Basic functionality Web - Security Question

Hi all

Assuming the following:

-you use in your digital data series ID's

-with php, you make a search query to get a number of points-, and then you view the results in a loop in a list of web page view.

- then on each line, you change a button for that item. Here, the link is something like: editpage.php? id = <? PHP echo $record-> getField ('item_id');? >

-now, when you click on the edit page - it will make another query to get all the details of the order of the day and view a change form - etc.

Problem: in this case - anyone can simply change the url = xxx to any other number id and it will search from the page of another record.

Q: HOW can lock us this in order to avoid the above scenario and it is a more secure system?

BTW: A method that we can use is to have a second field as a random body of numbers in the table data - search for the two--where people will have a hard time to guess like this link: editpage.php? id = <? PHP echo $record-> getField ('item_id');? > & random = <? PHP echo $record-> getField('randomnum);? >

even if we did not use of $_GET ['id'] and saved as cookie instead - a user could still change that too...

THE BEST SUGGESTIONS to lock things?

You should always check whether the user has the appropriate permissions editing. So, on your editing page, make a request before allowing first has an editing tool. Of course, the same is true for insert and delete.

Tags: Dreamweaver

Similar Questions

Maybe you are looking for

  • Download flash player 10.2 for 2 hours until normal now?

    I just download firefox 4 beta this morning. Went to POGO and the screen says to download the plug-ins which led me to install Adobe Flash Player 10.2. Have been installing for over two hours now. I'm doing something wrong? I'm afraid to hit exit and

  • Sat Pro L10 - loss of display Num/Caps Lock indicators and Volume level

    I have a few problems at the moment... First of all, some time ago, the volume level display (a green light that came on the screen) disappeared. I got said that his was due to an update that had to be done, but who for some reason any got rid of the

  • Genius traffic meter

    R7000Latest FirmwareIPhone 5 s Since none of my computers could connect to the router admin I installed genius on my iPhone. I have configured the counter to traffic and it is not monitoring anything. I got the instructions from the NG site and did w

  • What graphics card to HPE d 498

    PC: HP Pavilion Elite HPE desktop computer - 498d http://support.HP.com/us-en/document/c02542167 OS: Windows 7, 64 bit Question: Want to change the graphics card Why? Crash with floating point test and FarCry 3 game, doesn't crash with games cs and G

  • Bytes of TCP IP and subset of bytes for the connection of server and clients

    Hello I have a problem on the server and the client connection using the TCP/IP protocol. In the client, I have 41 cases, 1 case of timeout, others are for the case of button when they are pressed and then the LED on the server will be to market and