Skip to content
AITroveRead. Build. Understand.
Make this comfortable

HTML form names and disabled controls: know which values submit

Last updated: 1 Oct 20266 min read
tutorial
IntermediateBy AITrove Editorial

The name attribute identifies a submitted entry; disabled controls are excluded from normal form submission.

Use it for a real task

The reviewer can inspect a locked batch ID, but disabling that field also means the server will not receive it from that control. A separate hidden field can carry the ID, though the server must treat it as untrusted. A readonly text field stays focusable and may be submitted, which is a different interaction contract.

html
<form action="/receipts/review" method="post">
  <label for="batch-display">Batch ID</label>
  <input id="batch-display" value="RB-47" disabled>
  <input type="hidden" name="batch_id" value="RB-47">
  <label for="review-note">Review note</label>
  <input id="review-note" name="review_note" type="text" required>
  <button type="submit">Save review</button>
</form>

What the markup guarantees

The server must look up RB-47 and check the current user's permission. A form may contain repeated names, which are legitimate for some controls; decide how an endpoint handles them instead of silently taking one value.

Cost and limits

The markup cost is small. The cost of misunderstanding successful controls is a dropped value or an unintended duplicate at the server boundary.

Common Mistakes

  • Do not assume an input without name is sent.
  • Disabled is not the same as readonly.
  • Never authorize an action from a hidden value alone.

Connected lessons

Related: HTML forms: choose GET for retrieval and POST for a state change.

Related: HTML disabled fieldset: stop editing without implying saved state.

Related: HTML readonly versus disabled: preserve the right submission contract.

html
forms
Storage details