Spam submissions were still getting through with placeholder data. Two
more content filters on the public form endpoints:
- Reject emails from reserved documentation domains (example.com/.org/
/.net/.edu and subdomains) and reserved TLDs (.test/.example/.invalid/
localhost). testing@example.com and friends are never real leads.
- Reject a homesites count below 10. Real associations are larger; the
junk uses 0/1/2.
Both are validated server-side in security.js (validateEmail gains a
domain blocklist, new validateHomesites) and mirrored client-side in
app.js for immediate feedback. The homesites input min attribute goes
from 1 to 10. Blocked submissions return 400 with a `field` hint and
store nothing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>