javascript - How to prevent .load() from browser console? -


i want content of website dynamically loaded after login. $.post(...) interacts servlet validates user's credentials, , $.load(url) loads content separate page <div>. noticed that, long know fetch content from, can force behavior chrome javascript console, bypassing validation.

how can prevent user doing this?

you can't.

once document has been delivered user's browser under control of user. can run js like.

the urls present on webserver public interface it. can request them. can use authentication/authorization limit gets response, can't make response conditional on user running specific javascript supply.

the server needs authorize user each time delivers restricted data. can't once , trust browser enforce it.


Comments

Popular posts from this blog

javascript - Slick Slider width recalculation -

jsf - PrimeFaces Datatable - What is f:facet actually doing? -

angular2 services - Angular 2 RC 4 Http post not firing -