Learn
HTML form handling, explained
How forms actually submit, from the method and action attributes to fetch(), CORS, uploads, validation and spam. Each article has runnable code, the gotchas that show up in production, and links to the specs it is based on. For Formward reference material, see the docs; for copy-paste components, the framework examples.
HTTP
POST vs GET for HTML forms
When a form should use GET and when it must use POST: safety and idempotency, where GET data leaks, caching, the resubmit prompt, and Post/Redirect/Get.
Read article →HTML
How the HTML form action attribute works
How form action URLs resolve, what an empty action does, formaction and friends on buttons, how method and enctype combine, and what the server receives.
Read article →JavaScript
Submit an HTML form with fetch()
A fetch() form submit that holds up in production: FormData vs JSON, the Accept header, 4xx field errors, timeouts, double submits and a no-JS fallback.
Read article →JavaScript
The FormData API explained
FormData from a form, the submitter argument, multiple values per name, files, the formdata event, and converting to URLSearchParams or JSON without data loss.
Read article →Security
How to prevent contact form spam
Honeypot, time trap, rate limiting, Turnstile, disposable email blocking and server-side validation: what each layer stops, what it misses, and code for each.
Read article →Security
Honeypot fields done right
A form honeypot that bots fill and people never touch: naming that dodges autofill, accessible hiding with inert, and a silent-success server check.
Read article →Security
Cloudflare Turnstile on a contact form
Turnstile on a contact form: widget modes, server-side siteverify, single-use tokens that expire after 300 seconds, fetch() resets, and what Cloudflare sees.
Read article →HTTP
CORS and HTML forms
Why CORS never blocks a cross-origin form post but a fetch() JSON post needs a preflight, what credentials change, and how a form backend allows origins.
Read article →HTTP
multipart/form-data file uploads
How multipart/form-data works: enctype, boundaries, the empty file part, size limits at every hop, and why the server cannot trust the browser's MIME type.
Read article →HTML
HTML form validation, client and server
Constraint validation in practice: required, type and pattern rules, setCustomValidity, novalidate with custom messages, and the server checks you still need.
Read article →