For such things, if you're not doing everything Server Side to Render fully validated and sanitized data safely, you should be.
If it’s is purely a SPA, then all business logic would be behind secure APIs, so I don’t really understand your point.
For such things, if you're not doing everything Server Side to Render fully validated and sanitized data safely, you should be.