Add reCAPTCHA support to registration.

Because I *hate* spam bots.
This commit is contained in:
James Mason 2017-11-03 17:41:26 -07:00
parent 464b148321
commit a7fce677fc
No known key found for this signature in database
GPG key ID: 1B3951886C449023
6 changed files with 52 additions and 9 deletions

View file

@ -44,6 +44,9 @@ gem 'omniauth-openid'
gem 'omniauth-google-oauth2'
gem 'omniauth-github'
# Bot-filtering
gem 'recaptcha', require: 'recaptcha/rails'
# as authorization framework
gem 'cancancan'

View file

@ -420,6 +420,8 @@ GEM
loggability (~> 0.12)
rdoc (~> 5.0)
yajl-ruby (~> 1.3)
recaptcha (4.6.2)
json
redcarpet (3.2.3)
referer-parser (0.2.1)
request_store (1.1.0)
@ -636,6 +638,7 @@ DEPENDENCIES
rails-i18n (~> 4.0.0)
rails_12factor
rdoc-generator-fivefish
recaptcha
redcarpet
responders (~> 2.0)
rolify

View file

@ -1,3 +1,5 @@
@import "bootstrap/mixins";
html {
position: relative;
min-height: 100%;
@ -104,3 +106,12 @@ p.comment-body {
.qr-image{
margin-left: 120px;
}
.g-recaptcha {
@include clearfix;
padding-bottom: 12px;
div {
float: right;
}
}

View file

@ -1,5 +1,5 @@
class RegistrationsController < Devise::RegistrationsController
before_action :configure_permitted_parameters, if: :devise_controller?
prepend_before_action :check_captcha, only: [:create]
def edit
@openids = Openid.where(user_id: current_user.id).order(:provider)
@ -21,14 +21,35 @@ class RegistrationsController < Devise::RegistrationsController
edit_user_registration_path(resource)
end
def configure_permitted_parameters
devise_parameter_sanitizer.permit(:account_update) do |u|
u
.permit(:email, :password, :password_confirmation, :current_password, :username, :email_public)
private
def sign_up_params
params.require(:user).permit(
:email,
:password,
:password_confirmation,
:name,
:username
)
end
devise_parameter_sanitizer.permit(:sign_up) do |u|
u
.permit(:email, :password, :password_confirmation, :name, :username)
def account_update_params
params.require(:user).permit(
:email,
:password,
:password_confirmation,
:current_password,
:username,
:email_public
)
end
def check_captcha
unless verify_recaptcha
self.resource = resource_class.new sign_up_params
resource.validate # Look for any other validation errors besides Recaptcha
respond_with_navigational(resource) { render :new }
end
end
end

View file

@ -12,6 +12,7 @@
= f.input :name, input_html: { required: true }, hint: 'This is your real name'
= f.input :password, input_html: { required: true }
= f.input :password_confirmation, input_html: { required: true }
= recaptcha_tags
%p.text-right
= f.action :submit, as: :button, label: 'Sign Up', button_html: { class: 'btn btn-success' }

View file

@ -63,3 +63,7 @@ OSEM_SMTP_OPENSSL_VERIFY_MODE=""
# Enable the usage of the devise ichain plugin
OSEM_ICHAIN_ENABLED=false
# ReCAPTCHA keys
RECAPTCHA_SITE_KEY=""
RECAPTCHA_SECRET_KEY=""