Validation and verification
Validation and verification both try to stop bad data getting into a system, but they check different things. Validation asks whether data is sensible; verification asks whether it was copied correctly.
Validation checks
Validation is done automatically by the program. It checks that data follows set rules, not that it is true.
- Range check: the value is between a lower and an upper limit, e.g. a percentage from 0 to 100.
- Length check: the data has an exact number of characters, or a number within limits, e.g. a password of at least 8 characters.
- Type check: the data is the right data type, e.g. a whole number of tickets.
- Presence check: something has been entered and the field isn’t empty.
- Format check: the data matches a pattern, e.g. two letters then four digits.
- Check digit: the last digit of a code is recalculated from the others to catch entry mistakes.
Verification checks
Verification checks that data has been entered or copied exactly as it was meant to be. In a double entry check the data is typed in twice and the two versions are compared, as with a new password. In a visual check the person entering the data reads it back on screen and compares it with the original.
Writing a validation loop
A validation routine keeps asking until the input passes. The REPEAT loop below always runs once, so it asks at least once, and it only ends on a valid value. Giving a message after a wrong entry is good practice.
REPEAT
OUTPUT "Enter the number of eggs (0 to 500)"
INPUT Eggs
IF Eggs < 0 OR Eggs > 500 THEN
OUTPUT "That is not between 0 and 500"
ENDIF
UNTIL Eggs >= 0 AND Eggs <= 500Where marks go
- Saying validation checks data is correct: it only checks data is reasonable. A valid age can still be the wrong age.
- Naming a check without saying what it checks for this piece of data.
- Mixing up a length check (number of characters) with a range check (size of a value).
- Using IF instead of a loop, so the user only gets one more try.
- Getting the boundary wrong: using < instead of <=, so a limit like 500 is rejected.