Add abuse protection to the ROI calculator form
The calculator endpoint was open to anyone, and it has been collecting spam submissions. Add a layered guard that runs before anything is written to the DB or sent to the AI provider: - Cloudflare Turnstile CAPTCHA, verified server-side (active when TURNSTILE_* keys are configured; fails closed if unverifiable) - Honeypot field that only bots fill in - Signed, single-use form token enforcing a 4s minimum fill time - Per-IP rate limiting (5 per 10 min, 25 per 24h) Layers 2-4 need no configuration and work on their own, so submissions are throttled immediately; adding Turnstile keys upgrades it to a full challenge. Blocked submissions now stop the flow client-side instead of silently showing a result. Also sets `trust proxy` for correct client IPs behind nginx, caps the JSON body at 32kb, and fixes a latent ReferenceError in the "AI not configured" branch that called saveCalcSubmission() before the variables it closes over were declared. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -509,8 +509,17 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Honeypot: hidden from humans, irresistible to bots. Leave it empty. -->
|
||||
<div class="calc-hp" aria-hidden="true">
|
||||
<label for="hpCompanyUrl">Company website</label>
|
||||
<input type="text" id="hpCompanyUrl" name="hp_company_url" tabindex="-1" autocomplete="off" />
|
||||
</div>
|
||||
|
||||
<p class="calc-error hidden" id="calcError">Please fill in homesites and annual dues income to continue.</p>
|
||||
|
||||
<!-- CAPTCHA widget — rendered only when Turnstile keys are configured -->
|
||||
<div class="calc-captcha" id="calcCaptcha"></div>
|
||||
|
||||
<div class="calc-email-row">
|
||||
<div class="calc-field calc-field--full">
|
||||
<label for="calcEmail">Your email address <span class="calc-optional">(recommended)</span></label>
|
||||
|
||||
Reference in New Issue
Block a user