>Even field validation cannot be considered secure, because it is trivial to
>modify the JavaScript to get it to submit bogus values

The whole point is, however, that by doing field validation on the client
side first
you reduce the need to additional network traffic when the data in bad.  You
still need
to do validation checking on the CGI end as well, but unless the user has
been hacking
your code these tests will always validate to true.

