# Encrypt Post Data Before Submit and Decrypt it in Controller

**URL:** <https://discourse.cakephp.org/t/encrypt-post-data-before-submit-and-decrypt-it-in-controller/4328>\
**Category:** Uncategorized\
**Created:** [May 22, 2018, 12:07pm UTC](https://discourse.cakephp.org/t/encrypt-post-data-before-submit-and-decrypt-it-in-controller/4328 "2018-05-22T12:07:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![developers](https://avatars.discourse-cdn.com/v4/letter/d/aca169/32.png) [@developers](https://discourse.cakephp.org/u/developers)\
**Post date:** [May 22, 2018, 12:07pm UTC](https://discourse.cakephp.org/t/encrypt-post-data-before-submit-and-decrypt-it-in-controller/4328/1 "2018-05-22T12:07:39Z")

</div>

Hi All,

I am trying to encrypt the form data before the form submission to secure the data without using the ssl. I got [https://www.phpclasses.org/blog/package/9912/post/1-Encrypt-form-data-without-SSL-in-PHP.html](https://www.phpclasses.org/blog/package/9912/post/1-Encrypt-form-data-without-SSL-in-PHP.html) and is working fine. But it seems it isn’t working in cakephp, if we decrypt it from the ctp file then it is working but it isn’t decrypt the values if we try to decrypt it from the controller. Did anyone use this class for the encryption? or anyone knows how we can encrypt the data before submitting the form? The above class is using the php openssl aes encryption/decryption method.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![zhunt](https://avatars.discourse-cdn.com/v4/letter/z/958977/32.png) [@zhunt](https://discourse.cakephp.org/u/zhunt)\
**Post date:** [May 22, 2018, 6:24pm UTC](https://discourse.cakephp.org/t/encrypt-post-data-before-submit-and-decrypt-it-in-controller/4328/2 "2018-05-22T18:24:43Z")

</div>

Is there any reason you can’t use SSL? Generally it’s considered a bad idea to do browser-side encryption/decryption.

If you still want to go ahead, there are a number of javascript libraries that can handle the encryption/decryption on the user-end.

[https://www.quora.com/What-are-some-of-the-best-client-side-encryption-libraries](https://www.quora.com/What-are-some-of-the-best-client-side-encryption-libraries)

> <https://gist.github.com/jo/8619441>

  

> **[Comparing Performance of JavaScript Cryptography Libraries](https://medium.com/@encryb/comparing-performance-of-javascript-cryptography-libraries-42fb138116f3)**
>
> Cryptography is a computationally intensive application and has typically performed poorly in JavaScript. Recent additions of raw binary…

---

<div class="post-metadata">

**Author:** ![dakota](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/dakota/32/1421_2.png) [@dakota](https://discourse.cakephp.org/u/dakota)\
**Post date:** [May 23, 2018, 11:48am UTC](https://discourse.cakephp.org/t/encrypt-post-data-before-submit-and-decrypt-it-in-controller/4328/3 "2018-05-23T11:48:28Z")

</div>

Why no SSL? Thanks to [lets encrypt](https://letsencrypt.org/) it’s free to get a certificate. Client-side encryption is not secure at all (Since the encryption key needs to be sent to the client in order to be used)
