This is my biggest issues with SPAs. Its not that it is that hard, its just so much easier to keep it secure if its being done server-side.
In my mind, anything complex would probably be server side anyway for performance reasons (though I admit there are many, many SPAs with seemingly little thought about performance.)
API keys, anything that handles auth, etc.