c# - Security of displaying ID's in Hidden fields -
i trying understand proper way handle following scenario. wish learn more acceptable passed on page in terms of security.
lets take tournament scenario. have list of teams signed displayed on page. in order report result of game, have click on team , select win or lose. posted server in return records in database.
the dilemma know team have clicked , game. there many rounds, 1 team can displayed many times. such need have hidden field on page has id of team , id of game can record result.
what wondering is, how secure me create hidden field holds id. there better way handle such scenario? giving out information hacker if print out id in hidden field?
some of answers have found through research "may" ok long authorize request. user reporting score has enough privileges report score. wished ask of experts here @ stackoverflow further support research.
edit:
this web application. if printing out id no go, how else determine team selected round? need have sort of identifier.
if id included when post server, reveal id more holding in hidden field will. can hit f12 in chrome/firefox/ie , see data in post request.
if have user authentication, worry controlling permissions authorized user can do.
Comments
Post a Comment