Keep the browser behind a BFF
The frontend calls one controlled API boundary instead of connecting directly to internal report services.
Case Study · Data & Business Dashboard
An internal reporting platform that turns daily e-contract data into a usable executive dashboard while keeping the browser away from the report service and database.
My role
Frontend dashboard & BFF development
Stack
Angular 19 · Express BFF · TypeScript · REST API · Docker · Redis Session · Jest
Executives needed daily e-contract numbers in a form that was easier to understand than raw API responses. The dashboard also had to respect existing service boundaries: the browser should not query the report service directly or access the database, and repeated or expensive requests needed protection at the BFF layer.
I contributed to an Angular dashboard backed by an Express BFF. The frontend focuses on login, report views, Thai date filtering, drilldown, and chat-based report questions. The BFF acts as the single API boundary, proxies approved report endpoints, handles authentication flow, applies request controls and upstream timeouts, and keeps the report source of truth behind the service boundary.
The browser communicates only with the Express BFF. The BFF handles login/logout through login-service and proxies approved report requests to report-econtract-service, which remains the source of truth for report data. The dashboard does not access a database directly.
01
Angular Browser
02
Express BFF
03
Report E-Contract Service
04
Report Data
The frontend calls one controlled API boundary instead of connecting directly to internal report services.
The dashboard consumes report APIs and does not duplicate SQL or business report queries in the frontend.
The report assistant classifies supported questions and can call only explicitly allowed report APIs.
Rate limits, request IDs, health probes, and upstream timeouts make the BFF a controlled boundary for operational traffic.
The dashboard needed to present the same source data as clear KPIs, summaries, and drilldowns without creating a second reporting source.
The browser was kept away from report-econtract-service; all report traffic passes through the BFF so authentication and operational controls stay centralized.
Daily reports needed Thai date handling and explicit report-date context so the selected date could be carried consistently through the UI and API requests.
The BFF applies rate limits and upstream timeout/health controls so bursts or unavailable dependencies do not become uncontrolled browser traffic.
The system gives executives a focused reporting workspace while preserving a clean boundary around internal services. Report data stays owned by report-econtract-service, the browser stays behind the BFF, and operational guardrails are applied before traffic reaches shared backend services.