The order that survived a deploy
A food-delivery assistant builds an order over six tool calls in ten minutes: restaurant, two mains, a drink, an address, a tip. Halfway through, your Kubernetes cluster rolls out a new version and every pod is replaced.
Legacy: the order lived in the old pod's session map. The user hears "Sorry, let's start again."
Now: the first call returned orderId: "ord_7Kq…", stored in a database. The new pods look it up and carry on. Because the handle is visible to the model, the user can switch from phone to laptop and say "add fries to my order", and it still works.
The twist: an attacker notices the handles look like ord_0001, ord_0002… and tries other people's orders. That's state handle hijacking. Unguessable IDs, plus an ownership check on every call, stop it.