V8 Central — Product & Technical Spec
  1. Docs
  2. Technical
  3. Frontend vs backend

#Frontend vs backend responsibilities

The frontend is a view layer. The backend owns every rule, number and decision. "Hint" means the frontend may pre-check for UX, but the backend must check again.

FeatureFrontendBackend (sa-central-api-2)OSS
Login UIForm, states, 2FA step, redirectAuthentication, lockout/ban, rate limits, login history—
RegistrationForm, Turnstile widget, code fieldsTurnstile verify, validation, account creation, verification mail—
OAuthButtons, callback pageProvider exchange, account linking, 2FA/IP checks—
SessionhttpOnly cookies via BFF, refresh once, logout cleanupToken issue/refresh/revoke (Passport)—
Permission UIHide/disable by the permission mapAuthorization on every request (membership, role, plan gating, expiry)OSS permission on the machine account
Organization switcherCurrent organization choice, reload scoped dataMembership check per request—
Plan displayRender the catalog and current planPlan source: prices, limits, features, eligibility—
Usage displayBars, warningsUsage calculation (servers in Central, apps via OSS)Application counts
Limit enforcementDisabled button (hint)Refuse over-limit actions—
Payment UICheckout summary, redirect, return page pollingPayment verification with the gateway, crediting, idempotency, webhooks—
Subscription changesButtons enabled from API flagsProration, charging, state changes, reminders, expiry jobs—
InvoicesList, download linkGeneration, numbering, tax, PDF—
Server key formInput (masked), never stored/logged in the browserSecure storage (encrypted), never returnedKey creation/rotation (admin)
Server connection UIWizard + resultsActual connection: reachability, key, version, duplicate, limit/health, /auth/me
Server detailsRender live data, poll while visibleProxy with permission + audit + error mappingAll server operations
Server statusBadgesBackground health checks, last_seen/health
Provider connectOAuth button / token fieldToken exchange/validation, encrypted storage, refresh—
Create VPSWizard, progressProvider API calls, installer run, polling, linkingInstaller, CENTRAL_TOKEN
BlueprintsEditor, deploy dialog, run viewerStorage, upload signing, sending to OSS, run trackingExecution (WP Toolkit)
Audit displayTable, filters, detailsAudit creation for every action, retentionOwn server log
Search⌘K dialogQuery across permitted resources—
NotificationsBell, list, channel formsCreation, delivery to channels, test send(alerts API missing)
i18nAll UI strings, formattingTranslated messages via Accept-Language, codesTranslated messages
ThemeEntirely frontend——
ValidationZod schemas for instant feedbackFormRequest validation is authoritativeOwn validation
Delete protectionConfirm dialogsCheck the user's delete-protection setting before deletes—
Rate limitingShow wait timeEnforce limitsEnforce its own limits