Okay, I'll check to see if there's another way for the wrong userID to get into the URL.
Although it's kinda moot now because if the system finds that the intended recipient number doesn't match the number of the message's author, it just reports an error and stops.