I have a function called 'delete' like this :
<div onclick="delete($post_id, $_SESSION['id']">somelink</div>
function delete(post_id, session_id) {
  var p_id = post_id;
  var s_id = session_d;
  $.ajax({
    url:"delete.php",
    type:"POST",
    data: {  
      p_id: p_id,
      s_id: s_id
    },
  });
})
delete.php is a page to delete the post = p_id which was added from user id = s_id.
My problem is any user can delete any post for only the console when typing in it the function 'delete();' with parameters it called and delete posts!
Any ideas, please.
 
     
     
     
     
     
    