optimistx meinte:
> Assume:
>
> 1) A programmer has written a htlm page with javascript code, which is
> loaded to and executed in client's computer.
>
> 2) The http-server, which is sending the page, does not execute php,
> does not use ajax, does not use passwords, has sql-files (=the most
> typical server serving simple pages to clients). http-get-requests are
> used.
SQL and no PHP (or other server side scripting)? I'm intrigued... (Or
what are "sql-files"?)
> Would this be a security risk for the server? Or for the client so that
> the client could blame the programmer?
Since I cannot imagine the upper "configuration", it's up to the
programmer to figure out explanations.
Gregor
--
http://www.gregorkofler.com