Search by

florentingarnier / sylius-spam-protection-plugin

FlorentinGarnier

Protects the Sylius shop contact, registration and password reset forms with florentingarnier/spam-protection-bundle.

Package info

github.com/FlorentinGarnier/sylius-spam-protection-plugin

Type:sylius-plugin

pkg:composer/florentingarnier/sylius-spam-protection-plugin

Statistics

Installs: 4

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

v0.2.1 2026-10-06 21:01 UTC

This package is auto-updated.

Last update: 2026-10-06 21:03:27 UTC


README

CI Latest Version Total Downloads License: MIT Sylius

Protects the public forms of your Sylius shop against spam bots, without reCAPTCHA and without any puzzle for your customers. It relies on florentingarnier/spam-protection-bundle: a honeypot, single-use timed tokens, a proof of work solved by the browser, per-form rate limiting, IP reputation and gibberish detection.

Sylius form Scope Free text checked
Contact (ContactType) contact message
Registration (CustomerRegistrationType) registration —
Password reset request (UserRequestPasswordResetType) password_reset —

Requirements

  • PHP 8.2 or later
  • Sylius 1.14. Sylius 1.12 and 1.13 are no longer maintained: their dependencies have security advisories that will never be fixed. Use version 0.1 of the plugin with them.
  • JavaScript in the customer's browser

Sylius 1.14 requires api-platform/core 2.7, whose releases are all affected by security advisories. Composer 2.9 and later refuses to install them unless your project ignores these advisories, as this plugin does for its own CI in composer.json (config.policy.advisories.ignore-id). This concerns Sylius itself, not the plugin, which does not use API Platform.

Sylius 2

Sylius 2 is not supported yet. Two changes are needed:

  • its shop templates use Twig Hooks instead of template events, so the fields must be rendered through hooks;
  • its registration form is a Live Component, which submits the form on every re-render: the protection must skip these validation requests, or it would count them as rejected attempts.

Contributions are welcome.

Installation

  1. Require the plugin:

    composer require florentingarnier/sylius-spam-protection-plugin
  2. If you do not use Symfony Flex, enable the bundle and the plugin:

    // config/bundles.php
    return [
        // ...
        FlorentinGarnier\SpamProtectionBundle\FlorentinGarnierSpamProtectionBundle::class => ['all' => true],
        FlorentinGarnier\SyliusSpamProtectionPlugin\FlorentinGarnierSyliusSpamProtectionPlugin::class => ['all' => true],
    ];
  3. Load the JavaScript solver in your shop theme, as explained in the bundle documentation. Without it, the protected forms cannot be submitted.

  4. Download the IP reputation lists, then schedule the command daily:

    bin/console spam-protection:refresh-ip-lists

Configuration is optional: see the bundle documentation.

How the fields are rendered

The Sylius shop templates end their forms with render_rest: false, so a field added to a form is not rendered automatically. The plugin renders the protection in the forms' template events, with a priority of -100:

  • sylius.shop.contact.request.form
  • sylius.shop.register.form
  • sylius.shop.request_password_reset_token.form

If your theme overrides these templates:

  • It still calls the template events: nothing to do.
  • It renders form.spam_protection itself: nothing to do either. The plugin skips a field that is already rendered.
  • It calls neither: render the field in the form with {{ form_row(form.spam_protection) }}.

To remove the block from an event, for example when your theme renders the field elsewhere:

# config/packages/sylius_ui.yaml
sylius_ui:
    events:
        sylius.shop.contact.request.form:
            blocks:
                florentin_garnier_spam_protection: false

Protecting other forms

Any Symfony form can be protected with the bundle's form type, including your own shop forms:

use FlorentinGarnier\SpamProtectionBundle\Form\SpamProtectionType;

$builder->add('spam_protection', SpamProtectionType::class, [
    'protection_scope' => 'quotation',
    'content_fields' => ['message'],
]);

Testing

composer install
vendor/bin/phpunit

Contributing

Contributions are welcome. Please read CONTRIBUTING.md and the Code of Conduct. Report security issues privately, as described in SECURITY.md.

License

Released under the MIT License.