The smallest form on your site is still an entry point. It accepts input from strangers, hands that input to your systems, and often lands in an inbox someone opens without thinking. If you would not leave a door unlocked because it is small, do not leave a form unguarded because it is simple.
Here is the mental model we use. The browser belongs to the visitor, so nothing that happens there is a security boundary. Client side validation exists for comfort, to catch typos and give quick feedback. The server is where the rules actually live, and the server must assume every request was written by hand, by someone who read your JavaScript first.
That single idea decides most of the design:
- Validate everything again on the server. Length caps, required fields, email shape. The client already checked, and that means nothing.
- Accept only what you expect. Our endpoint takes JSON from our own origin with a hard size ceiling. Anything else is turned away before it is even parsed.
- Let bots defeat themselves. A hidden field that people never see, called a honeypot, stays empty in every real submission. When it arrives filled, we answer politely and deliver nothing.
- Rate limit by address. A person sends one message. A script sends five hundred. The difference is easy to see once you count.
- Escape on the way out. The message ends up in an email that a human opens. User text is encoded before it goes into that email, so a form can never smuggle markup into your inbox.
- Fail closed. If the mail service is down or a key is missing, we say so. A form that pretends to succeed is lying to the one person who tried to reach you.
None of this is exotic. It is a few dozen lines of deliberate code, and it is the difference between a form and a liability. We shipped exactly this pattern on our own contact page, a small serverless function carrying every check above, and honeypots start catching bots almost immediately on any public site.
The deeper habit is the one worth keeping. Find every place where the outside world can hand you data, and treat each one as a front door. Some doors are large, like a login page. Some are small, like a contact form. Attackers do not care about the size. They care about the lock.
Written by the Cypherslash team, from the build notes of this very site.