Security & Regulatory Compliance
Security and regulatory compliance are essential pillars of the PLANOVI web presence. The platform integrates bot deterrence, safe API authentication, input sanitization, and GDPR-compliant privacy mechanisms.
1. Cloudflare Turnstile Bot Defense
The contact inquiry form is shielded against automated spam bots, credential stuffing, and volumetric attacks using Cloudflare Turnstile:
sequenceDiagram
autonumber
actor User as Prospective Client
participant UI as "Browser (index.php)"
participant CF as Cloudflare Turnstile
participant Backend as contact-handler.php
participant Supabase as Supabase Database
User->>UI: Fills name, email, message
UI->>CF: Solves invisible Turnstile challenge
CF-->>UI: Issues cf-turnstile-response token
UI->>Backend: POST /contact-handler.php (JSON payload + token)
Backend->>CF: POST https://challenges.cloudflare.com/turnstile/v0/siteverify
CF-->>Backend: { "success": true, ... }
Backend->>Supabase: POST /rest/v1/website_form_messages
Supabase-->>Backend: 201 Created
Backend-->>UI: { "success": true, "message": "Dziękujemy..." }
Turnstile Verification Routine:
$verifyUrl = 'https://challenges.cloudflare.com/turnstile/v0/siteverify';$postData = http_build_query([ 'secret' => site_config('turnstile.secret_key'), 'response' => $turnstileToken, 'remoteip' => $_SERVER['HTTP_CF_CONNECTING_IP'] ?? $_SERVER['REMOTE_ADDR'] ?? '']);
$ch = curl_init($verifyUrl);curl_setopt($ch, CURLOPT_POST, true);curl_setopt($ch, CURLOPT_POSTFIELDS, $postData);curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);curl_setopt($ch, CURLOPT_TIMEOUT, 10);$result = curl_exec($ch);curl_close($ch);
$cfResponse = json_decode($result, true);if (empty($cfResponse['success'])) { http_response_code(403); echo json_encode(['success' => false, 'message' => __('contact.err_captcha')]); exit;}2. Input Sanitization & Attack Mitigation
- Email Validation: Validated via PHP’s
filter_var($email, FILTER_VALIDATE_EMAIL)before executing downstream queries. - XSS Prevention: Content rendered dynamically into PHP templates passes through
htmlspecialchars()or trusted localized translation dictionaries. - JSON Body & Form Encoded Support:
contact-handler.phphandles both rawapplication/json(php://input) and traditionalmultipart/form-datapayloads, ensuring client compatibility while strictly typing incoming keys.
3. Database Role Isolation (Supabase REST)
- Interactions with Supabase are performed using the project’s Anon Key over HTTPS.
- Row Level Security (RLS) policies within Supabase restrict public insert operations strictly to the
website_form_messagestable. - Table reads for form messages are locked down so unauthenticated public users cannot inspect contact submissions.
- System status queries in
status.phpaccess the public read-only tableapp_modulesand its joined maintenance recordsapp_modules_maintenance.
4. GDPR & Cookie Compliance
- Cookie Banner (
cookie-banner.php): A non-intrusive floating glassmorphic consent dialog informs visitors regarding essential cookies (session and language preferences). - Persistent Consent: User consent is stored in
localStorageundercookie_consent_planovito avoid re-prompting on subsequent visits. - Legal Document Transparency: Formal PDF documents for Terms of Service (Regulamin) and Privacy Policy (Polityka Prywatności) are maintained in
documents/and accessible on-demand viadocumentation.php.