idpSteve wroteInteresting..
@[deleted] : Would having separators then be less 'safe' than showing fields on a form and just having a user ignore them? I'm not sure if you're saying someone would be able to add data to a field hidden in a separator, or if you're saying using a separator is an added risk that doesn't exist on a form without separators.
Using hidden fields via CSS is moving the control from server side to client side. The use of separators is not risking in and of itself, but the use of css hide to take the separator away creates (potential) risk.
In your example create a staff record via the UI. Then go to the database table and manually add data to another field that should remain hidden. Then return to your UI, view the record youâve just modified and then open up the developer console. That âhiddenâ data will be served to the browser. Then change the hidden value (via the console). Now save.
Obviously in the example we are talking about we are hiding the field to guide the user to complete fields, but if we were using hide as a means of preventing one user from seeing data that should be available to another then this route has risk.