mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 11:55:05 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — anti-spam protection for all `/go` lead-gen forms. ## What is the current behavior? The shared `MarketingForm` used by every `/go` page has no spam protection: no honeypot, no captcha, no timing check, no dedupe. The Datadog NYC exec dinner form was getting probed with spam submissions ([DEBR-280](https://linear.app/supabase/issue/DEBR-280/reduce-spammy-submissions-on-exec-dinner-form)). ## What is the new behavior? Three layered defenses added to the shared `MarketingForm` + `submitFormAction` so every `/go` form is covered: 1. **Honeypot** — hidden `website` input (off-screen, `aria-hidden`, `tabIndex={-1}`). Server returns a fake success when filled so bots don't probe variations. The field is stripped from the payload before CRM fan-out. 2. **Minimum render-time check** — server rejects submissions that come back in under 3s with a fake success. 3. **Per-session email/form dedupe** — `sessionStorage` keyed by `formGuid`/`database_id` + email blocks double-submits; the success state is shown without re-hitting HubSpot/Customer.io/Notion. ## Additional context No new env vars or services required. Honeypot rejections are logged via \`console.warn\` for monitoring. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enhanced anti-spam protections (honeypot and minimum render time) to block bots. * Prevents accidental duplicate submissions within the same browser session. * Avoids creating duplicate contact/record entries when an existing email is found in storage. * **Other Improvements** * Cleaner event/context data sent to analytics for more accurate tracking. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45842) <!-- end of auto-generated comment: release notes by coderabbit.ai -->