Jan 18
Encrypt URL parameters
When using redirect on completion, we can currently assign URL parameters (e.g. FirstName=@FName). This is great, but users could easily tamper with the URL just by editing it - leaving form data open to tampering which is a security risk.
It would be great to have the option to encrypt URL parameters (maybe by random string generation).
For example - I have a form which allows customers to select a product, use a passcode to apply a discount, and then it sends the price information by redirect to a payment service. However, users can just look at the URL, figure out what the price parameter is, change the price parameter by simple edit, and pay whatever they want.
Pending
Ditto. Have the same problem. Wish they allowed custom JS to 'clean' the url, like forms.io