SilentShield 2.6 closes a gap that cost one shop its checkout registrations: forms that are sent with a button click and AJAX instead of a regular submit were not reported to us. This article explains what happened, what changes and what you need to do. The full list is on the changelog.
What went wrong
The widget measures typing and mouse movement and reports the result when a visitor submits a form. It listened for the browser’s submit event. Some shops never trigger that event. The OpenCart 3 checkout, for example, loads the registration step by AJAX and sends it with a plain button and jQuery.ajax.
The result: your server asked /v1/verify about a visitor for whom we had received nothing but the first page event. Without typing and mouse data the verdict was “suspicious”, and the registration failed for a real person. The form was protected, but the protection could not see the visitor.
What changes
With version 2.6 the widget also recognises this kind of submission. It looks at the request that carries the behavior_nonce. If that request leaves the page without a submit event and the form has not been checked yet, the widget holds it for a moment, reports the submission with the collected typing and mouse data, and sends the request once the verdict is in. If no answer comes within 15 seconds, the request is sent anyway and your server decides, as before.
Everything else stays as it was: forms with a regular submit, requests without a nonce and plain page posts are not touched.
How we tested it
We rebuilt the OpenCart checkout in our local test environment with real jQuery and let a simulated customer server call /v1/verify. With the switch off, the click-and-AJAX form was rejected (HTTP 403, “suspicious”, reasons NO_TYPING_PAUSES and NO_MOUSE_MOVEMENT). With the switch on, the same visitor was accepted (HTTP 200, “human”). A form with a regular submit, a plain page post and a request without a nonce behaved the same with the switch on and off.
What to know
- It covers requests made with
XMLHttpRequest, which includesjQuery.ajax. Forms sent withfetch()are not covered yet, except the WooCommerce block checkout, which has its own handling. - Your server-side check does not change. Keep calling
/v1/verifywith the nonce.