What is the result of call to "
https://brd.com/x/gift/someBase64String....."?
I may be wrong, but I think the information encoded in "someBase64String" are not sufficient, if they store information about sender, recipient and amount on the server side.