June 11, 2012, 09:05

It'd maybe be smart to clear the form before posting it back to your own server (if you're putting node behind a proxy with request logging). And for that matter, you could also append the submit button to the form via JS so that a user won't post it directly to your server if they happen to have JS turned off... After all, the point of everything Stripe's doing is to AVOID posting sensitive data to (potentially) insecure servers.

