Security and Request Validation Policy
Sensitive actions are server-validated with nonce and capability controls to reduce misuse risk.
Validation Controls
- Nonce validation for state-changing requests.
- Capability checks for privileged operations.
- Server-side policy checks even if UI control is visible.
Best Practice
Do not rely on client-side visibility. Always treat server-side validation outcomes as source of truth.