Denial of service due to business logic flaw (authenticated)
Specific authenticated request sequences could be triggered to put the application into an unrecoverable state for the affected user, requiring re-auth or session reset to recover.
Description
The audited authenticated flow had a business-logic ordering issue: specific sequences of requests left the application in an unrecoverable state for the affected user. The user-visible result was a frozen game UI requiring re-authentication or session reset.
Impact
Per-user denial of service. Recoverable, but disruptive and a friction point for legitimate players.
Recommendation
Make session and game-state transitions idempotent. Detect and gracefully handle out-of-order requests with explicit server-side validation. Add a session-recovery endpoint so the client can re-sync without forcing the user to reauthenticate.
Dedprz: Acknowledged. Zealynx: Acknowledged.