protect against bots with timeouts

This commit is contained in:
2015-10-06 09:16:07 +02:00
parent 99390a5e5a
commit b381cbf066
9 changed files with 56 additions and 2 deletions
+3
View File
@@ -15,3 +15,6 @@
*/
@import "bootstrap-sprockets"
@import "bootstrap"
body
padding-top: 20px
+14
View File
@@ -2,4 +2,18 @@ class ApplicationController < ActionController::Base
# Prevent CSRF attacks by raising an exception.
# For APIs, you may want to use :null_session instead.
protect_from_forgery with: :exception
INPUT_TIMEOUT = 2.seconds # We estimate that a user needs more then x seconds to enter some informations
# calculate how long a user needed for a form input, ussually we just
def input_to_fast?
fail 'session[:form_timestamp] not set' unless session[:form_timestamp]
duration = Time.now - session[:form_timestamp].to_time
duration < INPUT_TIMEOUT
end
# Set the current timestamp that marks entering a form
def set_form_timestamp
session[:form_timestamp] = Time.now
end
end
+4 -2
View File
@@ -1,14 +1,16 @@
class SupportersController < ApplicationController
before_filter :set_form_timestamp, only: :new
def new
@supporter = Supporter.new
end
def create
@supporter = Supporter.new supporter_form_params
if @supporter.save
if !input_to_fast? && @supporter.save
redirect_to thanks_path
else
flash.now[:danger] = t 'shared.actions.failed'
flash.now[:danger] = t '.timeout' if input_to_fast?
render :new
end
end
+2
View File
@@ -5,5 +5,7 @@ html
= javascript_include_tag 'application', 'data-turbolinks-track' => true
= csrf_meta_tags
body
= console if Rails.env.development?
.container
= render 'shared/flashes'
= yield
+5
View File
@@ -0,0 +1,5 @@
- if flash.any?
#flashes
- flash.each do |type, message|
div class="alert alert-#{type} fade in"
= message