Lesson 4 of 55 · HTML
Forms Overview
Duration: 9 min
The <form> Element
Forms collect user input and submit it to a server.
<form action='submit.php' method='post' novalidate autocomplete='on'>
<!-- form controls go here -->
</form>
Core attributes
action– URL that receives the form data. If omitted, the form submits to the same page.method–GET(query string) orPOST(request body). UsePOSTfor sensitive data.novalidate– Disables the browser's built‑in validation, useful when you provide custom validation.autocomplete–onoroff; guides browsers in offering previously entered values.enctype– Encoding type. Default isapplication/x-www-form-urlencoded. Usemultipart/form-datafor file uploads.
Security best practices
- Serve forms over HTTPS to encrypt transmitted data.
- Include a hidden CSRF token when handling state‑changing actions.
- Always perform server‑side validation, even if client‑side checks pass.
- Use the
autocompleteattribute thoughtfully – disable for passwords or one‑time codes.
Quick checklist for forms
actionpoints to a real endpoint? ✅methodappropriate for the data being sent? ✅enctypeset correctly for file uploads? ✅- HTTPS enforced for all form submissions? ✅
- CSRF token included for state‑changing actions? ✅
Tip: Provide a graceful fallback (
actionpointing to a real endpoint) for users who disable JavaScript.