@dcon.eth
there's a cool pattern enabled here, where servers can sign their own state data, then check that signature on each subsequent POST, effectively giving you a "verified frame state"
and relevant note to devs: even if you validate a frame action, there's no guarantee that the state wasn't modified before signing