⚙️ Backend Engineering · Auth & Security Basics
Validate all external input at the boundary
Parse, don't validate: coerce untrusted input into typed values once at the edge.
foundation~25 minBackend EngineersAPI DevelopersPlatform Engineers
Steps
- 1Define schemas per endpoint covering body, query, params, headers
- 2Reject unknown fields by default; allowlists beat blocklists
- 3Coerce types explicitly; fail closed on ambiguity
- 4Return field-level errors machines can render
- 5Reuse the same schemas for client-side forms where possible
- 6Fuzz one nasty payload corpus against public endpoints in CI
Common Pitfalls
- ▲Validating in UI but trusting raw req.body server-side
- ▲Mass assignment from spreads straight into ORM updates
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill auth-security-input-validation-zodInstall globally
$ npx skills add aniruddhaadak80/skills --skill auth-security-input-validation-zod -gTags
#validation#security#backend-engineering#auth-security