"Use a conventional solution like storing the id in session or using a token-based approach to avoid frontend database queries and XSS attacks"