API url security

Completely agree :slight_smile:

A very good example why numeric IDs must not be used by default :slight_smile:

Once they are used by default, by all frameworks in all programming languages, it’s easy to get in the trap of building an application with them without realizing the consequences, until you have problems, like yours.

A good example of how your brand image can be affected and you would not have any control of how to stop it.