Jump to content
View in the app

A better way to browse. Learn more.

FMForums.com

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

I've build a web site using FileMaker as the back end and FX.php as the class to access the FileMaker data. I've got it working but it's insecure. For instance, there's a link for editing a record that looks like this:

Edit

This results in a URL that includes the entry ID, which means that anyone can simply enter the URL and be able to edit that entry.

This would seem to be a problem that someone else has solved. I've been thinking that perhaps the user of PHP sessions is the answer. When the user logs in successfully, I store a session variable with the account id. If the session variable exists, then I check the entry's account ID against the session account ID and continue only if they are the same.

However, any other suggestions would be appreciated.

Thanks,

Chuck

Sessions seems to be the way to go.

You could use Forms to hide parameters from the URL. However, it is only slightly more secure.

All the best.

Garry

I second Garry on the use of SESSIONS.

You can keep a lot of information about the user in the session and save going back to the database for additional queries.

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.