A submit button with formnovalidate skips browser constraint validation for that submission only.
HTML formnovalidate: save a draft without publishing incomplete data
When it earns its place
A field inspector can save a report before writing the final finding, while publication requires that finding. The draft button posts to a draft endpoint and bypasses the required-field check; the publish button uses the form action and normal browser validation. The backend must keep these operations separate. Draft storage may accept incomplete fields, but publishing must run full server validation and permission checks regardless of which button or endpoint a client claims to use.
<form action="/reports/R-47/publish" method="post">
<label for="final-finding">Final finding</label>
<textarea id="final-finding" name="finding" required></textarea>
<button type="submit" formaction="/reports/R-47/draft" formnovalidate>Save draft</button>
<button type="submit">Publish report</button>
</form>Browser boundary
Formnovalidate affects native browser checks; it does not disable validation implemented by script or server. A draft is still a state-changing request and needs authentication, authorization, and request protection.
Cost and maintenance
The attribute costs nothing in delivery. The real engineering cost is a clear state model so incomplete drafts cannot accidentally become public records through a forged or misrouted request.
Common Mistakes
- Do not let the publish endpoint trust browser validation.
- Do not treat a draft POST as harmless because required was bypassed.
- Do not send both buttons to one ambiguous backend action without an explicit decision.
