Frontend playbook
Pick the app first. Then use Screens / Pages (default), Logic / Functions (same write-ups, capability names), or ENV / Metadata Catalog.
| App | Host | Audience | Start |
|---|---|---|---|
| User App | app*.nellalink.com | Logged-in owner (React) | Screens · Logic · ENV / Metadata Catalog |
| Front-facing | business*.nellalink.com/app/... | Guest, no login (React on faruq; Nuxt on master) | Screens · Logic · ENV / Metadata Catalog |
They meet at QR/share (User App publishes the URL) and at checkout (Front-facing calls Middleware; owner sees the inbox).
Browse x-api-key is public. IDOR is Core Backend and Middleware Backend. Security.