Using Anti Spam Fields in Enterprise Forms

Enterprise Forms includes an Anti Spam field that you can configure as either a Slider or a Honeypot. These fields help reduce automated spam submissions in forms.

Slider

When you configure an Anti Spam field as a Slider, the frontend renders a slider widget (or similar component). JavaScript adds a name-value pair for the slider to the form before submission. On the backend, the validation rule for the Slider requires that the field is present and contains a non-empty value.

The Enterprise Forms demo project provides an "Anti-Spam Form" that uses a Slider implemented with a jQuery-based widget. For implementation details, review the relevant demo templates to see how Slider-type Anti Spam fields are supported.

Honeypot

When you configure an Anti Spam field as a Honeypot, the field is rendered invisible to users. Human users do not see or fill in the field. The backend validation rule for the Honeypot requires that the field is empty when the form is submitted.

The Enterprise Forms demo project includes an "Anti-Spam Form" with a Honeypot field. This field is rendered with a custom CSS class (typically using display:none), or with a style="display:none" attribute if no custom class is specified. For implementation details, refer to the relevant demo templates to see how Honeypot-type Anti Spam fields are supported.

Important:
When using Anti Spam fields, your project must support at least the Slider field type. The Slider's validation requires a non-empty value, so the frontend must render and submit this field. If you do not support the Honeypot field, the form will still work, but the field will not provide any protection if it is not present in the DOM.

Disabling Anti Spam Fields

By default, the Anti Spam field type is available in the CMS form editor and can be added to forms. If your project does not support this field type, disable it to prevent building forms with incomplete or ineffective spam protection.

To disable the Anti Spam field type (or any other field type), update the repository-based configuration for the Enterprise Forms document type (eforms:form). In the Console, navigate to:

/hippo:namespaces/eforms/form/editor:templates/_default_/root/cluster.options

Add the following value to the multi-valued String property field.exclude:

com.onehippo.cms7.eforms.cms.fields.AntiSpamField

To automate this change for deployment, add a YAML definition with an add operation in your project's repository-data-application module:

definitions: config: /hippo:namespaces/eforms/form/editor:templates/_default_/root/cluster.options: field.exclude: operation: add type: string value: [com.onehippo.cms7.eforms.cms.fields.AntiSpamField]
Share Feedback
Page: /build/enterprise-plugins/enterprise-forms/using-anti-spam-fields
Section: Build
Category *