Anything sent to a web app via HTTP is user generated content. You can't assume it is ANYTHING.
Anything sent to a web app via HTTP is user generated content. You can't assume it is ANYTHING.
In PHP the exact same approach turned out to be a security hole because if the user supplies the right input you get a data structure that is meaningful to MongoDB.
As you say, you shouldn't assume anything about user generated content. But PHP's willingness to parse that input and turn it into something the programmer didn't expect to see often means that user generated content is harder to deal with in that language than you should reasonably expect it to be.
For several years if you followed the examples in the MongoDB docs, you wouldn't have known you had to, because the people who wrote those docs didn't know you did either.