PDA

View Full Version : Grid Id hidden but the users can see if they want



yeya
10 Dec 2007, 8:29 AM
Hello,

i have a edit grid, in my column model i use like id a real ID from my database (this is for some quick porpoise and to avoid some possibility errors), this column is hidden, well my grid works fine, but you can activate this column with the right click and select to show or selected the whole grid and copy to excel, and "boala" the column id appears, I wonder if there is a way that the user really can't see some columns but the programmer can used.?

I appreciate any help.

SeaSharp2
10 Dec 2007, 9:08 AM
Leave the database id as a declared record field but don't map this field into the column model. However the data is exposed to anyone with a browser debugging tool, remember there is no security through obscurity.

Best use some server-side validation to ensure people can only perform legit database operations using a valid database key value.