This is the most naive take on security ever. For the backend, you assume your client is compromised, but you still don't want to allow your client to be compromised.