1/** 2 * @file 3 * Unlock protected forms. 4 * 5 * This works by resetting the form action to the path that It should be as well 6 * as injecting the secret form key, only if the current user is verified to be 7 * human which is done by waiting for a mousemove, swipe, or tab/enter key to be 8 * pressed. 9 */ 10 11((Drupal, drupalSettings) => { 12 drupalSettings.antibot = drupalSettings.antibot || {}; 13 Drupal.antibot = {}; 14 15 Drupal.behaviors.antibot = { 16 attach(context, settings) { 17 drupalSettings = settings; 18 // Assume the user is not human, despite JS being enabled. 19 if (typeof drupalSettings.antibot !== 'undefined') { 20 drupalSettings.antibot.human = false; 21 } 22 23 // Wait for a mouse to move, indicating they are human. 24 document.body.addEventListener('mousemove', () => { 25 // Unlock the forms. 26 Drupal.antibot.unlockForms(); 27 }); 28 29 // Wait for a touch move event, indicating that they are human. 30 document.body.addEventListener('touchmove', () => { 31 // Unlock the forms. 32 Drupal.antibot.unlockForms(); 33 }); 34 35 // A tab or enter key pressed can also indicate they are human. 36 document.body.addEventListener('keydown', (e) => { 37 if (e.code === 'Tab' || e.code === 'Enter') { 38 // Unlock the forms. 39 Drupal.antibot.unlockForms(); 40 } 41 }); 42 }, 43 }; 44 45 /** 46 * Unlock all locked forms. 47 */ 48 Drupal.antibot.unlockForms = () => { 49 // Act only if we haven't yet verified this user as being human. 50 if (!drupalSettings.antibot.human) { 51 // Check if there are forms to unlock. 52 if (drupalSettings.antibot.forms !== undefined) { 53 // Iterate all antibot forms that we need to unlock. 54 Object.values(drupalSettings.antibot.forms).forEach((config) => { 55 // Switch the action. 56 const form = document.getElementById(config.id); 57 if (form) { 58 form.setAttribute('action', form.getAttribute('data-action')); 59 60 // Set the key. 61 const input = form.querySelector('input[name="antibot_key"]'); 62 if (input) { 63 input.value = config.key 64 .split('') 65 .reverse() 66 .join('') 67 .match(/.{1,2}/g) 68 .map((value) => value.split('').reverse().join('')) 69 .join(''); 70 } 71 } 72 }); 73 } 74 // Mark this user as being human. 75 drupalSettings.antibot.human = true; 76 } 77 }; 78})(Drupal, drupalSettings);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.