Block example.com emails and homesites under 10

Spam submissions were still getting through with placeholder data. Two
more content filters on the public form endpoints:

- Reject emails from reserved documentation domains (example.com/.org/
  /.net/.edu and subdomains) and reserved TLDs (.test/.example/.invalid/
  localhost). testing@example.com and friends are never real leads.
- Reject a homesites count below 10. Real associations are larger; the
  junk uses 0/1/2.

Both are validated server-side in security.js (validateEmail gains a
domain blocklist, new validateHomesites) and mirrored client-side in
app.js for immediate feedback. The homesites input min attribute goes
from 1 to 10. Blocked submissions return 400 with a `field` hint and
store nothing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-24 09:30:15 -04:00
parent 5f4af3886c
commit 1219117adf
4 changed files with 73 additions and 5 deletions

View File

@@ -469,7 +469,7 @@
<div class="calc-grid">
<div class="calc-field">
<label for="calcHomesites">Number of homesites</label>
<input type="number" id="calcHomesites" placeholder="e.g. 150" min="1" />
<input type="number" id="calcHomesites" placeholder="e.g. 150" min="10" />
</div>
<div class="calc-field">
<label for="calcPropertyType">Property type</label>