Re: Form Design Advice

From: Geoffrey <esoteric(at)3times25(dot)net>
To: pgsql-novice(at)postgresql(dot)org
Subject: Re: Form Design Advice
Date: 2005-03-04 17:35:11
Message-ID: 42289C4F.5000501@3times25.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-novice

Colin McGuigan wrote:
> Ross Gohlke wrote:
> > I'm not sure I understand. How could a user send incorrect data types if
> > the types are included as hidden fields? Since the variables are
> > declared as coming from $_POST, they cannot send anything in the URL.
>
> Nothing stops anyone from copying the "View Source" of a webpage to a
> local file, modifying it as they wish, and then pointing their web
> browser at the local file and submitting from that.

Correct and another point to understand is that 'hidden' fields are not
hidden.

--
Until later, Geoffrey

In response to

Browse pgsql-novice by date

  From Date Subject
Next Message Bruno Wolff III 2005-03-04 18:01:48 Re: Form Design Advice
Previous Message Ross Gohlke 2005-03-04 17:00:24 Re: Form Design Advice