Lesson 1 / الدرس 1

The half you have never seen / النصف الذي لم تره قط

Everything you have built so far runs on the visitor's machine, where they can read it, change it and lie about it. Server code runs somewhere they cannot reach — and that difference is the entire reason the backend exists.

كل ما بنيته حتى الآن يعمل على جهاز الزائر، حيث يستطيع قراءته وتغييره والكذب بشأنه. أما كود الخادم فيعمل في مكان لا يبلغه — وذلك الفرق هو سبب وجود الخلفية كله.

Open any page you have built and press view-source. Everything is there: your HTML, your CSS, every line of your JavaScript. The visitor has a complete copy of your front end and can edit all of it — which is fine for a layout and catastrophic for a price, a permission or a password check.

Two machines, and only one you control

In the browserOn the server
Who can read the codeEveryoneNobody but you
Who can change itThe visitorNobody but you
Where data livesOnly what was sentThe database, the files, everything
Can it be trustedNeverYes — it is yours
Runs whenAfter the page arrivesBefore the page exists

Read the fourth row twice. Everything the backend does follows from it: the server is the only place a decision can actually be made, because it is the only place the visitor cannot reach.

<form>
  <label>Quantity <input type="number" value="1" max="3"></label>
  <label>Price <input value="550" readonly></label>
  <button>Buy</button>
</form>

<p>Run it, then open the browser's element inspector and change
<code>max="3"</code> to <code>max="999"</code>, or delete
<code>readonly</code> and set the price to 1.</p>
Do it. Both edits take about four seconds and neither requires any skill. Every rule that lives only in the page is a suggestion — the browser will happily send whatever the visitor decided, and a server that trusts it has just sold something for one pound.

What PHP is, and why it is here

PHP is a language that runs on the server and produces the HTML the browser receives. It was built for exactly this job, it runs on almost every host in the world including the cheapest, and the site you are reading this on is written in it — which means everything you learn here you can go and read in a real, working codebase rather than a tutorial.

Try it live / جرّب بنفسك

Preview / المعاينة

Check yourself / اختبر نفسك

1. Why can a rule enforced only in the browser not be trusted?

2. What is the decisive difference between browser code and server code?

3. Should you validate a form in the browser at all?

Your task / مهمتك

Take any form on any site and break one of its rules using the browser's inspector. Report what you changed, what you sent, and what came back — then say what the server should have done.

خذ أي نموذج في أي موقع واكسر إحدى قواعده بفاحص المتصفح. وبلّغ بما غيّرت وما أرسلت وما عاد — ثم قل ما كان ينبغي للخادم أن يفعله.

  • The rule you broke, and exactly how you broke it القاعدة التي كسرتها، وكيف كسرتها بالضبط
  • What the server accepted or refused ما قبله الخادم أو رفضه
  • What the server should check, written as a rule ما ينبغي أن يفحصه الخادم، مكتوبًا قاعدةً
How do you want to submit? / كيف تريد التسليم؟