recordID= url protection (php / Mysql)
(I'm using Php / MySql / DWCS3)
My website allows clients to log in with their own username and password to view their personal records - and NOT anyone else's.
I achieved ths buy creating a query in MySql and using it as a recordset in Dreamweaver.
This works fine, but I found out that you can log in as 'Client A' and see all your records, but you can manually edit the recordID number in the URL to see other clients records!
How can I prevent users from editing the URL?
Can I encrypt it perhaps?
Thanks!
