Accessibility: Zoho form honeypot input sits silently in DOM #194
Labels
No Label
P0
P1
P2
P3
accessibility
backend
bug
content
data-integrity
enhancement
frontend
infra
integration
owner
owner-input
performance
phase-7
phase-8
release-blocker
security
seo
ui
ux
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: null/Queue-North-Website#194
Loading…
Reference in New Issue
No description provided.
Delete Branch "%!s(<nil>)"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: Minor
Description: The honeypot input in Contact.jsx has
aria-hidden="true"andreadOnly. Low risk but could confuse screen readers.File:
src/pages/Contact.jsxlines 242-243Fix direction: Move honeypot outside the
<form>or usetabIndex={-1}instead ofreadOnly.Already correct in the current code — the issue describes attributes that are not there.
It states the honeypot has aria-hidden='true' and readOnly, and proposes using tabIndex={-1} instead of readOnly.
src/pages/Contact.jsx:277-286 as it stands:
type='text' name='company_website' tabIndex={-1} autoComplete='off'
aria-hidden='true' style={{ display: 'none' }}
There is no readOnly. tabIndex={-1} is already there — the exact change this issue asks for. And the decisive attribute is style={{display:'none'}}: a display:none element is removed from the accessibility tree entirely, so no screen reader ever reaches it, which is a stronger guarantee than either aria-hidden or moving the field outside the form.
Closing as no change required.
Verify: read src/pages/Contact.jsx around the 'Honeypot' comment — the input carries tabIndex={-1} and display:none, and carries no readOnly attribute.