Gateway Gus saysValidate every request; reject bad input with 400 (malformed) or 422 (well-formed but invalid).
Never trust input. Validate shape, types, and rules on the server (client validation is UX only). Use 400 Bad Request for malformed/unparseable input and 422 Unprocessable Entity for syntactically valid but semantically wrong data (e.g. a missing required field, a too-short password). Return all validation errors at once so the client can fix them in one pass.
Power-ups you unlock
Always validate server-side
400 = malformed; 422 = valid shape, bad data
Return all field errors together
Client validation is UX, not security
Timeout Titan attacks — common mistakes
Trusting client-side validation as security
One error at a time (frustrating round-trips)
500 for what is really a client input error
Boss battleDecide 400 vs 422 for: broken JSON, and a missing required field.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>broken JSON → 400 Bad Request
missing "name" → 422 Unprocessable Entity
(return all field errors at once)</pre></body></html>