This is not just a Next.js style preference. It is a security boundary.
Cogweald keeps OpenAI, Supabase service-role access, billing, and the simulation engine in server-only code. Client Components can call controlled server actions or route handlers, but they never import those services directly.
The reasons are practical:
- API keys must not enter the browser bundle.
- A service-role client must not be exposed to users.
- Chapter generation needs authorization and state validation.
- Billing actions must run in a trusted server context.
AI apps often put sensitive calls in the browser just to make the first button work, then try to repair the boundary after deployment. A better approach is to establish it in the import graph from the beginning: which modules are server-only, and which data is safe to send to the client?
A feature can be finished later. Secrets should never be shipped first.
Top comments (0)