Jump to content

This topic is 8085 days old. Please don't post here. Open a new topic instead.

Recommended Posts

Posted

Am I correct that there is no way to do a -edit URL or Form without including the -RECID for the record you are editing?

If this is the case, considering that the recid is a serial number that developers have no control over, isn't it extremely easy to hack a URL and find data for other users?

Posted

As far as I know, you're right about the -recid being required for -edit but I'm not so certain about the ease of hacking a URL...

(2 minutes later...)

OMG!!! It was easier than I thought... I changed a record's data right through the URL! Of course, I tested it on an unprotected db we're still developing so there's no AP or WSD, but I was till shocked at how easy it was. Ironically, I'm going to use this trick for quick-editing data remotely until we finish the project and initate security. Thanx for the tip/warning/new tool.

Posted

The RecID is a very slippery number: it is not quite a serial number in that the series of numbers that FMP uses is not continuous -- there is a big break in the middle of the sequence of numbers.

This topic is 8085 days old. Please don't post here. Open a new topic instead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.