Wait a second, if you have user X who needs to request his data from the server, you do not need his identifier, you have it in the session, or if you use the cflogin function, you will have getUserAuth ().
I have an administrator who can see the information of other users, and you are worried that he sees bank details in which you need roles, cf roles or your own solution, etc.
In any case, you do not need to send an explicit call "gimme bank details for user 3456."
source share