Quote:
Originally Posted by cbkbud
If you're that paranoid, encode it ... but why?
If someone wants to they can delete the whole server with access to a single level. base64encode would be incredibly easy to break anyway.
Just don't give any staff edit attributes.
|
That was not the problem. Anyone with access to a single test level can edit clientr flags if they are not encoded. Not everyone with a single test level has access to delete the entire server. It has nothing to do with edit attributes.
Callstacks also solve this problem, but back then callstack access was not available.
Also, there are ways to use base64encode that are more difficult to break then simply saying var = base64encode(var).