Skip to content
Back to skills

Server Function Order

ASecurity

A server function is addressed by its place in its file, and only the build guard keeps a tab from another build from calling the wrong one. Applies whenever adding, removing, moving or changing the parameters of a function whose body opens with 'use server', and whenever touching the build guard or anything that calls the server outside `fetch`.

  • 5 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 20, 2026
devopsjavascriptgojava

Works with

  • cli

Security analysis

A100/100

Scanned September 28, 2026

npx -y skills add lxsmnsyc/overwander --skill server-function-order --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Server Function Order?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Server Function Order
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lxsmnsyc-server-function-order/badge)](https://www.skillsdirectory.com/skills/lxsmnsyc-server-function-order)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: server-function-order
description: A server function is addressed by its place in its file, and only the build guard keeps a tab from another build from calling the wrong one. Applies whenever adding, removing, moving or changing the parameters of a function whose body opens with 'use server', and whenever touching the build guard or anything that calls the server outside `fetch`.
---

# Server functions and the build guard

In a production build, SolidStart names every `'use server'` function by its file and its position in that file (`<file hash>-<index>`). The function's name is not part of it.

A tab loaded before a deploy keeps calling those positions, with the arguments its own build sends. When a function moves, that tab would call whatever sits in its slot now. This happened twice before the guard was strict:

- A new parameter at the front of the position save shifted every argument, so a player's chunk X was read as a step count and they were moved to 0,0.
- Three claim-list functions merged into one moved the nest and phenomenon claims up two slots.

## The guard

A tab names its build on every server call (`src/utils/stale-build.ts` wraps `fetch`), and `src/middleware/index.ts` refuses any server call that does not name the live build, before any function runs. The tab reloads on the refusal. A call that names no build is refused too.

Because no call from another build ever reaches a function, server functions may be added, removed, reordered or given new parameters like any other code. A function nothing calls any more is deleted rather than kept for its slot.

## The rules

- **Never weaken the guard.** Letting through a call that names no build, or another build, brings back every hazard above.
- **Every server call goes through `fetch`.** SolidStart's client looks `fetch` up when each call is made, so the wrapper covers it. Anything that reaches `/_server` another way (a `<form action>` posted without JavaScript, `navigator.sendBeacon`, a worker) sends no build header and is refused, so it needs the header added or a different route.
- **The guard must be installed first.** `guardServerCalls()` runs in `src/entry-client.tsx` before the app mounts; a call made before it would be refused.

## Checking a change

For a change to the guard, run `test/utils/build.test.ts` and `test/utils/stale-build.test.ts`. For a new way of calling the server, check in the browser's network panel that the request carries the `X-Build` header.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…