A form combines successful named controls into a request using its action and method.
HTML forms: choose GET for retrieval and POST for a state change
Use it for a real task
A receipt search is read-only and uses GET so the query can appear in the URL. Approval is a state change and uses POST. These are different endpoint contracts; a browser form does not provide authorization, replay protection, or a server-side validation rule.
<form action="/receipts/search" method="get">
<label for="receipt-query">Receipt ID</label>
<input id="receipt-query" name="receipt" type="search">
<button type="submit">Search receipts</button>
</form>
<form action="/receipts/approve" method="post">
<input type="hidden" name="receipt_id" value="R-47">
<button type="submit">Approve R-47</button>
</form>What the markup guarantees
The POST endpoint must authenticate the user, authorize the specific receipt, validate the ID, and apply a request-forgery defense appropriate to its session model. A hidden input can be edited by a client.
Cost and limits
Native form submission works without JavaScript and has predictable keyboard behavior. Network and server costs depend on the endpoint and payload, not on the presence of a form element.
Common Mistakes
- Do not use GET for a destructive action.
- A hidden field is still client input.
- Controls without a name are not submitted as normal form entries.
Connected lessons
- HTML labels: bind each control to a durable accessible name
- HTML form names and disabled controls: know which values submit
- HTML constraint validation: improve feedback without trusting the browser
Related: HTML character references: escape data before inserting it into markup.
Related: HTML labels: bind each control to a durable accessible name.
Related: HTML form names and disabled controls: know which values submit.
Related: HTML constraint validation: improve feedback without trusting the browser.
Related: HTML radio and checkbox controls: submit choices with explicit values.
Related: HTML file upload forms: declare multipart encoding and bound the server.
Related: HTML link versus button: navigation and actions have different contracts.
Related: HTML receipt review form project: one native flow with clear server boundaries.
Continue with HTML form ownership: connect an external submit button deliberately.
Related: HTML submit overrides: one form, two deliberate destinations.
Related: HTML hidden inputs: carry a token without treating it as secret.
Related: HTML submitter value: identify which button sent the form.
Continue with HTML search form: pair a search landmark with a real GET result route.
Continue with the connected Web Development lesson: Form submission: validate on the server and return field errors.
