1003 B
1003 B
Contact Feature Spec
Current Implementation
Public flow
- Public contact page exists at
/contact
- Form fields:
- name
- phone
- company
- message
- Submission uses a server action
- Success redirects to
/success
Protection
- Validation uses
zod
- Optional Cloudflare Turnstile verification
- Optional rate limiting by IP window
Delivery
- Messages are sent by SMTP through
nodemailer
- Recipient configuration comes from admin settings
- Messages are not persisted in the database
Admin controls
- SMTP settings page
- Test email action
- Contact protection settings page
Risks
- Contact history is lost if email delivery succeeds but later needs auditing
- Rate-limit counters are stored in
AppConfig
which mixes operational and business configuration
Recommended Improvements
- Store contact submissions if the business needs pipeline visibility
- Add spam and abuse observability
- Add structured delivery error reporting