Last modified by Agnease on 2026/06/16 17:18

From version 16.32
edited by Agnease
on 2026/06/16 16:42
Change comment: There is no comment for this version
To version 16.46
edited by Agnease
on 2026/06/16 17:00
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -5,20 +5,37 @@
5 5  
6 6   #set ($name = '')
7 7   #set ($email = '')
8 + ## Fields to help preventing bots filled forms.
8 8   #set ($contactWebsite = '')
10 + #set ($startedAtRaw = '')
9 9  
10 10   #foreach ($parameterName in $request.parameterNames)
11 - #set ($propertyName = $parameterName.split('_0_')[1])
12 - #if ($propertyName == 'name')
13 - #set ($name = $stringtool.trim($request.get($parameterName)))
14 - #elseif ($propertyName == 'email')
15 - #set ($email = $stringtool.trim($request.get($parameterName)))
16 - #elseif ($propertyName == 'contactWebsite')
17 - #set ($contactWebsite = $stringtool.trim($request.get($parameterName)))
13 + #set ($propertyParts = $parameterName.split('_0_'))
14 + #if ($propertyParts.size() > 1)
15 + #set ($propertyName = $parameterName.split('_0_')[1])
16 + #if ($propertyName == 'name')
17 + #set ($name = $stringtool.trim($request.get($parameterName)))
18 + #elseif ($propertyName == 'email')
19 + #set ($email = $stringtool.trim($request.get($parameterName)))
20 + #elseif ($propertyName == 'contactWebsite')
21 + #set ($contactWebsite = $stringtool.trim($request.get($parameterName)))
22 + #elseif ($propertyName == 'contactStartedAt')
23 + #set ($startedAtRaw = $stringtool.trim($request.get($parameterName)))
24 + #end
18 18   #end
19 19   #end
20 20  
21 - #if ("$!contactWebsite.trim()" != '')
28 + #if ("$!startedAtRaw" != '')
29 + #set ($startedAt = $numbertool.toNumber($startedAtRaw))
30 + #set ($now = $datetool.systemDate.time)
31 + #set ($elapsed = $now - $startedAt)
32 +
33 + ## Reject submissions faster than 10 seconds.
34 + #if ($elapsed > 0 && $elapsed < 10000)
35 + #set ($discard = $response.setStatus(400))
36 + #jsonResponse({'message': 'Please take a moment to describe your XWiki request before submitting.'})
37 + #end
38 + #elseif ("$!contactWebsite.trim()" != '')
22 22   #set ($statusCode = 400)
23 23   #set ($message = 'The request could not be sent. Please try again or contact Agnease by email.')
24 24   #elseif ("$!name" == '' && "$!email" == '')
... ... @@ -116,6 +116,7 @@
116 116   tabindex="-1"
117 117   />
118 118   </div>
136 + <input type="hidden" name="Agnease.Code.ContactRequest.ContactRequestClass_0_contactStartedAt" value="$datetool.getsystemDate.time" />
119 119   <input id="contactSubmit" type="submit" class="btn btn-primary" value="Send my request">
120 120   </form>
121 121   #end
XWiki.StyleSheetExtension[0]
code
... ... @@ -67,7 +67,7 @@
67 67   font-weight: 700;
68 68  }
69 69  /* CSS for hidden field to identify requests filled by bots. */
70 -.contact-hp-wrapperss {
70 +.contact-hp-wrapper {
71 71   position: absolute;
72 72   left: -9999px;
73 73   width: 1px;