# Are the form submissions encrypted?

**URL:** <https://discourse.getcockpit.com/t/are-the-form-submissions-encrypted/614>\
**Category:** Uncategorized\
**Created:** [February 27, 2019, 12:29pm UTC](https://discourse.getcockpit.com/t/are-the-form-submissions-encrypted/614 "2019-02-27T12:29:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alanford123](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@alanford123](https://discourse.getcockpit.com/u/alanford123)\
**Post date:** [February 27, 2019, 12:29pm UTC](https://discourse.getcockpit.com/t/are-the-form-submissions-encrypted/614/1 "2019-02-27T12:29:34Z")

</div>

I’ll be accepting user form submissions which will include sensitive data, such ass email, addresses and names. Nothing critical, but nothing that should be allowed to be leaked.

Does cockpit store form submissions in plain text? Can I make sure to harden the forms somehow?

---

<div class="post-metadata">

**Author:** ![pauloamgomes](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/pauloamgomes/32/48_2.png) [@pauloamgomes](https://discourse.getcockpit.com/u/pauloamgomes)\
**Post date:** [February 27, 2019, 1:35pm UTC](https://discourse.getcockpit.com/t/are-the-form-submissions-encrypted/614/2 "2019-02-27T13:35:39Z")

</div>

You can hook in the form save trigger and encrypt the form data, take a look on [https://github.com/owldesign/Encrypt](https://github.com/owldesign/Encrypt), as it provides encryption to collection fields.

---

<div class="post-metadata">

**Author:** ![artur](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/artur/32/4_2.png) [@artur](https://discourse.getcockpit.com/u/artur)\
**Post date:** [February 27, 2019, 3:39pm UTC](https://discourse.getcockpit.com/t/are-the-form-submissions-encrypted/614/3 "2019-02-27T15:39:10Z")

</div>

In general I would ALWAYS do form submissions via https to prevent man in the middle attacks.  
Having them encrypted in the db? well…your choice 🤷‍♂️

---

<div class="post-metadata">

**Author:** ![pauloamgomes](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/pauloamgomes/32/48_2.png) [@pauloamgomes](https://discourse.getcockpit.com/u/pauloamgomes)\
**Post date:** [February 27, 2019, 4:46pm UTC](https://discourse.getcockpit.com/t/are-the-form-submissions-encrypted/614/4 "2019-02-27T16:46:57Z")

</div>

@artur, think it may depend on the data being saved and due to GDPR - [https://gdpr-info.eu/issues/encryption/](https://gdpr-info.eu/issues/encryption/)

---

<div class="post-metadata">

**Author:** ![artur](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/artur/32/4_2.png) [@artur](https://discourse.getcockpit.com/u/artur)\
**Post date:** [February 27, 2019, 10:07pm UTC](https://discourse.getcockpit.com/t/are-the-form-submissions-encrypted/614/5 "2019-02-27T22:07:01Z")

</div>

Right, but then I would implement the encryption on db (system) level

- MongoDB: [https://docs.mongodb.com/manual/tutorial/configure-encryption/](https://docs.mongodb.com/manual/tutorial/configure-encryption/)
- SQLite: [https://www.sqlite.org/see/doc/trunk/www/readme.wiki](https://www.sqlite.org/see/doc/trunk/www/readme.wiki)

I have a special opinion regarding to GDPR but this is another topic 😉
