logoalt Hacker News

the_mitsuhikoyesterday at 4:52 PM1 replyview on HN

If you must not leak timestamps then you also cannot really have timestamp ordering internally because you will happen to start leak that out in other ways through collection based endpoints.


Replies

JimDabellyesterday at 5:10 PM

Not necessarily. For instance, in situations where unprivileged users can only see single items but privileged users can see collections. But yeah, time-ordering leaks information to people who can see the collection.