The Last Spike Online / 15 July 2026

In an online board game, the browser cannot be the referee

The key multiplayer decision was to make the server authoritative over game state. Clients send intent; they do not send finished truth.

2 min read
The Last Spike Online
WebSocketmultiplayerstate-machinearchitecture

Situation

In a local game, letting the client own the complete state is natural. In an online room, however, two browsers can simultaneously disagree about the turn, money or a hidden card. If clients try to synchronize one another's state directly, race conditions and a cheat-friendly protocol appear quickly.

Approach

I moved the authoritative state machine to the WebSocket server. The client sent commands; the server validated them, applied them through the deterministic engine, then broadcast only the view each participant was allowed to see. Reconnect and persisted-room behaviour were built on the same model, so a returning player did not try to reconstruct the game from stale local memory.

Outcome

Multiplayer behaviour became more stable and later hidden-information filtering gained a clear architectural home. The same domain engine still served local, AI and online play, but online truth came from one server-side state.