#Implementation phases
A realistic roadmap for the frontend (frontend-2), aligned with the backend phases in the V8 doc (Phase 1 Foundation, Phase 2 Auth, Phase 3 Account). The order is changed from the suggested one: Servers move before Plans/Billing, because plans and billing have no V8 requirements or API yet and carry open conflicts (D-3, D-4). See Feature dependencies.
Each phase is planned and approved separately (two-step protocol), and needs its backend endpoints first. Frontend work never fakes a missing API. Where the API isn't ready, the screen isn't built.
| Phase | Scope | Backend needed first | Blocked by |
|---|---|---|---|
| 0. Foundation | next-intl + app/[locale] + middleware. Messages for 8 locales. App shell (sidebar, top bar, drawer, breadcrumbs). Theme. API client (BFF route handlers, httpOnly cookies, error normalisation, retry). Global states (loading/error/not-found). Vitest + Playwright scaffolding. Add react-hook-form, TanStack Table, next-intl (justified deps) | Backend Phase 1 (Passport, CORS) | D-1 (session pattern) |
| 1. Authentication | Login, 2FA step, IP-approval notice, register (Turnstile), verify, forgot/reset, invitation password, OAuth callback, logout, route guards, session restore | Backend Phase 2 | — (requirements complete) |
| 2. Account | Profile, email change, password, 2FA + backup codes, Google Authenticator, IP whitelist, login history, sessions, account activity, API access, email preferences, notification channels, delete protection, delete account | Backend Phase 3 | — (requirements complete) |
| 3. Organizations + Roles + Members | Create-first-organization, switcher, organizations list/settings/set default/delete, roles + permission matrix, members + invitations + accept, leave organization, share server, ownership transfer | Backend Phase 4 — complete 2026-10-03 (by Pair 1) V8 requirement. Endpoints and the permission name list are still not published | Permission names (the backend's permission list and seeder are a separate step), D-28 (which single role a multi-role V7 member keeps) |
| 4. Audit core | Audit Log page, recent-activity component | Audit API + writer used by phases 3+ | — |
| 5. Servers | Connect existing server wizard, create a server at a cloud provider with automatic OSS install (moved here from Phase 5 on 2026-10-03), server list, status, disconnect, Server Details core (Overview, Applications, Databases, System Users, Services) through the proxy | Server link API + OSS client + proxy + the create-server API (backend draft parked at the end of their Phase 5) | Q1 (stored fields), D-10 (proxy style), D-11 (cached list fields), Q13/Q14 (open OSS registration, token rotation), Ubuntu 20.04 and Hostinger pre-installed stacks |
| 6. Plans + Subscription + Billing | Admin plan management (plans + the feature list), plans, current plan + usage, change/cancel/resume/renew, downgrade checks, trial and expiry banners, the locked-account state, coupons, enterprise contact, wallet, top-up + return page, transactions, invoices, auto-recharge, billing details. Plan-limit handling everywhere | Backend Phase 7 — complete 2026-10-03 V8 requirement for plans and the subscription lifecycle. Still needed: the plan catalog + admin endpoints, and the billing / gateway side (not in Phase 7) | D-5 (which gateway buys credit), D-22 (currency and tax), lifetime plans for new users (parked by the backend) |
| 7. Dashboard | KPIs, server status, live metrics, spend, usage, recent activity | Aggregation endpoint | needs 5 + 6 |
| 8. Integrations (was "Providers") | Cloud providers (connect by pasted token, "Needs new token", disconnect), plus Git accounts and backup storage pushed to one or many servers, and the Integrations overview page. Moved out on 2026-10-03: create-server → phase 5 (Servers), regions & sizes → phase 5, repos & branches → Applications (part of Server Details work) | Backend Phase 5 — Integrations, drafted 2026-10-03 V8 requirement. Needs the provider + create-server API and the OSS git / storage calls. Phase 5 itself needs backend Phase 4 (organizations), which is now complete | D-13 (own-VPS install, deferred to the Servers phase), Q10 (migrating V7 Git/storage connections — parked), D-27 (account level vs organization level), D-29 (V7 OAuth provider accounts → V8 tokens) |
| 9. Blueprints | List, editor, deploy to WordPress site, run results | Blueprint storage + run API + add-on install/licence | D-14, D-15 |
| 10. Search + Notifications + UX polish | ⌘K search, notification bell/list, Server Details later sections (firewall, cron, backups, PHP, Node, Fail2ban, settings, logs, disk cleaner) | Search API, notifications API, alerts source | D-16, D-17 |
| 11. Production readiness | Full a11y pass, responsive pass 320→1920, all 8 locales reviewed, performance budget, E2E suite green, error monitoring | — | — |
#Parallel work
- Phases 1–2 can start as soon as the backend Phase 2/3 endpoints are agreed. The UI can be built against the agreed contract with a mock server only if the backend team publishes the contract first (no invented APIs).
- Server Details core sections (phase 5) only need the proxy. The OSS API they use already exists and is documented.
- Pair 1 and Pair 2 split phases (V8 doc R4: Phase 1 by Pair 1, skipped phases by Pair 1; Phase 4 Organization & Members by Pair 1, Phase 5 Integrations by Pair 2, confirmed 2026-10-03). Who builds which frontend phase must still be agreed Open question D-20.
#Per-phase exit criteria
Build + lint green · Vitest + Playwright green for the phase · every string an i18n key (8 locales present) · light/dark checked · 320/768/1280 checked · axe clean · backend permission denial covered · docs (this site) updated.