Skip to content

Security & Regulatory Compliance

Security and regulatory compliance are essential pillars of the PLANOVI web presence. The platform integrates bot deterrence, safe API authentication, input sanitization, and GDPR-compliant privacy mechanisms.


1. Cloudflare Turnstile Bot Defense

The contact inquiry form is shielded against automated spam bots, credential stuffing, and volumetric attacks using Cloudflare Turnstile:

sequenceDiagram
    autonumber
    actor User as Prospective Client
    participant UI as "Browser (index.php)"
    participant CF as Cloudflare Turnstile
    participant Backend as contact-handler.php
    participant Supabase as Supabase Database

    User->>UI: Fills name, email, message
    UI->>CF: Solves invisible Turnstile challenge
    CF-->>UI: Issues cf-turnstile-response token
    UI->>Backend: POST /contact-handler.php (JSON payload + token)
    Backend->>CF: POST https://challenges.cloudflare.com/turnstile/v0/siteverify
    CF-->>Backend: { "success": true, ... }
    Backend->>Supabase: POST /rest/v1/website_form_messages
    Supabase-->>Backend: 201 Created
    Backend-->>UI: { "success": true, "message": "Dziękujemy..." }

Turnstile Verification Routine:

$verifyUrl = 'https://challenges.cloudflare.com/turnstile/v0/siteverify';
$postData = http_build_query([
'secret' => site_config('turnstile.secret_key'),
'response' => $turnstileToken,
'remoteip' => $_SERVER['HTTP_CF_CONNECTING_IP'] ?? $_SERVER['REMOTE_ADDR'] ?? ''
]);
$ch = curl_init($verifyUrl);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, $postData);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_TIMEOUT, 10);
$result = curl_exec($ch);
curl_close($ch);
$cfResponse = json_decode($result, true);
if (empty($cfResponse['success'])) {
http_response_code(403);
echo json_encode(['success' => false, 'message' => __('contact.err_captcha')]);
exit;
}

2. Input Sanitization & Attack Mitigation

  • Email Validation: Validated via PHP’s filter_var($email, FILTER_VALIDATE_EMAIL) before executing downstream queries.
  • XSS Prevention: Content rendered dynamically into PHP templates passes through htmlspecialchars() or trusted localized translation dictionaries.
  • JSON Body & Form Encoded Support: contact-handler.php handles both raw application/json (php://input) and traditional multipart/form-data payloads, ensuring client compatibility while strictly typing incoming keys.

3. Database Role Isolation (Supabase REST)

  • Interactions with Supabase are performed using the project’s Anon Key over HTTPS.
  • Row Level Security (RLS) policies within Supabase restrict public insert operations strictly to the website_form_messages table.
  • Table reads for form messages are locked down so unauthenticated public users cannot inspect contact submissions.
  • System status queries in status.php access the public read-only table app_modules and its joined maintenance records app_modules_maintenance.

  • Cookie Banner (cookie-banner.php): A non-intrusive floating glassmorphic consent dialog informs visitors regarding essential cookies (session and language preferences).
  • Persistent Consent: User consent is stored in localStorage under cookie_consent_planovi to avoid re-prompting on subsequent visits.
  • Legal Document Transparency: Formal PDF documents for Terms of Service (Regulamin) and Privacy Policy (Polityka Prywatności) are maintained in documents/ and accessible on-demand via documentation.php.