I am planning to use Ext JS for a large application. The application\'s features are role based. When user login, they only see menu and screen features related to them. My
Always enforce server side security, hiding controls in the frontend it's not enough. EDIT
On the client side? well, you can follow any of the advices in the other responses, but the true is that the user can execute arbitrary javascript, modify the page's DOM and do whatever request he want.