So mainly it's under developement it's a good idea..
I have thought of the 'tinckered with the input from forms'
I have a song table with a user id field (Pid). This user id is the id of the user that have access to this song.
Then I have a users table containing Userid, username and password.
I transfer songid from the song table and the username and password from the users tabel, and collect these 3 and the Pid (the userid on the user that have access to this song) from the song table.
And then I find the userid in the users table based on the username and password.
At last I check if the userid found in the users tabel is the same as the Pid in the song table, on the song they which to update.
This way you can't change the songid, username or password tranfered from the form, since the Pid on that chosen song then wouldn't be the same as the userid found by the username and password in the users table.
In short, the song id tranfered from the form has to matched the username and password fransfered from the form. So if you do not know the username and password on the user that have access to songid 8, then you can't update songid 8.