To get the id
and name
parameters without them being part in the URL:
Have the user send the values by POST, instead of GET (i.e., they select the values in a form and submit it). Then the values are sent as part of the request body, not the URL.
Run the site on HTTPS, so no one can observe the request body as it's being sent.