> For good security, you don't leak internal IDs at all, sure. It is rare to find people doing that.
We must live in a different universe. I'd wager to say that over 90% of all backends leak their primary key when speaking to the front-facing client.