Technical notes on web development, DevOps, and AI integration.
1 article
The same QA finding hit two admin modules: non-digit phones accepted. The fix: one backend validator, a frontend mirror, one 400 INVALID_PHONE contract.
TL;DR: KotaPortal's phone fields accepted garbage like bukan-angka because validation existed only client-side, never at the backend trust boundary. The fix was one allowlist validator in Go shared by both modules, mirrored in TypeScript on the frontend, with a length cap matching the database column. They skipped libphonenumber since the need was simple format checks, not international parsing.