Editor > Selected columns only : Security sufficient to protect against tampering?
Editor > Selected columns only : Security sufficient to protect against tampering?
data:image/s3,"s3://crabby-images/7643f/7643f44fe1f166c043d53d18cb827a39273592ef" alt="andrewmoir"
Dear All,
I want the customer to only be allowed to edit columns : First name, Last name, Salary in the following example :
https://editor.datatables.net/examples/inline-editing/columns.html
This is done in this manner : { data: 'first_name', className: 'editable' },
Is this secure against abuse? Can someone abuse this to allow them to edit say another column ("Position")?
Shouldn't I be trying to prevent any acceptance or validation on the "Position" column in the server side script? ( Field::inst( 'position' ), )
Or is the javascript alone sufficient?
Kind regards Andrew
This question has an accepted answers - jump to answer
Answers
Hi Andrew,
The
Field::inst()
is by default read / write. Use:to disallow writing to it.
Allan