Project Rules
Shared coding conventions for this repository, then the Next.js guidance that matches the installed version. Component restrictions, accessibility, responsive behavior, and code snippets stay in Standards & Best Practices.
Shared conventions
Next.js guidance
These notes describe this App Router app on Next.js 15.5.27. They do not add login, and they do not point at a docs folder this install does not have.
ArchitectureKeep routes, layouts, and shared UI in the App Router structure of the application you are building.Server and Client ComponentsKeep client JavaScript on the interactive pieces.Data fetchingChoose freshness from the data, not from a single cache rule.Authentication and authorizationAuthorize on the server. A hidden button is not a permission.SecurityStop injection, secret leaks, and unsafe uploads in a government-facing application.PerformanceShip less client JavaScript and avoid waiting in series.AccessibilityUse the element, name, and focus treatment the standards describe. This page is not an audit.TestingCheck types and behavior before calling a screen done.DeploymentBuild the application that is configured. Do not add a host that was not requested.