- Shipped
- September 7, 2026 at 5:05 AM UTC
- Author
- Kamo
- Commit
- 47ee9ea
SecurityService publishes **************** on core NATS; this puts it on **************** Same arrangement as the training badge, and for the same underlying reason: SecurityService owns the data and has no WebSocket of its own. THE PAYLOAD IS THE WHOLE CARD, not a cue to fetch one. Every other per-member relay here carries a count and lets the client re-read; this one cannot, because the entire point is that the celebration lands in the same second as the deed. A round trip inserted between the two is the one cost this feature cannot absorb. A dropped frame costs nothing: the unlock is committed to member_achievement_unlocks before it is published and the browser reads its pending rows on mount, so the worst case is being congratulated on the next page load rather than instantly. THE SEND GUARD IS THE INTERESTING HALF. The simple broker fans a frame out by destination regardless of which command carried it, so guarding SUBSCRIBE alone is not a guard. And because this topic's payload IS the popup — icon, wording, rarity, level, points — a client permitted to publish here could put an arbitrary full-screen message, in the platform's own congratulatory voice, in front of any colleague. It is the most convincing surface in the application for something that is not true. Not even the member the topic belongs to may write it.