protect against bots with timeouts

This commit is contained in:
2015-10-06 09:16:07 +02:00
parent 99390a5e5a
commit b381cbf066
9 changed files with 56 additions and 2 deletions
+14
View File
@@ -2,4 +2,18 @@ class ApplicationController < ActionController::Base
# Prevent CSRF attacks by raising an exception.
# For APIs, you may want to use :null_session instead.
protect_from_forgery with: :exception
INPUT_TIMEOUT = 2.seconds # We estimate that a user needs more then x seconds to enter some informations
# calculate how long a user needed for a form input, ussually we just
def input_to_fast?
fail 'session[:form_timestamp] not set' unless session[:form_timestamp]
duration = Time.now - session[:form_timestamp].to_time
duration < INPUT_TIMEOUT
end
# Set the current timestamp that marks entering a form
def set_form_timestamp
session[:form_timestamp] = Time.now
end
end
+4 -2
View File
@@ -1,14 +1,16 @@
class SupportersController < ApplicationController
before_filter :set_form_timestamp, only: :new
def new
@supporter = Supporter.new
end
def create
@supporter = Supporter.new supporter_form_params
if @supporter.save
if !input_to_fast? && @supporter.save
redirect_to thanks_path
else
flash.now[:danger] = t 'shared.actions.failed'
flash.now[:danger] = t '.timeout' if input_to_fast?
render :new
end
end