4 ms·
While client-side validation provides a possibly snappier user experience, developers should constantly be reminded that the client cannot be trusted. Data inte
by kgtm 15y ago
While client-side validation provides a possibly snappier user experience, developers should constantly be reminded that the client cannot be trusted. Data integrity checks and conformance validation that matters must take place at the other end of the transaction.
- rickharrison 15y agoI completely agree. I will probably add a note in the docs to remind people that you should always still perform server side checks.
- btucker 15y agoIt would also be cool if there was some documentation on how you might use validate.js in concert with server-side validations.
- javanix 15y agoThere isn't really any way to dovetail client-side validation with server-side validation. Client-side validation should always be assumed to be disabled completely - view it as merely a convenience for your users. Help them switch dates into a correct format, make sure their userids aren't taken before they finish filling out their forms, that sort of thing.
- aaronblohowiak 15y ago>There isn't really any way to dovetail client-side validation with server-side validation I think the parent of your comment was talking about using SSJS to re-use validation on both ends of the pipe.
- rickharrison 15y agoI will be adding server-side js support, so this will be a definite use case.
- hackernews 15y agoI am still implementing form validations as server-side validations and not sure I will ever change that. Super easy to deal with on a simple ajax request and it's in place for all requests. If a POST/PUT is done with an ajax request simply return the error message. Otherwise, set the HTTP status code and render the form with the error as the response.