Backend Development › Backend Basics · also in Web Application Security
Input Validation
Checking every input at the boundary before using it.
Also known as: validating input, request validation, data validation, sanitizing input
Input validation means checking everything that comes from outside your code before you use it: request bodies, query parameters, headers, uploaded files, webhooks and messages. Assume it can be missing, malformed, oversized or hostile.
The check belongs at the boundary: reject bad input right where it enters, so the rest of your code can trust what it gets.
from pydantic import BaseModel, Field, EmailStr # one common library; others work too
class SignupIn(BaseModel):
email: EmailStr
age: int = Field(ge=13, le=120)
name: str = Field(min_length=1, max_length=100)
A request that doesn’t fit gets a 400 or 422 with a message saying which field is wrong
(error response format).
What to check
- Presence and type: is it there, and is it a number or a string?
- Format: email, UUID, date.
- Range and length: min/max values, maximum string and list sizes, upload size limits.
- Allowed values: an enum or a known set (
status in {"open", "closed"}). - Business rules: things the server knows, such as “that username is taken” or “end date after start date”.
Principles
- Validate on the server, always. Browser-side checks are only a courtesy (form validation); anyone can bypass the frontend.
- Prefer allow-lists to block-lists. Define what is acceptable, instead of trying to list every bad thing.
- Reject, don’t silently fix, unless the correction is obvious and safe.
- Validation is not a replacement for safe handling. Even valid-looking text must never be pasted into SQL or HTML. Use parameterized queries (SQL injection) and escape output.
- Limit size everywhere. Unbounded input is a denial-of-service risk.
- Don’t leak internals in error messages (stack traces, SQL).
Turn the validated data into a typed object (DTO) at the edge, and pass that inward, not the raw dictionary.