This is my biggest issue, it's such a bare-faced lie!
It's completely insane for the browser to need to trust the client. Instead, you implement zero-trust, and require authentication and authorization for anything sensitive.
The server absolutely shouldn't trust the client isn't malicious, instead it should assume it is malicious until proven otherwise