We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25551 ☆ A M B ☆
    • 1,231 Posts
    Hey folks, I’m creating a fairly simple ticket system on one of my sites and I have most of it done. My question is how can I best hide variables in the URL so someone can’t see another’s tickets?

    An example of the URL is mysite.com/tickets&id=22&ticket=10

    Now I don’t want a user to simply change the URL to match their ID or another’s so they can look at them. What is the best practise for this scenario?
      Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
      AugmentBLU - MODX Partner

      BLUcart - MODX Revolution E-Commerce & Shopping Cart
      • 9130
      • 171 Posts
      It really depends on your usage scenario, How secure does this have to be? How does the user get this url in the first place? Is it sent to him by email? Does it appear on a page in your website?

      The best way is to have the user sign-in first and on each page check if he is allowed to view the item requested through the variables.

      The next best option involves cryptography, use some combination of encrypting the variables and signing (hashing) them to create the url. This will make the variables harder to read and impossible to modify without you being able to detect it.

      The least secure option is just by passing the variables through a http POST instead of a GET so the user does not see them. This is obviously the least secure method as anyone with basic web skills can easily view all the pages.
        • 4310
        • 2,310 Posts
        Ross, whilst looking for something else I found Secure-URL a PHP Class for encoding querystring parameters.
        Haven’t tried it but it could be worth a look smiley
          • 28215
          • 4,149 Posts
          You could always base64_encode them, and then base64_decode them in your snippet.
            shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
            • 10487 MODX Staff
            • 1,535 Posts
            My question is how can I best hide variables in the URL so someone can’t see another’s tickets?
            The best way I’ve found to solve this issue is to explicitly check user permissions on the ticket before you display it. I’m assuming that the users are logged in somehow (e.g. webusers) and that each ticket is attached to a user ID for that to work.

            EDIT: Is the ID in the querystring mentioned in the original post the user ID? If that was me, I’d ditch that. Enforce a login to view tickets and use the SESSION to store the user details. Just a thought wink
              Garry Nutting
              Senior Developer
              MODX, LLC

              Email: [email protected]
              Twitter: @garryn
              Web: modx.com
              • 25551 ☆ A M B ☆
              • 1,231 Posts
              I went with SESSION... seems to work. I logged in as 2 different users and changed the URL string manually and it’s not outputting each other’s tickets so I’m hoping this is the right track.

              Thanks for the suggestions.
                Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
                AugmentBLU - MODX Partner

                BLUcart - MODX Revolution E-Commerce & Shopping Cart