Download the PHP package eliepse/argile-honeypot without Composer
On this page you can find all versions of the php package eliepse/argile-honeypot. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download eliepse/argile-honeypot
More information about eliepse/argile-honeypot
Files in eliepse/argile-honeypot
Package argile-honeypot
Short Description Honeypot protecting forms from robot spam, made for the Argile Framework
License MIT
Informations about the package argile-honeypot
Argile Honeypot
Argile Honeypot is a simple protection against robot spammers for your public forms. It can be used for various project but has been made to work with the simple Argile framework.
How does it work?
The honeypot consist on hashing input names in the html response (handled by HoneypotResponseMiddleware
), and adding fake inputs (honeypots) with the original
names. Robot spammers will likely fill all fields, espacially the ones that will looks like real fields.
The middleware HoneypotRequestMiddleware
check the POST request from the client and check if fake fields has been
filled. If so, the request is blocked and an 403 response is sent. It also check if the form has been filled quicker
than a certain delay (default to 5 seconds).
How to use it?
First install the package by adding it to your composer.json or requiring it through the command line.
You also have to add the css class "onipat" to hide the fake inputs. A css file is available at
/resources/css/honeypot.css
1. Preparing the form
Then, add the HoneypotResponseMiddleware
to the route containing the form to protect. As an example:
In order for the middlware to work, you have to indicate some common fields copy as honeypot. Simply add the prefix
honeypot:
to the name of the input. Example:
The middleware will automatically change the name of the real field with a hash, and generate a fake field.
2. Handle the POST request
Now, we have to handle the request to block spams and change the inputs names to the original ones (so the rest of the code doesn't have to handle hashed names). Simply add the request middleware to your route as below.
License
This package is under the MIT license.
It is maintained by Élie Meignan.
All versions of argile-honeypot with dependencies
psr/http-message Version ^1.0
psr/http-server-middleware Version ^1.0
psr/http-server-handler Version ^1.0
slim/psr7 Version ^1.2