Any data that enters your system from outside a trust boundary should be treated as untrusted until proven otherwise. That includes form fields, API payloads, file uploads, headers, cookies, queue ...
Sticking to the centre lane might seem like a happy medium, but if you’re being passed on the right, it’s time to move over, ...