This is a clarification question: I’m studying for MCTS 70-515 and in my training kit it states that Hidden Fields: “users can view or modify data stored in hidden fields”
Now I’m aware that users can view the source of the page and then that would display the hidden field data. But I’m curious as to the modification part. How would a user modify a hidden field data and how would it affect the site? Even if they modify the data via View Source they can’t save the page and then post the data back to the server.
What am I missing that the author is assuming I know?
OK well all the answers said the same thing (at this time). I guess if the author would of said “savvy” user then that might of tipped me off. I guess I’ve always assumed that users wouldn’t know of Firebug or any other tool that can do manipulation after the page has been displayed to the user.
Thank you for all your answers. I appreciate it!
The hidden field is
just a key-value-pairrepresented as a key-value-pair when serialized and sent to the server, just like any other form element. There are a number of ways to modify hidden fields – one is to use FireBug or some other “developer console” in the browser, another is to manually write the request and send it to the server.