feat: phase 5 contact form — hCaptcha, honeypot, rate limit, notify
Working /contact POST flow: honeypot → hCaptcha server-verify → field validation → SlowAPI 3/hr IP rate limit → contact_submissions row → best-effort Resend notification (Reply-To = submitter) → generic success page. Spam paths don't persist and render the same success page (anti-enumeration). Send failures don't break the request path — the row is already durable. New services: HCaptchaService (async httpx + dev fallback), ContactService. EmailService gains send_contact_notification. Production config validator now requires ADMIN_CONTACT_EMAIL, HCAPTCHA_SECRET, HCAPTCHA_SITE_KEY. 23 new tests, all green. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
17
app/templates/emails/contact_notification.txt
Normal file
17
app/templates/emails/contact_notification.txt
Normal file
@@ -0,0 +1,17 @@
|
||||
{# Plaintext body for the admin contact-form notification email.
|
||||
Mirrors the HTML version so clients that reject HTML still get a
|
||||
readable message. #}New contact submission
|
||||
======================
|
||||
|
||||
Name: {{ submission_name }}
|
||||
Email: {{ submission_email }}
|
||||
Submitted at: {{ submitted_at }}
|
||||
IP: {{ ip }}
|
||||
|
||||
Message
|
||||
-------
|
||||
{{ message }}
|
||||
|
||||
--
|
||||
Replying to this email will respond directly to the sender
|
||||
({{ submission_email }}).
|
||||
Reference in New Issue
Block a user