The name attribute identifies a submitted entry; disabled controls are excluded from normal form submission.
HTML form names and disabled controls: know which values submit
Use it for a real task
The reviewer can inspect a locked batch ID, but disabling that field also means the server will not receive it from that control. A separate hidden field can carry the ID, though the server must treat it as untrusted. A readonly text field stays focusable and may be submitted, which is a different interaction contract.
<form action="/receipts/review" method="post">
<label for="batch-display">Batch ID</label>
<input id="batch-display" value="RB-47" disabled>
<input type="hidden" name="batch_id" value="RB-47">
<label for="review-note">Review note</label>
<input id="review-note" name="review_note" type="text" required>
<button type="submit">Save review</button>
</form>What the markup guarantees
The server must look up RB-47 and check the current user's permission. A form may contain repeated names, which are legitimate for some controls; decide how an endpoint handles them instead of silently taking one value.
Cost and limits
The markup cost is small. The cost of misunderstanding successful controls is a dropped value or an unintended duplicate at the server boundary.
Common Mistakes
- Do not assume an input without name is sent.
- Disabled is not the same as readonly.
- Never authorize an action from a hidden value alone.
Connected lessons
- HTML forms: choose GET for retrieval and POST for a state change
- HTML constraint validation: improve feedback without trusting the browser
- HTML radio and checkbox controls: submit choices with explicit values
Related: HTML forms: choose GET for retrieval and POST for a state change.
Related: HTML disabled fieldset: stop editing without implying saved state.
Related: HTML readonly versus disabled: preserve the right submission contract.
