Do we really want to force people into learning how to wrangle strings from an <input> field into valid dates or how to manually CSRF proof their forms to do basic web-dev?
Do we really want to force people into learning how to wrangle strings from an <input> field into valid dates or how to manually CSRF proof their forms to do basic web-dev?
The difference between Web development and desktop development is the HTTP protocol which is responsible for security issues and other behaviors (sessions, cookies) that you need to understand if you want to build solid applications.
Just the difference between client and server side validation is often not understood by beginners, which is a big problem.
If somebody rely on the framework to do all the job, he's going to have security issues in his applications and other weird behaviors (double submit when refreshing a page, etc.)
The point of a good framework should be to pave over the cracks like double submit bugs, since they are not really things than anybody should be wasting brain cells on.