TechnicalCollectible prompt
Schema validation on every server endpoint
Act as a senior backend engineer. Add input validation to every server entry point in my {{tech_stack}} app, which stores {{data_to_store}}. Before changing anything, list them all: API routes, server actions, edge or serverless functions, database functions callable from the browser, form handlers and webhooks. Note which validate today, and how.
Approach:
- One schema library across the project, such as Zod or Valibot in TypeScript or Pydantic in Python. Use what's already installed
- Parse, don't just check: handlers receive only the validated, typed result, never the raw body
- Strict objects that reject unknown fields, so nobody can sneak in a role, owner ID, price or admin flag
- Every field gets a type and limits: string lengths, number ranges, enums for fixed choices, trimmed text, normalized email, URLs limited to https, dates in a sane range, capped array sizes
- User IDs and ownership come from the session, never from the request body
- A body size limit per route
- Rich text sanitized on the server with an allowlist; plain text escaped on output
- Queries always parameterized or built with the query builder
Errors:
- 400 with one consistent shape and field-level messages the form can show
- Never echo raw input or internal details back
Shared schemas can power client-side form errors too, but the server is the authority. Don't loosen a schema or cast to any to make an error go away; find the caller sending bad data.
Write tests for each endpoint: valid input, a missing field, an extra field, a too-long value and a wrong type.
Finish with a table of endpoints and their validation before and after, plus the files changed.
Technicalnvoka.com/library/nvoka-input-validation-on-every-server-endpointScan to open
Technical
Schema validation on every server endpoint
Validate every request on the server with one schema library, so bad or extra data never gets in.
Curated by Nvoka
Claude CodeCursorCodexGitHub Copilot
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 2 filledYour prompt
Act as a senior backend engineer. Add input validation to every server entry point in my {{tech_stack}} app, which stores {{data_to_store}}. Before changing anything, list them all: API routes, server actions, edge or serverless functions, database functions callable from the browser, form handlers and webhooks. Note which validate today, and how.
Approach:
- One schema library across the project, such as Zod or Valibot in TypeScript or Pydantic in Python. Use what's already installed
- Parse, don't just check: handlers receive only the validated, typed result, never the raw body
- Strict objects that reject unknown fields, so nobody can sneak in a role, owner ID, price or admin flag
- Every field gets a type and limits: string lengths, number ranges, enums for fixed choices, trimmed text, normalized email, URLs limited to https, dates in a sane range, capped array sizes
- User IDs and ownership come from the session, never from the request body
- A body size limit per route
- Rich text sanitized on the server with an allowlist; plain text escaped on output
- Queries always parameterized or built with the query builder
Errors:
- 400 with one consistent shape and field-level messages the form can show
- Never echo raw input or internal details back
Shared schemas can power client-side form errors too, but the server is the authority. Don't loosen a schema or cast to any to make an error go away; find the caller sending bad data.
Write tests for each endpoint: valid input, a missing field, an extra field, a too-long value and a wrong type.
Finish with a table of endpoints and their validation before and after, plus the files changed.