Client-side validation is not a security boundary
Checks in the browser are a courtesy to the user. Whoever is attacking you is not using your browser.
They send the request directly, with whatever values they like, and every rule you enforced in JavaScript is absent. Client-side validation improves the experience and prevents mistakes. The server has to assume none of it happened.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
