Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8268585
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 8, 20262026-06-08T05:56:26+00:00 2026-06-08T05:56:26+00:00

For example: Server side is Asp.net MVC, Client side is KnockoutJS. From a security

  • 0

For example:
Server side is Asp.net MVC,
Client side is KnockoutJS.

From a security and standards perspective:
Is it acceptable for the server to output an edit link and the client side code then set the visibility of the control based on javascript viewmodel property such as “HasEditPermission”?

Or should the MVC Razor syntax selectively output the controls based on the viewmodel?

Traditionally this would all be done server side, however with most databinding now occurring on the client it is mixing concerns by having conditional logic in Razor and KnockoutJS.

It goes without saying that the server validates all postbacks based on permissions, so escalation of privileges is not possible. Its also fair to point out that the concept of “Obscurity is not security” does come into play here. Just because an edit link does not exist does not mean that it isn’t obvious for an attacker to attempt yourwebsite/users/edit/1

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-08T05:56:28+00:00Added an answer on June 8, 2026 at 5:56 am

    My pragmatic take on this is that if you can output conditional Knockout view models and data binding expressions etc via Razor at page generation time in a fairly clean way without too many hacks and design tradeoffs, then do so. But so long as you are not stashing security related data in your Javascript or the DOM (passwords, secret tokens etc) then I wouldn’t lose too much sleep over using client side logic to decide whether to make something like an Edit link visible or not. As you say, anyone can modify an existing URL which they have been given rightful access to anyway – which is why the resource itself does the appropriate checks when requested.

    Often with a Knockout style UI you might make certain links / buttons available based on dynamic client side conditions anyway – and the distinction between what is an actual “security breach” and what is someone cheekily exposing insufficient server guard code and buggering up your application logic by hacking things with Firebug becomes a bit blurred. I would say do what’s sensible and is in proportion to the risks / stakes of your specific business context.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have an ASP.NET application which features some server-side includes. For example: <!--#include virtual=/scripts.inc
I'm trying to integrate NHibernate.Validator with ASP.NET MVC client side validations, and the only
Is it available to open jquery Dialog Server Side From Behind Code in asp.net?
Example scenario in an ASP.NET application using SQL Server membership provider : 1) a
I am trying to figure out how to do a server ASP.NET MVC Image
I plan to use XMLHttpRequest post text/string to server from client side. I need
I know how to use client side JavaScript with asp.net script. But I am
I'm writing an asp.net server side control which has a few short parameters passed
ASP.NET server controls has a few categories, for example, normal ones e.g. TextBox, Button
I have an ASP.NET webpage that displays steps that must be performed server side.

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.