Plus, there's a lot of cases where the server sends some pieces of information to the client but the user isn't supposed to see it. The locations of the other players is a common example, where people modify their client to render outlines of players through walls. That's a huge advantage but doesn't even affect anything hit registration related.
Iirc, Warzone also sends information about non-existing players to suspected cheaters to attempt detecting aimbots.
Not just that, you can even chuck a flashbang/grenade far outside your visibility range and get someone this way too.
- https://technology.riotgames.com/news/demolishing-wallhacks-...
- https://technology.riotgames.com/news/peeking-valorants-netc...
Why does server-authoritative backwards reconciliation require trusting the client not to lie? The server keeps a history of the past N states and client claims to hits are verified by the server using that history. A client could lie and say it made a hit in one of those prior states (but not an state the client invented whole cloth.) But if the client is doing that then from the server's perspective that player is lagging and backwards reconciliation makes lagging players easier for other players to hit.
Obviously if you're doing client-authoritative unlagging then you need anticheat, but AFAIK competitive shooters have used server authoritative backwards reconciliation ever since the early 00s.
Not that this really matters. If you think that you could do favor the shooter style hit registration in a completely server authoritative way, we can just use wall hacks or aim bots as an example instead.
Why? Because even if software doing this is legitimate it's can still be used by actual cheaters by patching it.