A Read-Only Form Field Can Still Submit a Value

Illustrated browser cards passing between a device and stacked storage shapes
AI-generated conceptual illustration, not a product photograph or software screenshot.

A field you cannot edit may be read-only or disabled, and those states have different effects. Looking grey is not enough to identify which rule the form uses.

MDN’s readonly reference explains that supported read-only controls remain focusable, while disabled controls are not submitted with the form and cannot receive focus.

Try a harmless sample

In a local practice form, create two named text fields containing fictional identifiers. Make one read-only and the other disabled. Inspect the submitted form data in your own test environment. The visual inability to type into both fields does not make their submission behaviour identical.

For a form author, this matters when a displayed reference number is expected to accompany a submission. Test the actual data received rather than assuming that every visible value is sent.

Neither attribute is a security boundary. A server must validate the request and obtain authoritative values where necessary; a browser control does not make client-supplied data trustworthy.

For a visitor, a field that cannot be changed may reflect the form’s intended workflow. Read the surrounding instructions or contact the operator if its value is wrong. Do not substitute incorrect information elsewhere just to force the form through.

Editorial illustration from this site’s image library; not documentary evidence of the example or object discussed.