Summary
- Implement secure, comprehensive input validation on both client and server sides using allowlists, type checking, and sanitization to prevent injection attacks.
- Use this skill when handling user input from forms, API requests, or any external data source.
- When implementing form validation logic with field-specific error messages.
- When validating data types, formats, ranges, and required fields.
- When sanitizing input to prevent SQL injection, XSS, or command injection.
- When validating business rules like sufficient balance or valid date ranges.
- When implementing both client-side validation for user experience and mandatory server-side validation for security.