Win a copy of Programmer's Guide to Java SE 8 Oracle Certified Associate (OCA) this week in the OCAJP forum!
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic

Avoiding param in URL when action-redirect....

 
anand kumarblr
Greenhorn
Posts: 27
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
I have a mapping like this.
<result name="input" type="redirectAction" >
<param name="actionName">dispAcctTypePage</param>
<param name="accBean.zipCode">${accBean.zipCode}</param>
</result>

But the param come in url which is a security risk. please help how to eliminate param in browser URL.
 
David Newton
Author
Rancher
Posts: 12617
IntelliJ IDE Ruby
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Don't pass it as a parameter.

If you *are* going to pass it as a parameter and don't want the user to recognize it then you'll need to encrypt it.

The last I heard zip codes aren't exactly secret, though, and I've never really run across a case where a zip code needs to be secret.
 
anand kumarblr
Greenhorn
Posts: 27
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Thanks for your reply.
I am using Actionredirect because i need to show some prepopulated values in select box in input page.....

If i must not pass as parameter then how could i pass values from one action to another action.
Actually iam using MessageStoreInterceptor to remember the validation messages, but to remeber field values iam passing the param like i shown before. i have many paameters... i dont want user to see that in his URL.
 
Don't get me started about those stupid light bulbs.
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic