# Frontend and AJAX (not provided)

> SummerCMS is headless, so CMS pages, themes, components, the AJAX framework and Snowboard are not provided; build the frontend as a separate application.

WinterCMS renders its frontend on the server: CMS pages and layouts in a theme, partials, components that plugins attach to pages, and the AJAX framework with Snowboard for handlers such as `onSave` that update parts of a page without a reload. SummerCMS provides none of these. It is headless: it serves a JSON API, realtime channels and the admin SPA, and the frontend is a separate application that talks to it.

## What is not provided

| WinterCMS | In SummerCMS |
|-----------|--------------|
| CMS pages, layouts and partials in `themes/` | Not provided. The frontend application renders every page. |
| Themes and the theme customisation form | Not provided. |
| Components and `componentDetails`, `defineProperties`, `onRun` | Not provided. Expose the data a component loaded as a JSON route. |
| The AJAX framework (`data-request`, `$this->page`, AJAX handlers) | Not provided. Call JSON routes with the frontend's own HTTP client. |
| Snowboard and its plugins | Not provided. |
| Twig and the Twig filters and functions | Not provided. |
| Sessions and flash messages | Not provided. The API is stateless and authenticates each request with a token. |

A WinterCMS plugin that shipped components and AJAX handlers is ported as routes: each component's data loading and each handler becomes a JSON endpoint declared through `pact.HasRoutes`.

## Building the frontend

Build the frontend with any framework that can call a JSON API, as its own project with its own build and deployment:

- **Data:** call the plugins' JSON routes. [Routing](/docs/services/routing.md) shows how routes, auth groups and JSON responses are declared, and [Queries and pagination](/docs/database/queries-and-pagination.md) the list envelope.
- **Signing in:** the user plugin issues JWTs; send them as a bearer token or in the cookie the guard reads. See [Authentication](/docs/services/authentication.md).
- **Live updates:** instead of polling an AJAX handler, subscribe to realtime channels. The frontend connects to Centrifugo with a token from the token route and receives model broadcasts and explicit events. See [Realtime](/docs/services/realtime.md).
- **Cross-origin calls:** when the frontend runs on another origin, allow it in `http.cors`, as [Routing](/docs/services/routing.md) describes.
- **Push notifications:** see [Web Push](/docs/services/push.md).

The admin is the one frontend SummerCMS ships. It is a single-page app built the same way, against the admin API; see [Admin SPA](/docs/backend/admin-spa.md).

The full map of what carries over from WinterCMS, and what does not, is on [Coming from WinterCMS](/docs/setup/coming-from-wintercms.md).
