What is a better approach to protecting and validating URL parameters?

Encrypt URL parameter values then decrypt them when the need to use them
arises?

OR

Check to make sure the variable and its value are legitimate for a user by
querying the data store or cross checking?

OR

Both
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to