From any one of the many security experts that hang out here - can you give us an assessment of how secure this actually is?
But it /is/ server-side validation, that you as a developer get to specify.
(That said, we're definitely happy to get feedback on our approach from any security experts out there that want to take a look!)