#Route structure
All routes live under app/[locale]/ (next-intl). :locale ∈ en, es, de, fr, pt, ja, ru, hi. No routes exist yet: frontend-2 only has the scaffold app/page.js. Missing
#Public routes — (auth) group
| Route | Page |
|---|---|
/:locale/login | Login (+ 2FA step, IP-approval notice) |
/:locale/register | Register (?invite=<token>, ?ref=, ?aff=) |
/:locale/verify-email | "Check your inbox" + resend |
/:locale/verify/:token | Verification result |
/:locale/forgot-password | Request reset |
/:locale/reset-password/:token | Set new password |
/:locale/invitations/:token | Accept invitation (set password / join) |
/:locale/ip-approval/:key | IP approved / expired |
/:locale/oauth/:provider/callback | Social login landing |
/ | Redirect to /:locale/dashboard (or login) |
#Protected routes — (app) group (logged in)
| Route | Page | Permission |
|---|---|---|
/:locale/organizations/new | Create first/next organization | logged in |
/:locale/dashboard | Dashboard | org member |
/:locale/organizations | My organizations | logged in |
/:locale/organizations/:id/settings | Organization settings | Organization manage |
/:locale/account/profile | Profile | logged in |
/:locale/account/security | Password, 2FA, IP whitelist, sessions, login history | logged in |
/:locale/account/notifications | Channels + email preferences | logged in |
/:locale/account/api | API access | logged in |
/:locale/notifications | All notifications | logged in |
#Permission-protected routes (current organization)
| Route | Page | Permission |
|---|---|---|
/:locale/servers | Server list | Servers view |
/:locale/servers/new | Add server (connect / create) | Servers manage |
/:locale/servers/:id | Overview | Servers view + OSS dashboard |
/:locale/servers/:id/applications (/:appId/...) | Applications | application |
/:locale/servers/:id/databases | Databases | database |
/:locale/servers/:id/system-users | System users | system_user |
/:locale/servers/:id/services | Services | service |
/:locale/servers/:id/{firewall,cron-jobs,backups,php,node,fail2ban,logs,disk-cleaner,settings,activity} | Later sections | matching OSS permission |
/:locale/providers | Provider accounts | Providers view |
/:locale/blueprints · /new · /:id | Blueprints | Blueprints view/manage |
/:locale/members | Members + invitations | Members view |
/:locale/roles · /:id | Roles | Roles view |
/:locale/plans | Plans | Plans view |
/:locale/subscription | Subscription | Subscription view |
/:locale/billing · /wallet · /transactions · /invoices · /payment-methods · /auto-recharge · /settings | Billing | Billing view |
/:locale/billing/return | Payment return → verification | Billing view |
/:locale/audit-log | Audit log | Audit view |
Organization: the current organization is not in the page URL (it comes from the cookie + switcher), but it is in every API path. Alternative: /:locale/o/:orgSlug/... page URLs (shareable links). D-18.
#Per-group files
Each route group has loading.js, error.js, not-found.js. Detail segments (servers/[id]) have their own not-found and an "unreachable" state.
#Map
Public
loginregisterverifyforgot / resetinvitations/:tokenip-approvaloauth callback
App shell
dashboardorganizationsaccount/*notifications
Infrastructure
serversservers/:id/*providersblueprints
Organization
membersrolesorganizations/:id/settings
Finance
planssubscriptionbilling/*
Audit
audit-log