-
☆ A M B ☆
- 1,231 Posts
Hey folks, I’m creating a fairly simple ticket system on one of my sites and I have most of it done. My question is how can I best hide variables in the URL so someone can’t see another’s tickets?
An example of the URL is mysite.com/tickets&id=22&ticket=10
Now I don’t want a user to simply change the URL to match their ID or another’s so they can look at them. What is the best practise for this scenario?
It really depends on your usage scenario, How secure does this have to be? How does the user get this url in the first place? Is it sent to him by email? Does it appear on a page in your website?
The best way is to have the user sign-in first and on each page check if he is allowed to view the item requested through the variables.
The next best option involves cryptography, use some combination of encrypting the variables and signing (hashing) them to create the url. This will make the variables harder to read and impossible to modify without you being able to detect it.
The least secure option is just by passing the variables through a http POST instead of a GET so the user does not see them. This is obviously the least secure method as anyone with basic web skills can easily view all the pages.
You could always base64_encode them, and then base64_decode them in your snippet.
shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect |
github |
splittingred.com
-
☆ A M B ☆
- 1,231 Posts
I went with SESSION... seems to work. I logged in as 2 different users and changed the URL string manually and it’s not outputting each other’s tickets so I’m hoping this is the right track.
Thanks for the suggestions.