# Which validations can be bypassed and how when using the API to create topics/posts

**URL:** <https://meta.discourse.org/t/which-validations-can-be-bypassed-and-how-when-using-the-api-to-create-topics-posts/299282>\
**Category:** Development\
**Tags:** rest-api\
**Created:** [March 13, 2024, 10:39pm UTC](https://meta.discourse.org/t/which-validations-can-be-bypassed-and-how-when-using-the-api-to-create-topics-posts/299282 "2024-03-13T22:39:41Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![simon](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/simon/32/339122_2.png) [@simon](https://meta.discourse.org/u/simon)\
**Post date:** [March 20, 2024, 10:46pm UTC](https://meta.discourse.org/t/which-validations-can-be-bypassed-and-how-when-using-the-api-to-create-topics-posts/299282/6 "2024-03-20T22:46:59Z")

</div>

> [@Isambard](#):
>
> When I use skip validations to create a Topic, this works and it is possible for user to create a topic in a category even if normally he would have no rights to do so.

Are you sure about that? My understanding is that `skip_validations` does what it says it does in the options section that’s at the bottom of `post_creator.rb`:

> <https://github.com/discourse/discourse/blob/main/lib/post_creator.rb#L37>

It’s primarily used to ignore the constraints that are added through site settings like:

- min post length
- min body entropy
- min topic title length  
…

I think it’s also used to ignore posting rate limits.

I didn’t think it allowed users to create topics in categories that they don’t have permission to post in.

---

_[View the full topic](https://meta.discourse.org/t/which-validations-can-be-bypassed-and-how-when-using-the-api-to-create-topics-posts/299282)._
