Php Id 1 Shopping !link! Official
Never use logic based on ID numbers. Use role-based access control (RBAC) with database flags (e.g., is_admin = 1 ) instead of user_id = 1 .
This is a very basic shopping cart system and there are many ways to improve it, such as: php id 1 shopping
Instead of exposing order_id=42 , expose a random token: Never use logic based on ID numbers
The fix? The developer replaced all $_GET['id'] with prepared statements and implemented UUIDs. The hack became impossible. such as: Instead of exposing order_id=42
: The php?id= part of the string refers to a dynamic PHP page where a "product ID" is passed through the URL (a GET parameter).