Solution 1 :

1) Don’t use any sensitive data (credentials, Passwords) in the URL.

2) if the action is missing then the form submits to itself thats the reason your form submits to same page.

You have to specify action.

Use JavaScript or jquery functions, here is the example from jquery:

<script src=""></script>
  $(function () {
    $('form').on('submit', function (e) {         

        type: 'post',
        url: 'file',
        data: $('form').serialize(),
        success: function () {
          alert('form submitted');

Problem :

I was trying to figure out a post request for a login form that basically looks like this:

 <form method="post">
                <table class="table">
                            <td><input type="text" class="form-control form-control-sm" name="user" /></td>
                            <td><input type="password" class="form-control form-control-sm" name="pass" /></td>
                            <td colspan="2" class="text-right"><button type="submit" class="btn btn-primary">Login</button></td>

I do know the username and password for the login but I wanted to construct a post request url to achieve the same thing.

After some research I found out that if there is no action that the form posts to the same url

The landing url is something like:

So I tried :

However, this does not work and it redirects me back to the login page.

I cannot figure out what is wrong with my method


Comment posted by The Head Rush

You sent the login credentials in a GET request using request parameters written into a querystring. For this to work, the server needs an endpoint listening for a GET request with user and pass parameters at the request URL. Apparently, it doesn’t have one.

Comment posted by green coder

I did the same url in postman with a post request but it does not work either

Comment posted by darkhouse

does the for have an action?

Comment posted by green coder

No it doesn’t. I didn’t know that a form can not have an action and still post till today


Leave a Reply

Your email address will not be published. Required fields are marked *