Yes, the client could fake it, but such faking would not open up new capabilities that the client didn't already have.
Yes, the client could fake it, but such faking would not open up new capabilities that the client didn't already have.
Are you not too concerned about this because the real validation happens on the server anyway?
Suppose Al is in charge of color and Betty is in charge of size. They both get the form at the same time.
Al sends oldsize=M newsize=M oldcolor=green newcolor=blue
Betty sends oldsize=M newsize=S oldcolor=green newcolor=green
The server ignores Al's oldsize/newsize and Betty's oldcolor/newcolor because the values are unchanged.
You end up with size=S and color=blue no matter who sends the update first.
By "faking it" I refer to the fact that the old values are user-supplied data. Validation of the new data is a separate issue. Someone could "fake" an old value. This merely means they would change a value that they were already authorized to change. Messing with the "old" values on the client side has no hack value. That's why I'm not at all concerned about it.