posted 11 years ago
JavaScript files run on the client, therefore the client has to be supplied with copies of them, therefore they MUST be downloadable. Q.E.D.
You're also providing yet another example of why people shouldn't try to invent their own security systems. Security is NOT an "All You Have To Do Is..." operation. It's complex, it's difficult, it requires a lot of knowledge, and even professionally-designed systems periodically turn up exploitable. Most "clever amateur" systems can't stand 5 minutes in the sun. So we recommend that you learn to use the existing frameworks and channels rather than try and invent something.
Sometimes the only way things ever got fixed is because people became uncomfortable.