Re: Hiding the query string in ASP.NET
Adam Tuliper <[email protected]>
| Newsgroups | gmane.comp.windows.devel.dotnet.advanced |
|---|---|
| Message-ID | <[email protected]> |
use a querystring encryption class that then base64 encodes the result if you must do it this way.. as there is no hiding mechanism Im aware of. if there was.. you'd achieve no different security than a simple encryption as a user could just use fiddler to intercept and change the request. or secondly.. if possible.. restrict results to the current user. IE if the user is authenticated make sure only they have access to that range of data.. or.... generate a key that is based off of their login name. their 'link' is based off their login id and if they arent who they say they are then the decryption wont work. there are all sorts of little variations on these themes that can help. If this is a totally anonymous way without login.. then I would suggest using a different ID.. IE a GUID for a key so it cant reasonably be guessed. On Wed, Nov 5, 2008 at 2:16 PM, Clark, Michael (OFM) < [email protected]> wrote: > This may or may not be a .NET related question, but I really don't know > for sure, so... > > In our application we pass some data from one page to another using > other user cookies (not browser cookies), and we also have been passing > some information via the querystring. For example, a reimbursement > request id appearing in the querystring as > > ViewReimbursementRequest.aspx?request_id=324 > > Well, this works great except that if a user happens to know the > reimbursement request number of a request belonging to another user, he > could edit the query string to be able to look at that request. We > would like to limit this capability, and I recall having heard there was > a way to suppress the querystring part after the page name, and still be > able to pass the querystring. I'm not talking about using POST, or > about embedding the relevant data as a cookie, or in a session variable. > I remember hearing about this capability in a presentation I heard about > eight or nine years ago, as a new capability of Windows Server 2000 or > NT. But I don't know if it was a server option or setting or something > that could be set within an application. > > =================================== > View archives and manage your subscription(s) at > http://peach.ease.lsoft.com/archives > =================================== View archives and manage your subscription(s) at http://peach.ease.lsoft.com/archives