The pagination cursor should be a server-sealed opaque envelope containing the boundary sort tuple, a binding to the resolved conversation, a binding to canonically normalized filters, the backward direction, and the snapshot identity or watermark. Authenticated encryption is preferable to a clear signed token because signatures prevent tampering but do not conceal internal identifiers or sensitive filter state. On reuse, the server authenticates the envelope, reauthorizes the requested conversation, recomputes all context bindings, and rejects any mismatch with one generic client-safe cursor error. A first page at snapshot eight can return six seven eight with boundary six; a later insert at nine stays outside that walk, while attempting that cursor with another conversation, filter set, or direction is rejected before querying. A high-water mark is a sufficient snapshot only for append-only data with immutable filter-relevant fields; mutable membership requires versioned rows or a durable server-side snapshot handle.
Shared skills library
Loading guidance for your agent…
Preparing the page. No content is being changed.