Demo / API switch
Choose browser demo records or connect the workspace to your own server.
Default: local demo
Open src/config/backend.ts. Demo mode uses the existing local fake service and browser storage. No API server is required.
Enable your backend
- Copy .env.example to .env.local and set your public API and sign-in URLs.
- In src/config/backend.ts, comment the demo line and uncomment the HTTP line. Keep exactly one mode active.
- Implement the session and workspace contracts below on your server.
- Restart Vite during development, or rebuild and redeploy dist for production.
// mode: 'demo',
mode: 'http',VITE_API_BASE_URL=/api
VITE_LOGIN_URL=/loginThe Sign in link goes to your server authentication flow. Return the user to the React application after successful authentication. Same-origin cookie sessions are the simplest configuration. For a different API origin, configure credentialed CORS and cookie policy on your server. VITE values are public; never put private keys in them.
Required API contract
| Method | Path relative to API base | Response |
|---|---|---|
| GET | /session | JSON: signedIn true, role admin/manager/viewer, nonempty csrfToken. Return 401 when signed out. |
| GET | /workspace | Complete BusinessData snapshot. |
| POST | /workspace/actions | Accept an Action JSON body and return the committed BusinessData snapshot. |
| POST | /logout | Invalidate the session and return a success status, such as 204. |
{ "signedIn": true, "role": "manager", "csrfToken": "server-issued-token" }{ "version": 2, "customers": [], "projects": [], "products": [], "orders": [], "activity": [] }See src/features/business/model.ts for every record field and Action union. Requests send credentials; POST requests send X-CSRF-Token. Validate permissions, ownership, amounts and state transitions on your server. The reset action is blocked in HTTP mode. A successful mutation returns the full committed snapshot, not a partial record.
What changes and what stays a demo
| Area | HTTP mode behavior |
|---|---|
| Overview, Customers, Projects board, Orders, Inventory | Server workspace snapshot and mutations. No seeded fallback or localStorage persistence. |
| Workspace settings | Shows connection details; demo role switch, reset and failure simulation are disabled. |
| Team, Support, Billing and other admin modules | Separate AdminProvider browser demos; integrate their services independently. |
| Legacy showcase pages and sample profile identity | Illustrative data remains; connect each required feature and identity UI separately. |
| Appearance preferences | Remain local browser preferences. |
Verify the connection
- Confirm GET /session and GET /workspace in browser Network tools.
- Create or edit a customer and confirm POST /workspace/actions, then reload to verify server persistence.
- Return 401 and verify the sign-in screen; return malformed workspace data or 500 and verify the retry screen without sample records.
- Return 403 or 409 on save and verify the visible error and unchanged records.
- Sign out and confirm the server invalidates the cookie before the app shows the sign-in screen.
Return to demo mode
Comment mode: http and restore mode: demo in the config, then restart or rebuild. Previously saved browser demo records become available again; switching modes does not delete them.