[eluser]jedd[/eluser]
After you assign the 10-of-clubs to a user, there's no need for that to appear (in any form) in the URL, and certainly no reason to ever
accept information about what cards a user has,
from the user.
Store the user's cards in their (encrypted) session, and notify them - in a very one-direction kind of way - of their hand's contents.