Since I largely program in C#, I typically define the unique ids on my classes as enums. Enums in C# are open, not closed, so you can define something like a UserId like so:
public enum UserId { Unset = 0; }
public class User
{
public UserId Id {get;set;}
}
This works with various ORM and other mapping tools since enums are ints underneath, but you get static checking.Then there's the issue of protection when passing around ids in web apps as parameters, in cookies, etc. I devised Clavis [1] as an experiment for protecting URL parameters via an HMAC. The idea works pretty well in practice, but it's current incarnation is a little too cumbersome to use.
[1] A url http://foo.com?userId=1234 becomes http://foo.com?-userId=1234&clavis=asdbwef67t34rfbs, where the 'clavis' parameter is an HMAC of the URL's protected parameters, and changing any of them causes the request to fail. Unprotected parameters are also supported, so GET form submissions are still possible. See: http://higherlogics.blogspot.ca/2014/01/clavis-rebooted-secu...