Skip to content

docs: warn about front-end-only required field validation and known bugs#109

Open
RensTillmann wants to merge 1 commit intomasterfrom
claude/issue-106-20260326-2244
Open

docs: warn about front-end-only required field validation and known bugs#109
RensTillmann wants to merge 1 commit intomasterfrom
claude/issue-106-20260326-2244

Conversation

@RensTillmann
Copy link
Copy Markdown
Owner

Closes #106\n\n## Target Branch\n- [x] master\n\n## Type of Change\n- [x] Documentation update

Add security notices and technical clarifications to validation docs:

- validation.md: Top-level warning that all validation is JS-only with
  no server-side fallback; detailed explanation of how 'none' validation
  type fields rely on may_be_empty flag alone; document v6.3.3 bug where
  required fields with validation='none' may silently pass blank submit;
  note that submit_form_checks() has zero required-field assertions.

- conditional-validation.md: Browser-only scope notice for the entire
  feature; dedicated section for conditional-required (may_be_empty=conditions,
  since v4.9.0) documenting browser requirements, no server-side equivalent,
  and the has_hidden_parent() limitation with super-hidden class.

Closes #106

Co-authored-by: Rens Tillmann <RensTillmann@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update documentation: Required field validation bypass: JS guard and missing server-side enforcement

1 participant