
# Frontend/API integration — v0.4.0-alpha.1

## Scope

The Mini App performs a read-only request to:

`GET /api/v1/mandalas/1`

using the same HTTPS origin as the frontend.

The returned server cell state is applied to the visible Mini App state.

## Deliberate limitation

Cell occupation is still handled by the existing local interaction in this alpha.
The next release will move occupation to the authenticated API write endpoint.

## Failure behavior

If the API is unavailable, the Mini App retains its local state and shows
`Оффлайн-режим`. This fallback is temporary and will be removed once the server write
path is active.

## Read-path correction

The mandala summary endpoint includes the complete `cells` array so the frontend can
verify and render server-side ownership state, not only aggregate progress.


## Server-authoritative cell occupation

The main «Занять клетку» action now calls:

`POST /api/v1/mandalas/1/cells/:position/occupy`

The request includes `X-Telegram-Init-Data`. The browser does not mutate ownership
locally before the server confirms success.

After a successful write, the Mini App re-reads the full mandala from the API.
A `409 CELL_ALREADY_OCCUPIED` response leaves the local state unchanged and then
refreshes the server state.
