# Records and online support

Local records always work. Optional accounts and server-validated leaderboards are now implemented; see [online setup and validation](ONLINE.md) for deployment requirements and evidence. The notes below describe the local boundary and integrity requirements.

The three stable course IDs are `surf_boreas`, `surf_utopia_njv`, and
`surf_mesa_fixed`. Each course has a geometry/timing version. Records and replays
also carry the full movement configuration, including tick interval, auto-bhop,
start rules, and map-specific velocity limit. A map or movement change therefore
does not silently compete against an incompatible local personal best. Graphics,
audio, and the last-selected map are preferences, not record categories.

Ranked play now uses capped starts. Unrestricted start speed is an explicit
unranked local category; its old records cannot be submitted or relabelled as
capped-start times. Eligible guests can finish first, then sign in from the result
screen to save that run. A signed guest ticket must have been prepared before the
first command; login alone cannot make an unprepared or assisted run eligible.
The completed command replay is kept in this browser through login, then claimed
by the account and independently verified on the server. Sign in within 24 hours
of ticket issuance. Local personal bests remain available without an account.

New local best entries include `mapId`, `mapVersion`, `physicsConfig`, elapsed
time, ordered splits, and date. Existing Boreas storage keys remain compatible.
The local key's compact hash is only a storage convenience; it must not become
the sole identity or an integrity check for an online record.

`GameSession` owns authoritative simulation events and command recording without
depending on the renderer or DOM. A replay contains a declared initial state and
tick-indexed movement/buttons/view angles. It can be replayed in a server process
using the same map and configuration. Normal records are separate from practice,
restores, demonstration playback, focus/pause interruptions, and changed rules.

Online support authenticates the player and validates each submitted
replay on the server against pinned geometry/configuration and permitted initial
states. Derive elapsed time and checkpoint order there; do not trust browser
times, positions, local storage, or its `practice` flag. Store the complete
version identity and the replay digest with the result. A leaderboard can then
partition by map revision and movement rules while sharing the existing map
catalog and simulation. Migrated local times should be clearly marked unverified
unless their original command replays can be validated.

The imported maps/assets retain their original owners' rights. Check hosting and
redistribution permission before a public service release; this local build does
not confer those rights.
