Re: Hiding the query string in ASP.NET
Christoffer Skjoldborg <[email protected]>
| Newsgroups | gmane.comp.windows.devel.dotnet.advanced |
|---|---|
| Message-ID | <[email protected]> |
A more secure option would be to hash and/or encrypt the ids used in query strings (or ids present client-side in general). Remember to UrlEncode/Decode as well if you do so. /Chris On Wed, Nov 5, 2008 at 11:16 PM, Clark, Michael (OFM) < [email protected]> wrote: > This may or may not be a .NET related question, but I really don't know > for sure, so... > > In our application we pass some data from one page to another using > other user cookies (not browser cookies), and we also have been passing > some information via the querystring. For example, a reimbursement > request id appearing in the querystring as > > ViewReimbursementRequest.aspx?request_id=324 > > Well, this works great except that if a user happens to know the > reimbursement request number of a request belonging to another user, he > could edit the query string to be able to look at that request. We > would like to limit this capability, and I recall having heard there was > a way to suppress the querystring part after the page name, and still be > able to pass the querystring. I'm not talking about using POST, or > about embedding the relevant data as a cookie, or in a session variable. > I remember hearing about this capability in a presentation I heard about > eight or nine years ago, as a new capability of Windows Server 2000 or > NT. But I don't know if it was a server option or setting or something > that could be set within an application. > > =================================== > View archives and manage your subscription(s) at > http://peach.ease.lsoft.com/archives > =================================== View archives and manage your subscription(s) at http://peach.ease.lsoft.com/archives