Secret
BackendAny value that grants access.
A database password, an API key, a signing key. Never in code, never in a client bundle. If one leaks, revoke it first. Deleting the line comes second, and git history keeps it regardless.
See also Environment variable, Key rotation
Server state
FrontendData fetched from an API, held in the UI.
Not really your application’s state, but a cache of somebody else’s, which goes stale the moment anyone else changes it. Treating it as local state is what produces "I updated it but the list still shows the old value".
See also State, Cache