Validating server side client php security

Form validation is focussed towards the user input where as the security validations should be focused on how you use the data.

When you use the form data in an SQL query, it should be validated against SQL Injection.

Often, people confuse form validations with form security.

Form security (preventing exploits like SQL injection, XSS attacks etc ) are to be handled in addition to form validation.

A user's request is fulfilled by running a script directly on the web server to generate dynamic HTML pages. It is usually used to provide interactive web sites that interface to databases or other data stores on the server.

This is different from client-side scripting where scripts are run by the viewing web browser, usually in Java Script.

In this article you’ll construct and validate a simple form using HTML and PHP.

The validations also help in lesser server side errors.

For example, if you have set length limit in the database for a text input, it is better to do the validation before it actually gets cut off by the database system or even getting an error thrown.

The processing takes place on the end users computer.

The source code is transferred from the web server to the users computer over the internet and run directly in the browser.

