Add abuse protection to the ROI calculator form

The calculator endpoint was open to anyone, and it has been collecting
spam submissions. Add a layered guard that runs before anything is
written to the DB or sent to the AI provider:

- Cloudflare Turnstile CAPTCHA, verified server-side (active when
  TURNSTILE_* keys are configured; fails closed if unverifiable)
- Honeypot field that only bots fill in
- Signed, single-use form token enforcing a 4s minimum fill time
- Per-IP rate limiting (5 per 10 min, 25 per 24h)

Layers 2-4 need no configuration and work on their own, so submissions
are throttled immediately; adding Turnstile keys upgrades it to a full
challenge. Blocked submissions now stop the flow client-side instead of
silently showing a result.

Also sets `trust proxy` for correct client IPs behind nginx, caps the
JSON body at 32kb, and fixes a latent ReferenceError in the
"AI not configured" branch that called saveCalcSubmission() before the
variables it closes over were declared.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-23 07:13:14 -04:00
parent 50fdbb1b1d
commit 04ef642775
6 changed files with 383 additions and 8 deletions

View File

@@ -509,8 +509,17 @@
</div>
</div>
<!-- Honeypot: hidden from humans, irresistible to bots. Leave it empty. -->
<div class="calc-hp" aria-hidden="true">
<label for="hpCompanyUrl">Company website</label>
<input type="text" id="hpCompanyUrl" name="hp_company_url" tabindex="-1" autocomplete="off" />
</div>
<p class="calc-error hidden" id="calcError">Please fill in homesites and annual dues income to continue.</p>
<!-- CAPTCHA widget — rendered only when Turnstile keys are configured -->
<div class="calc-captcha" id="calcCaptcha"></div>
<div class="calc-email-row">
<div class="calc-field calc-field--full">
<label for="calcEmail">Your email address <span class="calc-optional">(recommended)</span></label>