I was thinking about it extensively this morning and the only solution I came up with was to accept only "new" events eg. X seconds from created_at but this has a lot of downsides too.

Requiring auth and enforcing protected events sounds good but yeah there's the client issue.

Reply to this note

Please Login to reply.

Discussion

You'd be AUTH'ing to publish a signed event, I don't see any issue there.

Twitter-like clients are not a great fit for this UX.

Community clients are. #workingonit

That's a valid point right there.