freecoding.school100% FREE · NO SIGNUP
Gateway RidgeISSUE #9 of 35

validation · request shape · 400 vs 422

Gateway GusVSTimeout Titan
Gateway Gus saysValidate every request; reject bad input with 400 (malformed) or 422 (well-formed but invalid).

Never trust input. Validate shape, types, and rules on the server (client validation is UX only). Use 400 Bad Request for malformed/unparseable input and 422 Unprocessable Entity for syntactically valid but semantically wrong data (e.g. a missing required field, a too-short password). Return all validation errors at once so the client can fix them in one pass.

Power-ups you unlock

Timeout Titan attacks — common mistakes

Boss battleDecide 400 vs 422 for: broken JSON, and a missing required field.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>broken JSON        → 400 Bad Request
missing "name"     → 422 Unprocessable Entity
(return all field errors at once)</pre></body></html>
▶ Open the interactive comic issue
‹ Error Responses · Problem+Json · Message + CodeContent Negotiation · Accept · Vary ›