Block example.com emails and homesites under 10
Spam submissions were still getting through with placeholder data. Two more content filters on the public form endpoints: - Reject emails from reserved documentation domains (example.com/.org/ /.net/.edu and subdomains) and reserved TLDs (.test/.example/.invalid/ localhost). testing@example.com and friends are never real leads. - Reject a homesites count below 10. Real associations are larger; the junk uses 0/1/2. Both are validated server-side in security.js (validateEmail gains a domain blocklist, new validateHomesites) and mirrored client-side in app.js for immediate feedback. The homesites input min attribute goes from 1 to 10. Blocked submissions return 400 with a `field` hint and store nothing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
42
security.js
42
security.js
@@ -147,6 +147,8 @@ const MESSAGES = {
|
||||
email_required: 'Please enter your email address.',
|
||||
email_invalid: 'Please enter a valid email address.',
|
||||
email_too_long: 'That email address is too long.',
|
||||
email_blocked: 'Please use a valid work or personal email address.',
|
||||
homesites_too_low: 'Please enter the number of homesites in your community (minimum 10).',
|
||||
};
|
||||
|
||||
const STATUS = { rate_limited: 429, honeypot: 400 };
|
||||
@@ -167,6 +169,26 @@ const EMAIL_RX = /^[A-Za-z0-9](?:[A-Za-z0-9._%+-]{0,62}[A-Za-z0-9])?@[A-Za-z0-9]
|
||||
// C0/C1 control characters and DEL — includes the CR/LF used for header injection.
|
||||
const CONTROL_CHARS_RX = /[\x00-\x1F\x7F-\x9F]/;
|
||||
|
||||
// Domains that are never a real lead. These are the IANA reserved documentation
|
||||
// domains (RFC 2606) plus reserved TLDs, which is what spam bots reach for.
|
||||
// A submitted domain is blocked when it equals one of these or is a subdomain
|
||||
// of one (e.g. `mail.example.com`).
|
||||
const BLOCKED_EMAIL_DOMAINS = new Set([
|
||||
'example.com', 'example.org', 'example.net', 'example.edu',
|
||||
]);
|
||||
const BLOCKED_EMAIL_TLDS = new Set(['test', 'example', 'invalid', 'localhost']);
|
||||
|
||||
function isBlockedDomain(domain) {
|
||||
const d = domain.toLowerCase();
|
||||
const tld = d.slice(d.lastIndexOf('.') + 1);
|
||||
if (BLOCKED_EMAIL_TLDS.has(tld)) return true;
|
||||
|
||||
for (const blocked of BLOCKED_EMAIL_DOMAINS) {
|
||||
if (d === blocked || d.endsWith('.' + blocked)) return true;
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Validate an email address.
|
||||
* Returns { ok: true, email } with the normalised (trimmed, lower-cased) value,
|
||||
@@ -204,10 +226,28 @@ function validateEmail(raw, { required = true } = {}) {
|
||||
if (local.length > 64 || domain.length > 253) return { ok: false, reason: 'email_too_long' };
|
||||
if (email.includes('..')) return { ok: false, reason: 'email_invalid' };
|
||||
if (!EMAIL_RX.test(email)) return { ok: false, reason: 'email_invalid' };
|
||||
if (isBlockedDomain(domain)) return { ok: false, reason: 'email_blocked' };
|
||||
|
||||
return { ok: true, email: email.toLowerCase() };
|
||||
}
|
||||
|
||||
// ── Homesites validation ─────────────────────────────────
|
||||
// Real associations have at least this many units; smaller values are the
|
||||
// placeholder junk (0, 1, 2…) the spam submissions use.
|
||||
const MIN_HOMESITES = 10;
|
||||
|
||||
/**
|
||||
* Validate a homesites count.
|
||||
* Returns { ok: true, homesites } (a finite number) or { ok: false, reason }.
|
||||
*/
|
||||
function validateHomesites(raw) {
|
||||
const n = typeof raw === 'number' ? raw : parseFloat(raw);
|
||||
if (!Number.isFinite(n) || n < MIN_HOMESITES) {
|
||||
return { ok: false, reason: 'homesites_too_low' };
|
||||
}
|
||||
return { ok: true, homesites: n };
|
||||
}
|
||||
|
||||
/**
|
||||
* Run every protection layer for a public form POST.
|
||||
* Returns { ok: true, ip } or { ok: false, status, error, reason }.
|
||||
@@ -276,6 +316,8 @@ module.exports = {
|
||||
issueFormToken,
|
||||
guardSubmission,
|
||||
validateEmail,
|
||||
validateHomesites,
|
||||
MIN_HOMESITES,
|
||||
messageFor,
|
||||
publicConfig,
|
||||
clientIp,
|
||||
|
||||
Reference in New Issue
Block a user