Splitting responsibility between the user interface and the server: where state lives, where checks run, and how the two talk.
- The Untrusted Client
- Everything in a browser or app can be read and changed by its user, so every rule that matters is enforced on the server.
- Where State Lives
- Server state, client state, URL state and caches, with a single source of truth for each value.
- Rendering Models
- Server-rendered, client-rendered and hybrid pages, and what each costs in speed, search visibility and complexity.
- UI States
- Treating each screen as a state machine with loading, empty, error, partial and success states.
- Accessibility
- Semantic markup, keyboard navigation, contrast and screen-reader support, so the interface works for everyone.
- APIs Shaped for Interfaces
- Designing server responses around what screens need, avoiding both over-fetching and chatty clients.