4 ms·
Ask HN: Is isTrusted in DOM event reliable?
I'm curious about prevent spam bot submitting forms (well, beside using captcha).
Some DOM events, for example MouseEvent, or FormEvent contains a boolean, read-only property `isTrusted`. Basically, to see if the action was performed by the user, we check if `event.isTrusted` is `true`.
From what I saw, there is one case to bypass a form `submit` event. When the form has a submit button (which does nothing). If I click the button through JavaScript, the button's `click` event will have `isTrusted = false`. But when it bubble up, the form's `submit` event will have `isTrusted` became `true`.
Is there any other case, isTrusted not reliable?
- phillipseamore 6y agoThe isTrusted flag won't help out with that, it's primarily an indicator that the event follows a user gesture and can escalate privileges (like playing audio). A spam bot will usually not be using an actual browser (or running JS) - and if it were it could easily say all events are trusted.
- docuru 6y agoCan you give an example? I asume spam bot should run in a browser-like enviroment (i.e puppeteer), which events should behave the same (i.e `isTrusted` will always be `false` since events are not real).
- trinovantes 6y agoA malicious bot developer can just compile their own browser and set the flag to be true
- docuru 6y agoAlright. I forgot that people can roll their own browser. Update: I did a little research, but still unsure if it is possible to modify `isTrusted` from the core (Chromium, Qt).
- phillipseamore 6y agoHow are you guarding you endpoints? Most bots just scrape and parse HTML/JS looking for form actions, fields, fetches and XHRs and send straight to the endpoints. No browser engines involved.
- docuru 6y agoFor the APIs, that'd be rate limiting and blacklist IPs. It doesn't completely stop spam, but would reduce them. Is there any other method should I be thinking about?
- phillipseamore 6y agoI've used all kinds of things through the years; CAPTCHAs, expiring tokens, signed endpoint URLs. For local websites I've also simply blocked IP ranges from various countries (sometimes even down to all other states/countries). All your focus should be on doing validation at the endpoint, doing stuff on the client side (not related to validation at the endpoint) is a waste of time.
- docuru 6y agoHmm, true. Thanks for the useful insights