Check flow data and rules
The server may check fields, request types, routes, addresses, or rules depending on the module. Scope is specific to the endpoint and version.
The dossier confirms server-side validation for certain fields, request types, routes, addresses, or rules. These validations are specific to the documented module, endpoint, and version.
In documented flows, the server may validate fields, the request type, a route, an address, or a module-specific rule. The result can therefore differ from a value prepared in the interface. The dossier states that these validations are specific to the endpoint and version.
They all contribute to technical operation, but they do not have the same role and should not be confused.
The server may check fields, request types, routes, addresses, or rules depending on the module. Scope is specific to the endpoint and version.
App Check and reCAPTCHA Enterprise are documented for configured functions, including Web forms. The dossier states that they do not replace server-side validation.
HERE and/or OSRM may be used for geocoding and routes depending on the flow. Quality depends on addresses, keys, and service availability, among other factors.
These examples show why the exact flow should be identified before concluding that a result is abnormal.
Documented forms may use App Check or reCAPTCHA Enterprise in addition to server validation specific to the function.
HERE and/or OSRM may be involved depending on the flow. The result depends on the supplied data and service availability.
A protected flow may depend on Firebase Authentication, a group control, and the Firestore rules actually deployed.
If the result is unexpected, record what helps reproduce the case without sending secrets or unnecessary personal information.
Record the exact journey and page used.
Indicate the account type or context without a sign-in identifier.
Precisely describe the action performed before the unexpected result.
Keep only the non-sensitive elements needed to understand or reproduce the case.
Explain what you expected to observe based on the journey and configuration.
Copy the exact message and describe the actual behaviour obtained.
Add the approximate date and time and a sanitized screenshot if it helps the diagnosis.
This page describes mechanisms confirmed by component. It does not mean every action is revalidated in the same way.
Choose the resource that matches the organizational, functional, or technical question you need to clarify.
Explore guides about data categories, roles, and server-side validations.
View the Security and data collection →Review an accessible presentation of documented access categories, validations, and technical mechanisms.
Explore the Security page →Gather useful context, steps, and results before contacting support.
Prepare a support request →Learn how the interface prepares a request and why certain information may be rechecked server-side.
Understand the validation architecture →If a validation produces a result you do not understand, note the flow, page, action, date, expected result, observed result, and exact message. Clean screenshots and do not send secrets.