Should I expose a user ID to public?

If it were dangerous, Stack Overflow wouldn’t be displaying user IDs in their URLs in order to make user profile lookups work: https://stackoverflow.com/users/104826/rfactor

Edit of seriousness of immense levels: if user IDs are themselves sensitive data; for example your primary keys for some reason happen to be social security numbers, that’ll definitely be a security and privacy liability. If your user IDs are just auto-increment numbers though, you’re clear.

Leave a Comment

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)