All projects

Backend & security

.NET Game Server

Research prototype

An authoritative multiplayer backend that became a practical study in translating a distrust-the-client security model into working software.

The project

The Game Server began as an exercise in designing a multiplayer backend from an intentionally distrustful starting point: a client should be able to request a change, but it should not be treated as the authority that decides what becomes server truth. The early architecture decomposed the system around that assumption, separating user data, competitive scores, leaderboards, session logs, administrative data, and enforcement state while defining different read and mutation boundaries for players, administrators, and the server itself.

That architecture progressed into a substantial ASP.NET Core implementation backed by Entity Framework Core and SQL Server. The server added HTTP authentication, device-scoped refresh sessions, WebSocket gameplay sessions, modular game handlers, leaderboards, player data, a cosmetic economy, server-side scoring state, object lifecycle records, position history, and session telemetry. A later security review then tested the implementation against the project's own trust assumptions and exposed important places where the prototype violated them, turning the project into both a backend implementation and a concrete study in the difference between designing a security boundary and consistently enforcing it in code.