3 ms·
Presumably it is exactly the same as in any other web application--the save method is using an HTTP request under the covers, which must be rejected if the user
by fooandbarify 14y ago
Presumably it is exactly the same as in any other web application--the save method is using an HTTP request under the covers, which must be rejected if the user is not authorized to perform that action.
- jimmar 14y agoI don't think it's just a matter of authorization. I think you would have to use something like anti-forgery tokens to prevent automated scripting of http requests.