A public forum for discussing the design of software, from the user interface to the code architecture. Now closed.
I'm hoping someone here can answer a question for me. I've searched all over and can't seem to find any info.
Depending on what is being done on an admin page, there may be no buttons or up to 4 to perform various actions.
And remember. Never trust your remote browser! Validate every input, authorize every action if the logged user has appropriate permissions to do it.
Just the button hiding is not sufficient, because the http request faking is so easy...
Thursday, April 14, 2005
This topic is archived. No further replies will be accepted.Other recent topics
Powered by FogBugz