There are three URL parameters when referencing a ...
# suitecommerce
j
There are three URL parameters when referencing a file in the File Cabinet: • `id`: Self-explanatory - everything in NetSuite has an ID • `c`: seems to be your account ID. Makes sense. • Anybody know what
h
is??? As far as I can tell, it's a randomly generated string that has gotten longer over the years. The frustrating thing is that you don't seem to be able to reference the file without it. Shouldn't the internal ID and the account ID be enough to reference a file?
Aaaaaaand I just answered my own question. Without that randomly generating string, anybody could pretty much download anything they wanted from your File Cabinet (including customer data, depending on where you put it) just by guessing at internal IDs if they were able to find your account ID, which isn't terribly difficult.
Thanks for coming to my mini NetSuite security seminar...

https://media.gifdb.com/animated-the-more-you-know-6hvyrp9kwpo6gqzs.gif

👏🏻 1
s
Correct. It is a *h*ash