Transcript
Hello, friends. So here I have a basic application and let me create another organization. Let's name it a fourth organization, create organization. And you see, I see the idea of this new organization. And this is, uh, considered not a good security practice to have your ID visible in the URLs or if you like, uh, hover on, uh, a link. You say, go to inspect. And I see the idea of this resource because, uh, a competitor can, uh, know how many organizations I have in total. And you can check a month from now and see what is the growth rate of my application. So, uh, this is the most simple example why I would want to hide ideas from, uh, your URLs and your markup. Now, uh, there are a few different ways to hide ideas. Uh, the most simple way is, uh, to use friendly id. I love this gym. I use it in many of my applications. But, uh, I don't want to add the, uh, slug attribute to all my models and, uh, update them based on the name, based on another attribute of the model. Then there is SL Fire Bill by Ramis, but the gem also, uh, requires adding a slug migration to all the models, and I don't want this. Then there's this hash I rails gem, but it hasn't been updated in five years. And this gem, uh, does not, uh, require you to, uh, add, uh, additional SL attribute to the model. Uh, but, uh, the finders, uh, don't work outta the box. So you need to update the finders, uh, all around the application to use hash, uh, this find by hash id. Then there is this Id jam that is very nice, but, uh, again, it does not, uh, uh, support, uh, the default rails find method. So you would need to use, uh, article, uh, uh, find the, instead of article do find all around your application. And I want to just, uh, drop in solution that works, uh, out the box when you just add it to the application and you can, uh, obfuscate all the ideas around the application. Then there is this prefixed ideas jam by, uh, uh, excite and, uh, it's an G. But, uh, the ideas that are generated can get, uh, really long and also not all find the methods, uh, work, uh, out the box. So you would need to use, uh, find by prefix ID in some places instead of just using, uh, find and, uh, while exploring bullet train. Uh, it's an, uh, open source, uh, boilerplate. I notice their id. You see, uh, I'm like, uh, navigating different resources. And here is, uh, an example of an obfuscated, uh, uh, hashtag ID of the restore. So if I like hover anywhere, you see, uh, I will have this, uh, obfuscated ID and not the real ID of the record. And looking into the source code of, uh, bull chain, that's actually open source, I highly recommend you to, uh, have a look at it. Uh, I found that this obfuscated IDs in bull chain are defined, so they have this concern, obfuscated the id. Uh, let's try adding this, uh, concern to our application and see if, uh, it can be a drop in solution to obfuscate, to hide our ideas in our application. All, uh, advanced with minimal installation. So, uh, I will go to my, uh, models. Mm. And, uh, in models inside concerns. I will create this, uh, uh, obfuscates id, uh, file. I will, uh, copy it from, uh, bullet chain. I will also add a source like attribution where I took it, um, extract it from, uh, uh, bullet chain. Okay, we have this obfuscates id. So, uh, it, uh, will need the hash id. We will also need to install this jam. Now you see it over as the find there has many finders, uh, and we'll be able to use, uh, uh, to pre to see the hash, the id, the obfuscated ID of the record. So let's, uh, uh, study rails console and, uh, let's say organization First and organization 0.2 per, uh, now this, uh, just says the ID 12, but, uh, we want to use obfuscated id. So we would need to add this obfuscated ID to our application record. So here I will say, include, uh, obfuscates id. Now I will restart the rails console. Uh, define the organization, organization to parm. I have this error. Hash ID is new, so I need to, uh, add, uh, hash IDs. I will add the gem to the gem file, gem, uh, hash IDs bundle bin. Uh, yeah, no need to run dev. Let's first try in the console, uh, defining the organization. Organization do two parm. And you see, instead of the ID previously we had the id. Here we have this, uh, hashed id. So if I start the server, Let's go to our application. I refresh, uh, search by Id still works. Uh, but if I go to an organization, you see, I don't have the ID here anymore. I have the, uh, obfuscated, the hidden id. If I go to projects, I go to show a project. You see, the organization ID is hidden and the project ID is hidden. And it is kind of a shop in solution already is, uh, uh, used the obfuscated ID concern from bullet train and, uh, in initialize it in the application record. And I needed the gem hash IDs. So yes, that's basically it. This is the, I think, easiest, uh, most lean way. You can hide the ID of all the records in your application with the just one drop in tiny solution. Thanks for watching.
1