Key idea
A web app is split across the network. The frontend runs in the visitor's browser, on their computer. The backend runs on a server you control. Everything in the browser can be read and changed by the visitor, so secrets and the final say on who may do what stay on the server.
The browser's side
Open https://shop.example.com and the browser downloads files: HTML for the content, CSS for how it looks, and JavaScript for what happens when you click. Then it runs them itself, on the visitor's laptop or phone. That's the frontend, also called the client.
Frontend code is good at what happens on screen: opening a menu, warning that a form field is empty, updating the cart count without reloading the page.
The server's side
The backend is a program running on a server. It receives the HTTP requests you met in Cloud foundations, reads and writes the database, calls other services such as a payment provider, and sends a response back.
It can be written in any language: JavaScript on Node.js, Python, Go, Ruby, PHP. Visitors see only its responses, never its code or the passwords it uses.
What the browser can't be trusted with
The visitor owns their browser. With the developer tools open, anyone can read every file your frontend downloaded, change what its JavaScript does, or send any request they like. Two rules follow.
Secrets stay on the server. An API key in frontend code is published to every visitor, even inside a minified file. Build tools that copy variables into frontend code, such as Vite's VITE_ prefix or Next.js's NEXT_PUBLIC_, make those values public on purpose.
The server makes the final check. Hiding the Delete button from people who aren't admins is good design, but it isn't security: anyone can send the delete request by hand. On every request, the server checks who is asking and whether they're allowed.
Where a piece of code goes
Ask two questions:
- Does it need a secret, the database, or the power to decide who's allowed? It goes on the server.
- Does it react to what the visitor does on the page, without waiting? It goes in the browser.
Some work belongs on both sides. Checking that an email address looks right gives instant feedback in the browser, and the server checks it again before saving, because the browser's check can be skipped.
Check yourself