HTML forms send user-entered data to a server-side page for processing. In Classic ASP, use the Request object to read submitted values. The two common form methods are GET and POST.
Use GET for non-sensitive, bookmarkable parameters such as filters or record IDs. Use POST when submitting changes, larger form bodies, or data that should not be exposed in the URL. Neither method replaces server-side validation or HTTPS.
<form method="post" action="file_name.asp">
...form controls...
</form>
The action attribute identifies the receiving ASP page. The method attribute controls whether the form is submitted through the query string (GET) or request body (POST).
A GET form places name/value pairs in the URL. A URL may look like this:
https://www.plus2net.com/file_name.asp?name=john&country=USA&age=10
Read a named query-string value explicitly:
Dim userName
userName = Request.QueryString("name")
Always quote the field name. The older pattern Request.QueryString(name) can accidentally treat name as a variable instead of the literal form-field name.
Example GET form:
<form method="get" action="my_file.asp">
<label for="name">Your Name</label>
<input type="text" id="name" name="name">
<label for="age">Age</label>
<input type="number" id="age" name="age">
<button type="submit">Submit Data</button>
</form>
The receiving ASP page can read the fields separately:
Dim userName, age
userName = Request.QueryString("name")
age = Request.QueryString("age")
Response.Write "Welcome " & Server.HTMLEncode(userName)
When output contains visitor-controlled text, HTML-encode it before inserting it into the response.
You can inspect all query-string keys during development:
Dim key
For Each key In Request.QueryString
Response.Write Server.HTMLEncode(key) & " = " & _
Server.HTMLEncode(Request.QueryString(key)) & "<br>"
Next
POST sends the form body separately from the URL. A typical POST form looks like this:
<form method="post" action="file_name.asp">
...form controls...
</form>
Read POST fields explicitly with Request.Form:
Dim city
city = Request.Form("city")
Classic ASP also supports the combined Request("city") lookup, but using Request.Form or Request.QueryString explicitly makes the data source clearer.
For diagnostics, POST fields can be enumerated:
Dim key
For Each key In Request.Form
Response.Write Server.HTMLEncode(key) & " = " & _
Server.HTMLEncode(Request.Form(key)) & "<br>"
Next
In application code, normally read only the fields the page expects, validate them on the server, and encode data appropriately for its output context.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.