diff --git a/framework-docs/modules/ROOT/pages/web/webmvc-view/mvc-jsp.adoc b/framework-docs/modules/ROOT/pages/web/webmvc-view/mvc-jsp.adoc index 190480ef8f0..dfbefbc36a9 100644 --- a/framework-docs/modules/ROOT/pages/web/webmvc-view/mvc-jsp.adoc +++ b/framework-docs/modules/ROOT/pages/web/webmvc-view/mvc-jsp.adoc @@ -45,10 +45,10 @@ or see the tag library description. [[mvc-view-jsp-formtaglib]] == Spring's form tag library -As of version 2.0, Spring provides a comprehensive set of data binding-aware tags for -handling form elements when using JSP and Spring Web MVC. Each tag provides support for -the set of attributes of its corresponding HTML tag counterpart, making the tags -familiar and intuitive to use. The tag-generated HTML is HTML 4.01/XHTML 1.0 compliant. +Spring provides a comprehensive set of data binding-aware tags for handling form elements +when using JSP and Spring Web MVC. Each tag provides support for the set of attributes of +its corresponding HTML tag counterpart, making the tags familiar and intuitive to use. +The tag-generated HTML is HTML 4.01/XHTML 1.0 compliant. Unlike other form/input tag libraries, Spring's form tag library is integrated with Spring Web MVC, giving the tags access to the command object and reference data your @@ -74,7 +74,7 @@ page: where `form` is the tag name prefix you want to use for the tags from this library. [[mvc-view-jsp-formtaglib-formtag]] -=== The Form Tag +=== The `form` Tag This tag renders an HTML 'form' element and exposes a binding path to inner tags for binding. It puts the command object in the `PageContext` so that the command object can @@ -163,9 +163,14 @@ following example shows: [[mvc-view-jsp-formtaglib-inputtag]] === The `input` Tag -This tag renders an HTML `input` element with the bound value and `type='text'` by default. -For an example of this tag, see <>. You can also use -HTML5-specific types, such as `email`, `tel`, `date`, and others. +This tag renders an HTML `input` element with the bound value and `type='text'` by +default. For an example of this tag, see <>. You can +also use HTML5-specific types, such as `email`, `tel`, `date`, and others, by supplying a +`type` attribute. See <> for details. + +NOTE: Do not use the `input` tag with `type='password'`. Use the +<> instead, since it does not render +the bound value by default. [[mvc-view-jsp-formtaglib-checkboxtag]] === The `checkbox` Tag @@ -374,6 +379,8 @@ by using `itemValue` and the label by using `itemLabel`, as the following exampl === The `password` Tag This tag renders an HTML `input` tag with the type set to `password` with the bound value. +Use this tag, instead of the <> with +`type='password'`, for password fields. [source,xml,indent=0,subs="verbatim,quotes"] ---- @@ -805,7 +812,15 @@ Kotlin:: The Spring form tag library allows entering dynamic attributes, which means you can enter any HTML5 specific attributes. -The form `input` tag supports entering a type attribute other than `text`. This is -intended to allow rendering new HTML5 specific input types, such as `email`, `date`, -`range`, and others. Note that entering `type='text'` is not required, since `text` -is the default type. +The form `input` tag supports entering a `type` attribute other than `text`. This is +intended to allow rendering HTML5 specific input types, such as `email`, `date`, `range`, +and others. Note that entering `type='text'` is not required, since `text` is the default +type. + +The `input` tag does not support `type='checkbox'` or `type='radio'`. Use the +<> and +<> tags instead. For any supported +type, the bound value is rendered as-is. + +NOTE: Do not use `type='password'` with the `input` tag. Use the +<> for password fields. diff --git a/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/InputTag.java b/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/InputTag.java index 056f7bfda47..44177ed3288 100644 --- a/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/InputTag.java +++ b/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/InputTag.java @@ -25,6 +25,16 @@ import org.jspecify.annotations.Nullable; * The {@code } tag renders an HTML 'input' tag with type 'text' using * the bound value. * + *

A different {@code type}, such as {@code email}, {@code tel}, {@code date}, + * or {@code range}, may be supplied as a dynamic attribute. The bound value is + * rendered as-is for any supported {@code type}. {@code checkbox} and + * {@code radio} are not supported; use the {@code } and {@code } + * tags instead. + * + *

NOTE: Do not use this tag with {@code type="password"}. + * Use the {@code } tag ({@link PasswordInputTag}) for password fields, + * since it does not render the bound value unless explicitly configured to do so. + * *

Attribute Summary

* * @@ -381,6 +391,8 @@ public class InputTag extends AbstractHtmlInputElementTag { /** * Flags {@code type="checkbox"} and {@code type="radio"} as illegal * dynamic attributes. + *

Any other {@code type} is permitted, but {@code type="password"} should + * not be used with this tag. Use {@link PasswordInputTag} instead. */ @Override protected boolean isValidDynamicAttribute(String localName, Object value) { diff --git a/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/PasswordInputTag.java b/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/PasswordInputTag.java index d05b0e4a608..b5120557cdc 100644 --- a/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/PasswordInputTag.java +++ b/spring-webmvc/src/main/java/org/springframework/web/servlet/tags/form/PasswordInputTag.java @@ -22,6 +22,10 @@ import jakarta.servlet.jsp.JspException; * The {@code } tag renders an HTML 'input' tag with type 'password' * using the bound value. * + *

Use this tag instead of the {@code } tag ({@link InputTag}) with + * {@code type="password"} for password fields. By default, the bound value is + * not rendered. + * *

Attribute Summary

*
* diff --git a/spring-webmvc/src/main/resources/META-INF/spring-form.tld b/spring-webmvc/src/main/resources/META-INF/spring-form.tld index dbafb776061..9ee792a619f 100644 --- a/spring-webmvc/src/main/resources/META-INF/spring-form.tld +++ b/spring-webmvc/src/main/resources/META-INF/spring-form.tld @@ -198,7 +198,7 @@ - Renders an HTML 'input' tag with type 'text' using the bound value. + Renders an HTML 'input' tag with type 'text' using the bound value. A different type (for example, 'email' or 'date') may be supplied as a dynamic attribute, but 'checkbox' and 'radio' are not supported. Do not use this tag for passwords; use the 'password' tag instead. input org.springframework.web.servlet.tags.form.InputTag empty @@ -395,7 +395,7 @@ - Renders an HTML 'input' tag with type 'password' using the bound value. + Renders an HTML 'input' tag with type 'password'. The bound value is not rendered unless 'showPassword' is true. Use this tag instead of 'input' with type 'password'. password org.springframework.web.servlet.tags.form.PasswordInputTag empty