Firstly, should the static page that is served for the app be the login page?
Secondly, my server side code is fine (it won\'t give any data that the user shouldn\'t
I think you should do this server sided only... There are many chances of getting it hacked unit and unless you have some sort of amazing api responding to it