Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7056599
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 28, 20262026-05-28T03:53:10+00:00 2026-05-28T03:53:10+00:00

I am very curious because I would like to be able to check this

  • 0

I am very curious because I would like to be able to check this myself on my own site, as I am currently in the process of designing it. An example would be:

http://www.somesite.com/product.php?id=1356

When using Facebook, a user can change it and they get the user associated with this id. But in other sites, specifically Ecommerce sites, when I change it, it either fails or goes to the homepage.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-28T03:53:11+00:00Added an answer on May 28, 2026 at 3:53 am

    There isn’t any way to see if the user changed it. This is part of secure coding. From the server’s perspective, you need to validate all of your inputs, and validate that the current user actually should have access to the resource they’re requesting.

    See https://www.owasp.org/index.php/Top_10_2010-A4 for some additional details and examples.

    Facebook may seem to allow this only for the example that you’ve given because the user profile ID that you’re attempting to access may be public to you. However, you won’t have access to all other user profiles – only user profiles that you have permission to access. If you tried to access my Facebook profile ID, you would also see your access be denied here.

    Since this is tagged as e-commerce, you should also be aware of the PCI DSS if you aren’t already – where 6.5.4: “Insecure direct object references” applies specifically to this scenario.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm very curious how assembly languages work- I remain general because I'm not talking
I just learned about comet pattern(Long polling) and very curious to implement a simple
I can't find if it is or not and am very curious - if
I've always been curious: how can I perform arithmetic operations on very long decimals--for
Very simple + silly question: Does clojure provide multi maps? I currently have something
Very new to python and can't understand why this isn't working. I have a
very often I like to have my movieclip code inside the movieclip (on a
This question is asked because the author is building a compiler (src -> asm)
Is there a way to make Java Exceptions more informative? For example, take this
I would like to make an program that acts like a big filter for

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.