#Frontend vs backend responsibilities
The frontend is a view layer. The backend owns every rule, number and decision. "Hint" means the frontend may pre-check for UX, but the backend must check again.
| Feature | Frontend | Backend (sa-central-api-2) | OSS |
|---|---|---|---|
| Login UI | Form, states, 2FA step, redirect | Authentication, lockout/ban, rate limits, login history | — |
| Registration | Form, Turnstile widget, code fields | Turnstile verify, validation, account creation, verification mail | — |
| OAuth | Buttons, callback page | Provider exchange, account linking, 2FA/IP checks | — |
| Session | httpOnly cookies via BFF, refresh once, logout cleanup | Token issue/refresh/revoke (Passport) | — |
| Permission UI | Hide/disable by the permission map | Authorization on every request (membership, role, plan gating, expiry) | OSS permission on the machine account |
| Organization switcher | Current organization choice, reload scoped data | Membership check per request | — |
| Plan display | Render the catalog and current plan | Plan source: prices, limits, features, eligibility | — |
| Usage display | Bars, warnings | Usage calculation (servers in Central, apps via OSS) | Application counts |
| Limit enforcement | Disabled button (hint) | Refuse over-limit actions | — |
| Payment UI | Checkout summary, redirect, return page polling | Payment verification with the gateway, crediting, idempotency, webhooks | — |
| Subscription changes | Buttons enabled from API flags | Proration, charging, state changes, reminders, expiry jobs | — |
| Invoices | List, download link | Generation, numbering, tax, PDF | — |
| Server key form | Input (masked), never stored/logged in the browser | Secure storage (encrypted), never returned | Key creation/rotation (admin) |
| Server connection UI | Wizard + results | Actual connection: reachability, key, version, duplicate, limit | /health, /auth/me |
| Server details | Render live data, poll while visible | Proxy with permission + audit + error mapping | All server operations |
| Server status | Badges | Background health checks, last_seen | /health |
| Provider connect | OAuth button / token field | Token exchange/validation, encrypted storage, refresh | — |
| Create VPS | Wizard, progress | Provider API calls, installer run, polling, linking | Installer, CENTRAL_TOKEN |
| Blueprints | Editor, deploy dialog, run viewer | Storage, upload signing, sending to OSS, run tracking | Execution (WP Toolkit) |
| Audit display | Table, filters, details | Audit creation for every action, retention | Own server log |
| Search | ⌘K dialog | Query across permitted resources | — |
| Notifications | Bell, list, channel forms | Creation, delivery to channels, test send | (alerts API missing) |
| i18n | All UI strings, formatting | Translated messages via Accept-Language, codes | Translated messages |
| Theme | Entirely frontend | — | — |
| Validation | Zod schemas for instant feedback | FormRequest validation is authoritative | Own validation |
| Delete protection | Confirm dialogs | Check the user's delete-protection setting before deletes | — |
| Rate limiting | Show wait time | Enforce limits | Enforce its own limits |