Reading the sheet…
Reading the sheet…
The default service load for new trials in this session, and exactly what this deployment is running. There are no accounts and no API keys: ownership is an anonymous cookie in this browser.
New trials in this session start at this load. A trial records the load it was saved at, so moving this default never rewrites an existing grade.
Server version reported as 17.11 (fcae950).
Ownership. An unguessable 128-bit owner id is set in an HTTP-only cookie before any render. Every query is scoped to it, so one visitor cannot read or mutate another visitor’s trials. Ownership is per browser, so clearing cookies starts a new empty estate.
Destructive operations. A tombstone requires the record’s current seal, which is only readable by someone who can already read the record. A stale link cannot delete a trial.
Abuse controls. Writes are throttled per owner. On a serverless runtime that counter is per instance and therefore a hint rather than a guarantee; the real limits are the bounded list sizes, the input size caps and the database constraints. A deployment that needs a hard global limit should put a rate limiter in front of the routes.
Input. Every external string is bounded before it reaches the engine or the database, every query is parameterised, and error responses carry a stable code and message rather than a stack trace.