I treat every external callback as a transaction that may never arrive successfully.
My review question is not only “what happens when the callback succeeds?” It is:
• What state was committed before it?
• What can make it revert?
• Who can recover, after what delay?
• Can recovery race with a late callback?
Async security lives in the transitions between transactions, not only inside each function.