top | item 42812656

(no title)

joking | 1 year ago

Thats by design, you can’t trust the client, everything has to be checked server side.

discuss

order

Clent|1 year ago

I think you misunderstand what's being described. The server didn't check it, it accepted the modified hidden field. The server should have rejected the request.