I have poked and prodded at making my own turn-based game, and one thing I have learned is validation. Don't trust input, and you will make robust serverside code. Assume every bit sent by the client was maliciously sent in order to bring down your service in flames. Keep this mentality, and security becomes that much easier.
AJAX long polling is a good way to send data while avoiding spurious requests and/or delays, albeit with a bit more load on the server.