Title Query Strings Eliminated From URL
Overview: I want to eliminate the opportunity for my logged in customers from seeing or "tinkering" with the URL Query Strings while viewing their invoices.
My Language: Classic ASP VB Script, Database: MS SQL Server, Software Tool: Dreamweaver CS4
Website: [url removed, login to view]
Temporary Login: emailtest
Temporary Password: abc
Invoice Page is located: [url removed, login to view]
These are testing accounts & invoices so I welcome you to login and see it so you can make an evaluation for yourself. Login, Accounts, Order History, Select any ordernumber.
With this example of invoice number 137428387... changing the number to 137428394 will produce an invoice from a different customer (without logging in as the other customer).
The privacy of other peoples information can be obtained from the quizitive customer logged into their account.
Goal: Query Strings (that represent order numbers) Eliminated From URL's while customers can still view their invoices by selecting an order number at the Order History page.
Observation: I assume that this webpage may need to call up the invoices through sessions variables rather than current URL parameters
This Project Deadline: June 10, 2009
32 freelanceria on tarjonnut keskimäärin 78 $ tähän työhön
An experienced web and application programmer having more than seven years of development experience. I can easily do it. Let me know further details. Thanks