Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not frowned upon, but it would require tighter coupling between the controller and the view...?


Yes, that makes sense. If your view's form should only update the user's name, then the logic that handles that form submission should only update the user's name. Allowing the client to inject other attributes (even allowed/whitelisted ones) could potentially break other app logic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: