all | FE: Integrations, Providers, Servers, Server details, Phases |
| 5.2, 5.3 Named accounts + Edit | New 2026-10-03: each provider account gets a name, several accounts per provider are allowed, and Edit changes the name or pastes a new token. "Needs new token" now points at Edit | Name field in the connect modal and everywhere the account is picked; one Edit modal (token blank = keep current) replaces the separate "paste new token" dialog; the list groups by provider and shows names | FE: Integrations, Providers |
| 5.6, 5.8, 5.9 Git & storage | New / changed 2026-10-03: Git and storage accounts also get a name; the result per server applies to connect, update and remove alike; a Test button checks the account on that server | One result table reused by all three actions (never a single "saved" toast for a multi-server action, including removals); per-server Test with the last result shown on the row | FE: Integrations §C |
| Who can do it | New 2026-10-03: connect, edit, test and remove follow the organization roles from Phase 4 | Every button on the integration screens is permission-driven. The permission names are still unpublished, so checks come from the API catalog | FE: Integrations, Roles & permissions |
| 5.1, 5.4, 5.5 Cloud providers | Pasted API token for every provider — no OAuth (Lightsail: access key + secret), checked on save, encrypted; no renewal — a rejected token marks the account "Needs new token"; disconnect keeps servers. Requirements complete 2026-10-03 | One connect modal for all providers, never a redirect; "Needs new token" blocks creating servers with that account. Conflict with V7's OAuth accounts → D-29 (how they migrate) | FE: Integrations, Providers |
| 5.3 Regions & sizes | Moved out of Phase 5 → Servers phase (2026-10-03), read live when creating a server | Part of the create-server wizard, not the Integrations page | Servers, FE: Integrations §B |
| 5.13 Repos & branches | Moved out of Phase 5 → Applications phase (2026-10-03), read from the server's OSS | Account → repository → branch dependent dropdowns move to the application-from-Git flow | Server details, Phases |
| Create server (was Phase 5 B) | Moved out of Phase 5 into the Servers phase on 2026-10-03; the backend's draft is parked at the end of their Phase 5, with Q13, Q14, the Ubuntu 20.04 limit and Hostinger's pre-installed stack | Spec kept and clearly marked as Servers phase work: wizard + progress screen (Creating / Installing OSS / Ready / Failed), polling, safe to leave the page. Still answers D-12. Frontend phase 5 (Servers) now owns it | FE: Integrations §B, Servers, Providers, Phases |
| 5.5 Disconnect a provider | Changed 2026-10-03: blocked while any server was created with the account; the warning lists those servers. Allowed only when none use it | Disconnect button disabled with "Used by N servers" and the list in the dialog — replaces the earlier "servers keep running" wording | FE: Integrations, Providers |
| 5.16 Integration activity log | New 2026-10-03: every integration action (connect, edit, add to other servers, update everywhere, remove, disconnect) goes into the organization activity log with who, which account, which servers and when. Tokens and keys are never logged | Nothing new to build — but one entry can cover several servers, so render the server list inside the entry rather than one entry per server | FE: Integrations, Audit log |
| 5.13 Accounts already on the server (renumbered from 5.16) | New 2026-10-03: Central reads existing Git / storage accounts from OSS and shows them; the same account on several servers appears once; adding it to more servers needs the token pasted once | The list mixes accounts Central set up with accounts found on a panel — found ones are marked, grouped by account (not by server), and Central never claims to hold their secret | FE: Integrations §C |
| 5.6–5.15 Git & storage | Form in Central, secret pushed to chosen servers' OSS, per-server result, update everywhere, remove from one or all, repos/branches read from OSS, provider lists | Per-server modals + the organization overview. Central never shows a saved secret again | FE: Integrations, Server details |
| Phase 6 | (by Pair 1) — no name or rules yet, Pair 2's doc just points at Pair 1 | Nothing to spec. Watch Pair 1's doc | Phases |
| Phase 7 Plans (Subscription) | Requirements complete 2026-10-03 V8 requirement: admin-managed plans with a per-plan feature list, one plan per owner across all their organizations, paid from credit (tax added, saved as a charge), trial, change with unused days returned as credit, downgrade checks, cancel / resume, auto-renew, reminders, the V7 expiry flow (day −7 warning → day −15 servers removed from Central + account locked), coupons, plan visibility + display name, enterprise form, activity log | Full screen spec written, including the shared "may I do this?" pattern for plan guards and the locked-account state. Answers D-3 (owner, not organization), D-4 (credit wallet stays, lifetime and legacy kept) and D-6 (limits apply) | FE: Plans & subscription, Plans, Subscriptions, Billing, Audit log |
| 7.1, 7.2, 7.13, 7.14 Admin side | Create / edit / hide / archive plans; one feature list turned on-off per plan; coupons; per-plan visibility and display name | Admin plan editor is a full page driven entirely by the API's feature list, so later phases add features without a frontend change. Two users may legitimately see different plan lists | FE: Plans & subscription §A |
| 7.12 After expiry | Reminders → day −7 warning → day −15: servers removed from Central (not deleted at the provider) and the account locked | The harshest rule in the product: a persistent banner with the exact date and "Add credit", plus a dedicated locked screen where only billing works and which says servers still exist at the provider | FE: Plans & subscription §B |
| Q9 | Answered 2026-10-03: accepted — Git uses an access token / app password, Google Drive a service account, instead of V7's one-click login | No OAuth button on any integration screen; every connect form is a token form | FE: Integrations, Open questions |
| Q10 | Parked: how V7 Git / storage connections move is decided later, with the migration phase | Empty states must explain that a migrated user needs to reconnect | Open questions |
| Q11 | Dropbox skipped for now — not supported in Phase 5 | Not in the storage picker; V7 Dropbox users need a message and an alternative | FE: Integrations, Open questions |
| Q12 Hostinger | Answered 2026-10-03: not a provider. V7 only detects a Hostinger IP when adding an existing server, then removes its pre-installed Apache/MySQL. Servers-phase matter | Nothing in the provider picker. Noted on the Servers page as an existing-server case | Providers, Servers |
| Q13, Q14 | Open OSS registration after an automatic install; rotating the Central token that sits in the start-up script | Moved to the Servers phase with the create-server flow. Q13 is a security hole, not a screen — the progress screen must not reveal the panel URL before Central claims it | Open questions, Servers |
| D-27 (frontend decision) | Bhavik: integrations are account level (frontend doc 3.I1–3.I4). Backend Phase 5: cloud providers per organization | Conflict — the frontend keeps account level and flags it; only the record's owner differs, not the screens | FE: Integrations, Providers, Open questions |
| Q1–Q3 | Server fields, how the key reaches Central, offline display | Server wizard + offline states wait on these | Open questions |
| Q7 | PHPStan — skipped for now (2026-10-03) | Backend only. Frontend keeps ESLint + Prettier | — |
| Q8 | Translations (i18n) and language detection are needed by every phase, but no backend phase sets them up (noted 2026-10-03, not decided) | Frontend i18n is already planned (next-intl, 8 locales, Phase 0). What is missing from the backend: Accept-Language support, error/notification type + params instead of English sentences, and a profile language field | Internationalization, Open questions |
| Organizations, plans, subscriptions, billing, roles, members, servers, providers, blueprints, audit | Not in the backend doc yet | Frontend pages show V7/OSS-based proposals, marked Missing / Open question | Core platform + Modules sections |