Web Security / Thinking like a defender
Lesson 2 of 27
Never trust input
Anything that comes from the user can be changed: form fields, URLs, cookies, headers, even hidden fields. Validate it on the server, every time.
Key points
- Client-side checks are for convenience only
- Validate type, length and format on the server
- Use allow-lists, not block-lists
Quiz · +10 XP
Where must input validation happen to be secure?
Log in to save progress and earn XP.