Leaderboard & Counting Service · View 20 of 21 · Assurance
Decisions
- The token's subject must equal the member reference in the event. A client that can write another member's counter is the whole attack, and this check is the one that prevents it.
- Client-writability is a property of the counter definition, read at admission. It is not a scope on the token, so revoking it is a configuration change rather than a token rotation.
- The inflation signal holds rather than refuses, because a false positive that rejects must be re-earned by the member while a false positive that holds can simply be cleared.
What the refusals catch
- Subject mismatch — writing as someone else. Client-writability — writing a counter the product never exposed. Bounds — a plausible event with an implausible delta. Inflation — plausible events at an impossible rate.
- The idempotency echo in the response is what lets a client retry safely without a second effect.
Risks
- Reading the counter definition at admission puts the control plane on the hot path of every client write. It is cached per instance, which makes a revocation eventually consistent by up to the cache TTL.
- A held contribution is invisible to the member, who sees their action not counted and has no way to learn why.