Urgent.News

What's breaking now, across thousands of outlets.

Tech

Backend Validation: AI Will Find the Gaps Your UI Hides

Your checkout page has a discount field: type a code, the price drops 10%; type a wrong one, the button greys out. You tested it and it works — what you probably didn't test is the backend validation behind it. Now look at what the browser actually sends on "Pay": the cart, the code, and in a surprising number of apps, a total the page worked out for itself. If the server accepts that number…

Your checkout page features a discount field: type in a code, the price decreases by 10%, but entering an incorrect code causes the button to turn grey. You've tested it and confirmed it functions correctly – however, have you considered the backend validation that supports it? Now, examine the data transmitted from the browser when you execute the checkout: the cart details, the discount code, and, surprisingly, a calculated total worked out by the server itself.

If the server accepts that total without validation, the only barrier preventing a 100% discount is the JavaScript running within the customer's browser, which they control. Although this scenario may seem hypothetical, it aligns with OWASP's examples, such as an API that permits hosts to modify the total_stay_price field—an action they shouldn't be able to carry out (OWASP API3).

Such vulnerabilities often go unnoticed because identifying them necessitates a diligent human with developer tools active—no longer the case. Server-side validation, enforcing every rule on the server rather than merely the page, is now an essential requirement for any live application, as AI has made discovering these gaps both cost-effective and rapid.

This article delves into why, the gaps AI uncovers first, a checklist, and a quick self-assessment for you and your development team. TL;DR: Your frontend serves as a suggestion only. Any entity can disregard a browser-based rule by sending requests directly, and AI tools now execute these at speeds exceeding human capability. This isn't solely an issue for attackers; AI assistants and automated tools also interact with your application in ways your UI never anticipated—treat each request as if it originated outside your page.

Address this through server-side validation. Validate every input, verify ownership for every record, accept only anticipated fields, independently recalculate prices and statuses, implement rate limiting, and maintain unassuming error messages.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

ever wondered what led to the headlines?

Well, go no further, cuz I built India-monitor so you can dig into the full story and progress behind any major bill/law, event, or incident in India.

  • India Monitor provides verified facts and insights on major Indian events.
  • Users can listen to briefs on the go via mobile app or audio.
  • Project emphasizes open innovation with code on GitHub.

IoT VLAN on OPNsense: three firewall rules that don't break casting or Home Assistant

Moving smart plugs, bulbs, TVs and cameras onto their own VLAN is the single biggest security win on a home network, and it is also the change most people roll back a week later because the cast…

  • Separate IoT devices onto their own VLAN for enhanced security.
  • Implement three firewall rules in OPNsense to maintain casting and Home Assistant functionality.
  • Use mDNS repeater to resolve multicast traffic limitation between VLANs.

More from Sunday 11 October →