Frontend
Back-office
The eight shipped administrator capabilities over Referential and SIV.
The back-office is a TanStack Start server-rendered application. Authenticated server functions call SmartGare services; bearer and refresh tokens never reach browser JavaScript.
Shipped workspaces
| Capability | Route | Workflow |
|---|---|---|
| Carrier master data | /transporteurs | search, register, correct, activate, suspend, reactivate |
| Lines and itineraries | /trajets-quais | line register, calling points, immutable revisions |
| Vehicle records | /parc-acces | search, register, correct, transfer, category, lifecycle |
| Vehicle permits | vehicle detail + REF-7 | issue, history, derived validity presentation |
| Permit CSV import | REF-8 | upload and mixed-result report |
| RFID identifiers | vehicle detail + REF-9 | enroll, history, explicit revocation |
| Permit expiry review | REF-11 | worklist and manual watch trigger |
| Display administration | /points-affichage | points, profiles, assignment, retirement |
BFF security
- Login callback and token refresh happen server-side.
- Session cookies are HTTP-only.
- Backend calls use server functions.
- Routes, controls, reads, and mutations are capability-gated.
VITE_API_MOCKmust never be enabled in a deployment.
Preserving domain grain
The UI does not flatten backend distinctions:
- a line is not a carrier, destination, schedule, departure, or bay;
- permit validity is derived, not copied to a vehicle;
- vehicle
ACTIVEis administrative state, not access permission; - correction, transfer, category change, suspension, and reactivation are separate commands;
- itinerary revisions preserve published history;
- partial permit imports remain visible row by row.
URL and paging contract
Server paging and filters live in route search parameters when the workspace must be shareable or reloadable. Registers avoid fixed-height inner scrolling; the visual overview and table are projections of the same server page.
Mock mode supplies representative identity, capabilities, and records without persisting mutations. It is UI-development support, not production integration proof.