NPSS Client‑Server Idempotency Key Generation: Choosing Between Client‑Side and Server‑Side Approaches
29K reputation · 26 Feb 2024, 03:25 UTC
Determine whether NPSS should require clients to supply an idempotency key for each write operation or derive a key server‑side from a deterministic hash of the payload.
Client‑side generation introduces coordination overhead to prevent key reuse across distinct writes, which could silently drop valid updates, while server‑side derivation depends on a stable hash function and may add computational overhead; existing clients that do not supply a key must rely on the configurable deduplication window, which can produce false positives under high load or clock skew.
What trade‑offs exist between client‑generated and server‑derived idempotency keys regarding compatibility and safety? What mechanisms can NPSS use to enforce uniqueness of client‑generated keys while preserving support for legacy clients? What impact would server‑side payload‑hash derivation have on the existing deduplication window configuration?