Validation
also: input validation, validate, validating, validated
Checking that data coming into your app, like a form entry, is acceptable before using it. For example, rejecting an email address with no @.
Checks that run in the live app on incoming data (form fields, API request bodies, uploads) to confirm its type, format and range before it's processed or stored. Unlike tests, validation runs on every input. Libraries like Zod define the rules.
A bouncer checking IDs at the door every night is validation. A fire inspection before the venue opens is more like testing. Different jobs, both needed.
"Validate" and "test" get mixed up. Validation protects your live app from bad data; tests check your code works before you ship. When an agent says it "validated" something, ask which one it means.
I added validation to the signup endpoint: email must be valid and password at least 12 characters. Invalid requests now get a 400 with a clear message.
Add server-side validation to the booking form: the date can't be in the past and party size must be 1 to 20. Don't rely only on the check in the browser.
Thinking validation and testing are the same thing. Tests check your code during development; validation checks users' data every time the live app runs.