v3.0.0.0
FlatlyPage
- <?php
- require_once __DIR__ . '/config.php';
- $site_settings = get_site_settings();
- if (session_status() === PHP_SESSION_NONE) {
- session_start();
- }
- function generate_form_token() {
- $token = bin2hex(random_bytes(32));
- $_SESSION['form_token'] = hash('sha256', $token);
- $_SESSION['form_token_time'] = time();
- return $token;
- }
- function validate_form_token($submitted) {
- if (empty($submitted) || empty($_SESSION['form_token'])) {
- return false;
- }
- if (time() - ($_SESSION['form_token_time'] ?? 0) > 1800) {
- return false;
- }
- $valid = hash_equals($_SESSION['form_token'], hash('sha256', $submitted));
- if ($valid) {
- unset($_SESSION['form_token'], $_SESSION['form_token_time']);
- }
- return $valid;
- }
- function validate_contact_form($data) {
- $errors = [];
- if (!empty($data['website'])) {
- $errors['_honeypot'] = 'Bot detected';
- return $errors;
- }
- $load_time = intval($data['_lt'] ?? 0);
- if (time() - $load_time < 3 || time() - $load_time > 3600) {
- $errors['_time'] = 'Please take a moment before submitting';
- }
- if (!validate_form_token($data['_token'] ?? '')) {
- $errors['_token'] = 'Invalid form token, please refresh the page';
- }
- $antibot_input = strtoupper(trim($data['antibot'] ?? ''));
- $antibot_answer = strtoupper($_SESSION['antibot_answer'] ?? '');
- $antibot_age = time() - intval($_SESSION['antibot_time'] ?? 0);
- if (empty($antibot_answer) || $antibot_age > 1800) {
- $errors['antibot'] = 'ANTIBOT expired, please refresh the image';
- } elseif ($antibot_input !== $antibot_answer) {
- $errors['antibot'] = 'Incorrect code, please try again';
- } else {
- unset($_SESSION['antibot_answer'], $_SESSION['antibot_time']);
- }
- if (empty($data['name'])) {
- $errors['name'] = 'Name is required';
- } elseif (strlen($data['name']) > 100) {
- $errors['name'] = 'Name cannot exceed 100 characters';
- }
- if (empty($data['email'])) {
- $errors['email'] = 'Email is required';
- } elseif (!filter_var($data['email'], FILTER_VALIDATE_EMAIL)) {
- $errors['email'] = 'Invalid email format';
- }
- if (empty($data['message'])) {
- $errors['message'] = 'Message is required';
- } elseif (strlen($data['message']) > 5000) {
- $errors['message'] = 'Message cannot exceed 5000 characters';
- }
- return $errors;
- }
- function send_contact_email($name, $email, $message) {
- $to = get_site_settings()['contact_email'];
- $subject = "New Message from " . get_site_settings()['site_name'] . " Contact Form";
- $email_body = "You have received a new message from the contact form.\n\n";
- $email_body .= "- - - - - - MESSAGE DETAILS - - - - - - \n";
- $email_body .= "Name: " . $name . "\n";
- $email_body .= "Email: " . $email . "\n\n";
- $email_body .= "Message:\n" . wordwrap($message, 72) . "\n";
- $email_body .= "- - - - - - - - - - - - - - - \n";
- $email_body .= "Sent on: " . date('Y-m-d H:i:s') . "\n";
- $email_body .= "Automated message from " . get_site_settings()['site_name'] . "\n";
- $headers = "From: " . $email . "\r\n";
- $headers .= "Reply-To: " . $email . "\r\n";
- $headers .= "Content-Type: text/plain; charset=UTF-8\r\n";
- return mail($to, $subject, $email_body, $headers);
- }
- function save_contact_to_file($name, $email, $message) {
- $log_dir = __DIR__ . '/contacts';
- if (!is_dir($log_dir)) {
- mkdir($log_dir, 0755, true);
- }
- $filename = $log_dir . '/contacts_' . date('Y-m') . '.txt';
- $log_entry = "\n" . str_repeat('-', 50) . "\n";
- $log_entry .= "Date: " . date('Y-m-d H:i:s') . "\n";
- $log_entry .= "Name: " . $name . "\n";
- $log_entry .= "Email: " . $email . "\n";
- $log_entry .= "Message:\n" . $message . "\n";
- $log_entry .= str_repeat('-', 50) . "\n";
- return file_put_contents($filename, $log_entry, FILE_APPEND | LOCK_EX);
- }
- if ($_SERVER['REQUEST_METHOD'] === 'POST') {
- $name = trim($_POST['name'] ?? '');
- $email = trim($_POST['email'] ?? '');
- $message = trim($_POST['message'] ?? '');
- $errors = validate_contact_form([
- 'name' => $name,
- 'email' => $email,
- 'message' => $message,
- 'website' => $_POST['website'] ?? '',
- '_lt' => $_POST['_lt'] ?? 0,
- '_token' => $_POST['_token'] ?? '',
- 'antibot' => $_POST['antibot'] ?? '',
- ]);
- $spam_keys = ['_honeypot', '_time', '_token'];
- $is_spam = false;
- foreach ($spam_keys as $k) {
- if (isset($errors[$k])) {
- $is_spam = true;
- break;
- }
- }
- if ($is_spam) {
- $_SESSION['contact_success'] = true;
- header('Location: ' . $_SERVER['PHP_SELF'] . '?slug=' . ($slug ?? 'contact') . '&success=1');
- exit;
- }
- $user_errors = array_diff_key($errors, array_flip($spam_keys));
- if (empty($user_errors)) {
- save_contact_to_file($name, $email, $message);
- $email_sent = send_contact_email($name, $email, $message);
- if ($email_sent) {
- $_SESSION['contact_success'] = true;
- header('Location: ' . $_SERVER['PHP_SELF'] . '?slug=' . ($slug ?? 'contact') . '&success=1');
- exit;
- } else {
- $_SESSION['contact_error'] = 'An error occurred while sending the message. Please try again later.';
- }
- } else {
- $_SESSION['contact_errors'] = $user_errors;
- $_SESSION['contact_data'] = [
- 'name' => $name,
- 'email' => $email,
- 'message' => $message,
- ];
- }
- }
- $_SESSION['form_token_raw'] = generate_form_token();
- function get_contact_message() {
- if (isset($_GET['success']) && $_GET['success'] == '1') {
- return [
- 'type' => 'success',
- 'text' => 'Thank you for your message! We will respond as soon as possible.',
- ];
- }
- if (isset($_SESSION['contact_error'])) {
- $error = $_SESSION['contact_error'];
- unset($_SESSION['contact_error']);
- return ['type' => 'error', 'text' => $error];
- }
- return null;
- }
- function get_contact_data($field) {
- if (isset($_SESSION['contact_data'][$field])) {
- $value = $_SESSION['contact_data'][$field];
- return htmlspecialchars($value, ENT_QUOTES, 'UTF-8');
- }
- return '';
- }
- function get_contact_error($field) {
- if (isset($_SESSION['contact_errors'][$field])) {
- return $_SESSION['contact_errors'][$field];
- }
- return '';
- }
- if (isset($_SESSION['contact_errors']) || isset($_SESSION['contact_data'])) {
- register_shutdown_function(function () {
- unset($_SESSION['contact_errors']);
- unset($_SESSION['contact_data']);
- });
- }