Lazo Lab Sign up

App 7: Your First Website with Flask / Build a guestbook website

Lesson 6 of 10

Validating input

Never trust what users send. Strip spaces, refuse empty messages, cap the length, and show a helpful error. Jinja escapes HTML automatically, which blocks most XSS.

Key points

  • Check length and emptiness on the server
  • flash() shows one-time messages
  • Jinja escapes {{ }} output for you
from flask import flash
app.secret_key = "change-me"  # load from an environment variable in real apps

msg = request.form.get("message", "").strip()
if not 1 <= len(msg) <= 200:
    flash("Messages must be 1 to 200 characters.")
else:
    messages.append(msg)

Your turn

Add validation and flash messages to your guestbook.

Watch a video on thisOpens YouTube search results for “Validating input” in a new tab

Quiz · +10 XP

Where must input be validated to be secure?

Log in to save progress and earn XP.