diff --git a/public/js/login.js b/public/js/login.js index 43877d5..7b14d73 100644 --- a/public/js/login.js +++ b/public/js/login.js @@ -10,7 +10,7 @@ async function doLogin() { const res = await fetch(`${API}/api/auth/login`, { method: 'POST', headers: { 'Content-Type': 'application/json' }, - body: JSON.stringify({ username, password }), + body: JSON.stringify({ username, password, website: document.getElementById('hpWebsite').value }), }); const data = await res.json().catch(() => ({})); if (res.ok && data.token) { diff --git a/public/login.html b/public/login.html index f96d8b0..8fbbd6f 100644 --- a/public/login.html +++ b/public/login.html @@ -25,6 +25,7 @@ body{font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;b

Админ-панель

+
Неверный логин или пароль
На главную
diff --git a/server.js b/server.js index dbd237b..2f0019b 100644 --- a/server.js +++ b/server.js @@ -653,6 +653,10 @@ async function logAudit(req, action, target) { app.post('/api/auth/login', apiLimiter, async (req, res) => { const rawUsername = typeof req.body?.username === 'string' ? req.body.username.trim().toLowerCase() : ''; const password = String(req.body?.password || ''); + if (typeof req.body?.website === 'string' && req.body.website) { + await recordFailure(req, 'honeypot', 1, BAN_TTL_MS); + return res.status(401).json({ error: 'Неверный логин или пароль' }); + } if (!rawUsername || rawUsername.length > 100 || !password) { return res.status(401).json({ error: 'Неверный логин или пароль' }); }