> Database ids on the URL are also a security concern.
More so than in mark up? If so why?
Should surrogate keys never be exposed to users in any form? Then what's the alternative? Nonces for everything, all the time?
More so than in mark up? If so why?
Should surrogate keys never be exposed to users in any form? Then what's the alternative? Nonces for everything, all the time?
Easy to enumerate, if that's a concern.