Dont pass variables via URL

check this thread out. What are you are looking for is called access control list