You might not use foreign keys, but still have autoincremented primary key.
Database ids on the URL are also a security concern.
You might not use foreign keys, but still have autoincremented primary key.
Database ids on the URL are also a security concern.
They shouldnt be. Users should only be allowed access to their own records, even if they know the id's of records belonging to other users.
What performance cost there is (and in my experience it is not much) is because a UUID is twice as large as a bigint. And there are situations where that matters. But not that many of them.
postgres[7878][1]=# SELECT amname, pg_indexam_has_property(oid, 'can_unique') FROM pg_am WHERE amtype = 'i';
┌────────┬─────────────────────────┐
│ amname │ pg_indexam_has_property │
├────────┼─────────────────────────┤
│ btree │ t │
│ hash │ f │
│ gist │ f │
│ gin │ f │
│ spgist │ f │
│ brin │ f │
└────────┴─────────────────────────┘
(6 rows)
And postgres' btree indexes definitely are affected by the randomness in many UUID generation schemes.Looks like I have a conversation to have. Thanks. :)
Yes, in fact - even then. There are fascinating historical stories about lay-people who scoffed and then failed to account for the dark art of statistics. https://www.statisticshowto.datasciencecentral.com/german-ta...
That sounds like they wanted to migrate to another cluster, and wanted to have both clusters running at the same time (for testing) without risking an ID overlap, so they turned the least significant bit of the ID into a cluster identifier. The older cluster was 0 (even numbers), the new cluster was 1 (odd numbers).
More so than in mark up? If so why?
Should surrogate keys never be exposed to users in any form? Then what's the alternative? Nonces for everything, all the time?
Easy to enumerate, if that's a concern.
1. Mutable data (looks nice but can change)
2. Incrementing data (looks nice but can be guessed and measured)
3. Random looking data (immutable and unguessable but ugly)
Guids aren't the only option for 3 and some of the others may not look as bad, but it still seems the safest option. Any other compelling reasons to not use guids?