Skip to content

Learn

HTML form handling, explained

How forms actually submit, from the method and action attributes to fetch(), CORS, uploads, validation and spam. Each article has runnable code, the gotchas that show up in production, and links to the specs it is based on. For Formward reference material, see the docs; for copy-paste components, the framework examples.

HTTP

POST vs GET for HTML forms

When a form should use GET and when it must use POST: safety and idempotency, where GET data leaks, caching, the resubmit prompt, and Post/Redirect/Get.

Read article →

HTML

How the HTML form action attribute works

How form action URLs resolve, what an empty action does, formaction and friends on buttons, how method and enctype combine, and what the server receives.

Read article →

JavaScript

Submit an HTML form with fetch()

A fetch() form submit that holds up in production: FormData vs JSON, the Accept header, 4xx field errors, timeouts, double submits and a no-JS fallback.

Read article →

JavaScript

The FormData API explained

FormData from a form, the submitter argument, multiple values per name, files, the formdata event, and converting to URLSearchParams or JSON without data loss.

Read article →

Security

How to prevent contact form spam

Honeypot, time trap, rate limiting, Turnstile, disposable email blocking and server-side validation: what each layer stops, what it misses, and code for each.

Read article →

Security

Honeypot fields done right

A form honeypot that bots fill and people never touch: naming that dodges autofill, accessible hiding with inert, and a silent-success server check.

Read article →

Security

Cloudflare Turnstile on a contact form

Turnstile on a contact form: widget modes, server-side siteverify, single-use tokens that expire after 300 seconds, fetch() resets, and what Cloudflare sees.

Read article →

HTTP

CORS and HTML forms

Why CORS never blocks a cross-origin form post but a fetch() JSON post needs a preflight, what credentials change, and how a form backend allows origins.

Read article →

HTTP

multipart/form-data file uploads

How multipart/form-data works: enctype, boundaries, the empty file part, size limits at every hop, and why the server cannot trust the browser's MIME type.

Read article →

HTML

HTML form validation, client and server

Constraint validation in practice: required, type and pattern rules, setCustomValidity, novalidate with custom messages, and the server checks you still need.

Read article →
HTML form handling, explained for developers | Formward