Skip to content

feat: validate that all remote form fields were created with form.fields.foo.as(...)#16331

Merged
Rich-Harris merged 16 commits into
sveltejs:version-3from
ottomated:form-name-prefix
Jul 23, 2026
Merged

feat: validate that all remote form fields were created with form.fields.foo.as(...)#16331
Rich-Harris merged 16 commits into
sveltejs:version-3from
ottomated:form-name-prefix

Conversation

@ottomated

Copy link
Copy Markdown
Contributor

closes #16321

Made the form ID a suffix so it's easier to read in the browser's inspector.


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs
  • This message body should clearly illustrate what problems it solves.
  • Ideally, include a test that fails without this PR but passes with it.

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

@pkg-svelte-dev

pkg-svelte-dev Bot commented Jul 13, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 19cbd86:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/19cbd86fa4c7c4a1c953aba151c28027c24a49cc

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16331

Note

This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed.

@changeset-bot

changeset-bot Bot commented Jul 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 19cbd86

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@ottomated
ottomated changed the base branch from main to version-3 July 13, 2026 04:11
@ottomated ottomated changed the title feat: validate feat: validate that all remote form fields were created with form.fields.foo.as(...) Jul 13, 2026

@vercel vercel Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additional Suggestions:

  1. handle_focusout fails to strip the /form_id suffix from the field name, so touched/can_validate are keyed with the raw suffixed name instead of the clean key, breaking field.touched() and validation-skipping for non-array fields.
  1. Stale-submitter cleanup wrongly clears a field's reactive input value on every submit because form_data keys retain the / suffix that strip_prefix doesn't remove, so the presence check never matches previous_submitter_name.

Fix on Vercel

Comment thread packages/kit/src/runtime/client/remote-functions/form.svelte.js
@teemingc teemingc added the forms Stuff relating to forms and form actions label Jul 13, 2026
@ottomated

Copy link
Copy Markdown
Contributor Author

Writing this made me realize the whole form key parsing thing is duplicated in a lot of places (removing [] from the end, stripping the n: or b: prefix, and now validating the form name suffix); maybe refactoring that should be part of this PR because this feels like it'll be a nightmare to maintain?

Comment thread packages/kit/src/runtime/app/server/remote/form.js Outdated
@Rich-Harris

Copy link
Copy Markdown
Member

Yeah, I've occasionally thought the same thing but never got round to acting on it

@ottomated
ottomated marked this pull request as draft July 13, 2026 21:18

@Rich-Harris Rich-Harris left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@Rich-Harris
Rich-Harris marked this pull request as ready for review July 23, 2026 11:54
@Rich-Harris
Rich-Harris merged commit 7390dbe into sveltejs:version-3 Jul 23, 2026
16 of 17 checks passed
Rich-Harris pushed a commit that referenced this pull request Jul 24, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/kit@3.0.0-next.12

### Major Changes

- breaking: rename `Pathname` type to `Path` and `Asset` to `AssetPath`
([#16430](#16430))
  breaking: remove leading `/` from `Path` and `AssetPath`
- breaking: write tsconfig to `node_modules/$app/tsconfig`
([#16458](#16458))

- breaking: error on `event.url`, `event.params` and `event.route`
access inside queries
([#16452](#16452))

- breaking: delete `$service-worker` module
([#16450](#16450))

- breaking: detect new deployments on data, remote, and form action
responses, tab focus, and visibility change, and default
`version.pollInterval` to 1 hour
([#16496](#16496))

### Minor Changes

- feat: add `$app/manifest` module with `immutable`, `assets`,
`prerendered`, and `routes` exports
([#16372](#16372))

- feat: validate that all remote form fields were created with
form.fields.foo.as(...)
([#16331](#16331))

- feat: make `$app/paths` importable in service workers
([#16441](#16441))

- feat: `$app/service-worker` module
([#16458](#16458))

- feat: better tsconfig validation
([#16458](#16458))

- fix: default cookies to `secure` to `false` during development
([#16462](#16462))

### Patch Changes

- fix: allow `undefined` values to be passed to form field `.as(...)`
where applicable ([#15681](#15681))

- fix: include queries refreshed from within another query in the
serialized response
([#16461](#16461))

- fix: generate sourcemaps for remote modules
([#16440](#16440))

- fix: avoid empty getElementById() call on hash routing navigation
([#16448](#16448))

- fix: warn if hook files are spelled as "hook" instead of "hooks"
([#16483](#16483))

- chore: deprecate the `alias` option
([#16470](#16470))

- fix: prevent infinite loops when server-side queries refresh each
other in a cycle during the single-flight drain
([#16461](#16461))

- fix: populate `version` in service workers
([#16434](#16434))

- fix: resolve remote modules as external during dev prebundling so
packages can re-export remote functions
([#16426](#16426))

- fix: refetch route-tracking server data when navigating away from an
error page ([#16381](#16381))

- fix: serialize `query(...).set(...)`/`query(...).refresh()` values
into the rendered HTML when called from within a query during SSR
([#16461](#16461))

- fix: fall back to the page's form actions when a sibling endpoint has
no POST handler ([#16349](#16349))

- fix: return a lightweight 404 instead of rendering the error page for
subresource requests
([#16463](#16463))

- fix: preserve stripped path prefixes by making trailing-slash
redirects relative
([#16431](#16431))

- chore: deduplicate type-stripping logic in `tweak_types`
([#16454](#16454))

- fix: more informative error message when running a command inside a
query or prerender function
([`eb5c973`](eb5c973))
## @sveltejs/adapter-cloudflare@8.0.0-next.3

### Patch Changes

- chore: bump `@cloudflare/workers-types` to `4.20260621.1`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12
## @sveltejs/adapter-netlify@7.0.0-next.4

### Patch Changes

- fix: await `init` on every request to prevent race condition
([#16467](#16467))

- chore: bump Rolldown to `1.2.0`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12
## @sveltejs/adapter-node@6.0.0-next.6

### Patch Changes

- fix: preserve stripped path prefixes by making trailing-slash
redirects relative
([#16431](#16431))

- chore: bump Rolldown to `1.2.0`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12
## @sveltejs/adapter-vercel@7.0.0-next.3

### Patch Changes

- fix: await `init` on every request to prevent race condition
([#16467](#16467))

- chore: bump Rolldown to `1.2.0`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

forms Stuff relating to forms and form actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tighten up form transport stuff

3 participants