While perusing ASVS 3.0.1 I came across requirement V5.18:
Verify that client side validation is used as a second line of defense, in addition to server side validation.
Umm... is client-side validation not said to have no security benefit whatsoever?
I mean, as a convenience function to alert users to undesired input, yes, but as a security requirement? Have I missed something?