TallyT
Tally
Jan 18

Encrypt URL parameters

When using redirect on completion, we can currently assign URL parameters (e.g. FirstName=@FName). This is great, but users could easily tamper with the URL just by editing it - leaving form data open to tampering which is a security risk. It would be great to have the option to encrypt URL parameters (maybe by random string generation). For example - I have a form which allows customers to select a product, use a passcode to apply a discount, and then it sends the price information by redirect to a payment service. However, users can just look at the URL, figure out what the price parameter is, change the price parameter by simple edit, and pay whatever they want.
PendingPending

Dec 28, 2024

Ditto. Have the same problem. Wish they allowed custom JS to 'clean' the url, like forms.io