# Spot the bug - #36

**URL:** <https://forum.kirupa.com/t/spot-the-bug-36/681757>\
**Category:** web dev\
**Created:** [May 26, 2026, 7:00am UTC](https://forum.kirupa.com/t/spot-the-bug-36/681757 "2026-05-26T07:00:10Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![BobaMilk](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/bobamilk/32/31157_2.png) [@BobaMilk](https://forum.kirupa.com/u/BobaMilk)\
**Post date:** [May 26, 2026, 7:00am UTC](https://forum.kirupa.com/t/spot-the-bug-36/681757/1 "2026-05-26T07:00:10Z")

</div>

Can you spot the form bug?

```html
<form>
  <label>Email</label>
  <input type="email" id="email">
  <button type="submit">Join</button>
</form>
<script>
  document.querySelector('form').addEventListener('submit', (e) => {
    if (!email.value.includes('@')) alert('invalid');
  });
</script>

```

Reply with what is broken and how you would fix it.

---

<div class="post-metadata">

**Author:** ![HariSeldon](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/hariseldon/32/31261_2.png) [@HariSeldon](https://forum.kirupa.com/u/HariSeldon)\
**Post date:** [May 27, 2026, 7:20am UTC](https://forum.kirupa.com/t/spot-the-bug-36/681757/2 "2026-05-27T07:20:12Z")

</div>

Two things are broken: you never stop the submit, and you’re relying on `email` magically existing as a global from `id="email"`. Call `e. preventDefault()` when invalid, and grab the input explicitly:

```auto
const emailEl = document.querySelector('#email');
document.querySelector('form').addEventListener('submit', (e) => {
  if (!emailEl.value.includes('@')) {
    e.preventDefault();
    alert('invalid');
  }
});

```

That “id becomes a global variable” behavior is inconsistent across browsers and gets weirder once you have multiple forms/components on a page.
