'You must not convert this to SQL on the client side. You must validate the fields submitted are in your approved list on the backend (indexes/security).'
Interesting point. Can't you get around this by only exposing certain tables/fields in the UI based on the users permissions?