YES YES always YES. Never trust anything that comes from the browser.
In the most benign case, what if they had Javascript disabled?
For a more devious case, what if they were manually posting the data with something like curl
?
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…