App 7: Your First Website with Flask / Build a guestbook website
Lesson 6 of 10
Validating input
Never trust what users send. Strip spaces, refuse empty messages, cap the length, and show a helpful error. Jinja escapes HTML automatically, which blocks most XSS.
Key points
- Check length and emptiness on the server
- flash() shows one-time messages
- Jinja escapes {{ }} output for you
from flask import flash
app.secret_key = "change-me" # load from an environment variable in real apps
msg = request.form.get("message", "").strip()
if not 1 <= len(msg) <= 200:
flash("Messages must be 1 to 200 characters.")
else:
messages.append(msg)Your turn
Add validation and flash messages to your guestbook.
Quiz · +10 XP
Where must input be validated to be secure?
Log in to save progress and earn XP.