protect against bots with timeouts
This commit is contained in:
@@ -2,4 +2,18 @@ class ApplicationController < ActionController::Base
|
||||
# Prevent CSRF attacks by raising an exception.
|
||||
# For APIs, you may want to use :null_session instead.
|
||||
protect_from_forgery with: :exception
|
||||
|
||||
INPUT_TIMEOUT = 2.seconds # We estimate that a user needs more then x seconds to enter some informations
|
||||
|
||||
# calculate how long a user needed for a form input, ussually we just
|
||||
def input_to_fast?
|
||||
fail 'session[:form_timestamp] not set' unless session[:form_timestamp]
|
||||
duration = Time.now - session[:form_timestamp].to_time
|
||||
duration < INPUT_TIMEOUT
|
||||
end
|
||||
|
||||
# Set the current timestamp that marks entering a form
|
||||
def set_form_timestamp
|
||||
session[:form_timestamp] = Time.now
|
||||
end
|
||||
end
|
||||
|
||||
@@ -1,14 +1,16 @@
|
||||
class SupportersController < ApplicationController
|
||||
before_filter :set_form_timestamp, only: :new
|
||||
|
||||
def new
|
||||
@supporter = Supporter.new
|
||||
end
|
||||
|
||||
def create
|
||||
@supporter = Supporter.new supporter_form_params
|
||||
if @supporter.save
|
||||
if !input_to_fast? && @supporter.save
|
||||
redirect_to thanks_path
|
||||
else
|
||||
flash.now[:danger] = t 'shared.actions.failed'
|
||||
flash.now[:danger] = t '.timeout' if input_to_fast?
|
||||
render :new
|
||||
end
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user