We still need to do server-side validation since a lot of things can go wrong here if users get cheeky