diff --git a/public/js/login.js b/public/js/login.js
index 43877d5..7b14d73 100644
--- a/public/js/login.js
+++ b/public/js/login.js
@@ -10,7 +10,7 @@ async function doLogin() {
const res = await fetch(`${API}/api/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
- body: JSON.stringify({ username, password }),
+ body: JSON.stringify({ username, password, website: document.getElementById('hpWebsite').value }),
});
const data = await res.json().catch(() => ({}));
if (res.ok && data.token) {
diff --git a/public/login.html b/public/login.html
index f96d8b0..8fbbd6f 100644
--- a/public/login.html
+++ b/public/login.html
@@ -25,6 +25,7 @@ body{font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;b
Админ-панель
+
Неверный логин или пароль
diff --git a/server.js b/server.js
index dbd237b..2f0019b 100644
--- a/server.js
+++ b/server.js
@@ -653,6 +653,10 @@ async function logAudit(req, action, target) {
app.post('/api/auth/login', apiLimiter, async (req, res) => {
const rawUsername = typeof req.body?.username === 'string' ? req.body.username.trim().toLowerCase() : '';
const password = String(req.body?.password || '');
+ if (typeof req.body?.website === 'string' && req.body.website) {
+ await recordFailure(req, 'honeypot', 1, BAN_TTL_MS);
+ return res.status(401).json({ error: 'Неверный логин или пароль' });
+ }
if (!rawUsername || rawUsername.length > 100 || !password) {
return res.status(401).json({ error: 'Неверный логин или пароль' });
}