# Auto-generated id safe to expose in url param

**URL:** <https://discuss.elastic.co/t/auto-generated-id-safe-to-expose-in-url-param/10816>\
**Category:** Elasticsearch\
**Created:** [February 20, 2013, 11:41am UTC](https://discuss.elastic.co/t/auto-generated-id-safe-to-expose-in-url-param/10816 "2013-02-20T11:41:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Le\_Son\_Phung](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/le_son_phung/32/2169_2.png) [@Le\_Son\_Phung](https://discuss.elastic.co/u/Le_Son_Phung)\
**Post date:** [February 20, 2013, 11:41am UTC](https://discuss.elastic.co/t/auto-generated-id-safe-to-expose-in-url-param/10816/1 "2013-02-20T11:41:59Z")

</div>

Hi guys,

Just want to ask how the index id is automatically generated and it is safe  
to use in url param like this?

/customers/?customer\_id=sh\_8aCaiQB-v4ZEqJfBzlg

Regards,  
Son.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 20, 2013, 11:44am UTC](https://discuss.elastic.co/t/auto-generated-id-safe-to-expose-in-url-param/10816/2 "2013-02-20T11:44:01Z")

</div>

You mean _document ID_?

If so, yes it's auto generated if you don't provide it.  
It's a unique id.

Your URL doesn't seem to be an Elasticsearch URL, does it?

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr | @scrutmydocs

Le 20 févr. 2013 à 12:41, Le Son Phung [son@wego.com](mailto:son@wego.com) a écrit :

> Hi guys,
> 
> Just want to ask how the index id is automatically generated and it is safe to use in url param like this?
> 
> /customers/?customer\_id=sh\_8aCaiQB-v4ZEqJfBzlg
> 
> Regards,  
> Son.
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Le\_Son\_Phung](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/le_son_phung/32/2169_2.png) [@Le\_Son\_Phung](https://discuss.elastic.co/u/Le_Son_Phung)\
**Post date:** [February 20, 2013, 11:50am UTC](https://discuss.elastic.co/t/auto-generated-id-safe-to-expose-in-url-param/10816/3 "2013-02-20T11:50:49Z")

</div>

Ah yes I mean document id.

I will expose it in my front-end app and once the front-end app get the id  
it will use it to query against ES.

So not sure if I need to escape document id when I pass it around in the  
http url?

Separately, just curious, unique id in a sense of per cluster, per index,  
or per universe (hardly collided)?

On Wednesday, 20 February 2013 19:44:01 UTC+8, David Pilato wrote:

> You mean _document ID_?
> 
> If so, yes it's auto generated if you don't provide it.  
> It's a unique id.
> 
> Your URL doesn't seem to be an Elasticsearch URL, does it?
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> 
> Le 20 févr. 2013 à 12:41, Le Son Phung \<[s...@wego.com](mailto:s...@wego.com) \<javascript:\>\> a  
> écrit :
> 
> Hi guys,
> 
> Just want to ask how the index id is automatically generated and it is  
> safe to use in url param like this?
> 
> /customers/?customer\_id=sh\_8aCaiQB-v4ZEqJfBzlg
> 
> Regards,  
> Son.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![drewr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drewr/32/7803_2.png) [@drewr](https://discuss.elastic.co/u/drewr)\
**Post date:** [February 20, 2013, 4:31pm UTC](https://discuss.elastic.co/t/auto-generated-id-safe-to-expose-in-url-param/10816/4 "2013-02-20T16:31:25Z")

</div>

Le Son Phung wrote:

> Ah yes I mean document id.
> 
> I will expose it in my front-end app and once the front-end app get the id  
> it will use it to query against ES.
> 
> So not sure if I need to escape document id when I pass it around in the  
> http url?
> 
> Separately, just curious, unique id in a sense of per cluster, per index,  
> or per universe (hardly collided)?

Per universe. It's a base64-encoded random UUID. Collisions are  
theoretically possible, but I would focus on other parts of your  
application first. 🙂

[http://git.io/L1-mpA](http://git.io/L1-mpA)

-Drew

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:50am UTC](https://discuss.elastic.co/t/auto-generated-id-safe-to-expose-in-url-param/10816/5 "2017-07-06T02:50:29Z")

</div>


