Clicked a bit too quick. Why are you letting users delete records in the
first place? That's an admin job...

On 4/23/06, Pete <[EMAIL PROTECTED]> wrote:
>
> In message <[EMAIL PROTECTED]>
> , Gerry Danen <[EMAIL PROTECTED]> writes
>
> >in the script where you show the delete link, you have to know the record
> >number. then include as part of the link delete.php
> ?entry=<?=$recordnumber?>
> >
> >in delete.php, use $_GET["entry"]
> >
> >Gerry
> >http://dev.danen.org/
>
> If you do that, then users can see the record number in the URL.  If
> they change the URL, then they will be able to delete all the records
> one by one...
>


--
Gerry
http://dev.danen.org/


[Non-text portions of this message have been removed]



The php_mysql group is dedicated to learn more about the PHP/MySQL web database possibilities through group learning.



SPONSORED LINKS
American general life and accident insurance company American general life insurance company American general life
American general mortgage American general life insurance Computer internet security


YAHOO! GROUPS LINKS




Reply via email to