score-api.txt
My browser game needs an online leaderboard. Backend: <stack> on <host>.

Build:
- One endpoint to submit a score and one to fetch the top 20.
- A table with name, score, date, and whatever I need to reject
  duplicates.
- A sanity check that rejects impossible scores and impossibly fast runs.
- A rate limit per player.
- Names trimmed, length-limited and escaped when displayed.

Be honest about how much cheating this stops, and what more would cost.

Anything the browser sends can be edited. A plausibility check stops casual cheating, and for a small game that's usually enough.