So is it safe to validate form on client-side only?
Asked Answered
R

3

9

Of course, I know that server-side validation is a MUST.

I'm using jQuery to validate form inputs and using jquery ajax to do server-side(PHP) validation at the same time. So I guess it may be safe since it's validating for both sides while javascript is enabled.

Well, here is my problem...

But what if the user has javascript disabled on his browser and if some bad guys try to do something bad from editing my client-side script?

Because i'm making server-side validation through jquery ajax, and i'm planning not to validate them directly in php script(action="some.php") even user's javascript is enabled.

So... does it is still safe?

Sorry for my bad english, hope you don't mind.

Reorganize answered 20/11, 2012 at 15:53 Comment(2)
Possible duplicate off: #3484014Paleopsychology
Wow some thing i thought where obvious. No wonder people get hacked so often. Just damn.Grudging
M
15

No, it is not safe. You should always validate your data on the server side, after the form has been submitted. Client-side validation and AJAX validation before submitting the form are only enhancing the user experience, by providing quicker feedback on invalid data. Both client-side validation and AJAX pre-submit validation do not and can not protect you from a maliciously crafted form submission. Attackers and abusers usually don't even use a browser in order to submit data to your server.

Messeigneurs answered 20/11, 2012 at 15:59 Comment(0)
G
7

My rules are fairly simple...

  1. If you care about your data, then you must validate on the server.
  2. If you care about your user experience, then you must validate on the client.
Giusto answered 20/11, 2012 at 15:56 Comment(1)
Best answer!, short and accurate.Hydrastinine
S
6

Since javascript is readable for any visitor, and easily editable with the newest browsers, anyone with a bit programming skills can bypass your javascript validation in no time. So you should validate on the server side also, always.

Sublimation answered 20/11, 2012 at 16:0 Comment(0)

© 2022 - 2024 — McMap. All rights reserved.