If you want to impress me, develop some system that lets you write validation rules once and have them work on both the client and the server.
Back in my previous existence, before a strange series of events transformed me into an A.I. programmer, I was a generalist web developer. Back in 2001 I was helping some guys make a voice chat site aimed at Brazil, and against my advice, they implemented validation in Javascript and not on the server.
We launched and it all seemed OK for a few weeks until I get a call at 7 pm because the site is all f'ed up.
Well, doing some investigation I find that there's a user with the empty string for his user name and that this has had a bigger impact on the system than one might think.
I nuked the guy with the SQL monitor and added server-side validation that night.
Since then I worked on hundreds of different sites and web applications and I've had to deal with the busted app made by somebody who was too lazy to do server side validation many many times.
On one hand you've got the person who browses without Javascript turned on. Perhaps you're one of the cool kids who makes apps that don't work at all without Javascript, so you don't need to worry about him.
You still need to worry about the people that want to mess with you. If you build a community site that's substantial at all (say 10,000+ users) you're going to get hit. Today it's easier than ever to reverse-engineer client-server communication with Firebug and then use curl or another tool to make phony requests.
Apps built in this style, where all validation is done on the client have a surface area that's 100% soft underbelly.