Skip to content
Grav 2.0 is officially stable. Read the announcement →

Community guidelines

Please keep discussions civil and on-topic. Repeated violations may lead to a temporary ban.

General

Form backend validation

Started by Alexander Kim 8 years ago · 3 replies · 617 views
8 years ago

As i've noticed this form plugin only does clientside HTML5 validation, is there a way to make validation on the backend? Clientside is not secure, because users can modify it.

8 years ago

Where or how did you notice this?

8 years ago

Because inputs allow even <script> to be submitted without validation, if i make validate.required or validate.pattern it adds clientside only validation.

8 years ago

Does the script run or does it get escaped? Have you been able to use this to run some javascript from form input?

You'll have a much better chance to get help if you describe a lot more about what you've found with examples. No-one wants to tease this out of you slowly, especially volunteers trying to help. I am sure this will be taken very seriously with reproducable evidence.

Suggested topics

Topic Participants Replies Views Activity
General · by Jerry Hunt, 4 days ago
2 80 10 hours ago
General · by pamtbaau, 15 hours ago
1 51 15 hours ago
General · by Andy Miller, 1 day ago
0 45 1 day ago
General · by Marcel, 12 months ago
6 346 5 days ago
General · by Duc , 5 days ago
3 40 5 days ago