(function () {
try {
// AQ-r2 (2026-06-09): respect the explicit-denial sentinel
// written by cookie-consent-harden.js writeATR() on any
// marketing-axis denial (payload.marketing === false; cycle-3 F1).
// Without this gate, the next page navigation re-creates
// gmx_first_touch from the current URL+referrer+utm_*+click_ids,
// silently undoing the reject-all deletion (sweep finding #1).
// The sentinel is cleared the moment the visitor grants
// marketing in the banner (analytics-only grant does NOT
// clear), restoring the writer path on the very next
// page load. Page-cache-safe: the sentinel is a
// browser-resident cookie checked in the inline script, so
// varnish/breeze-served HTML still hits this gate.
if (/(?:^|;\s*)gmx_consent_denied=1(?:;|$)/.test(document.cookie || '')) return;
var CLICK_IDS = ['gclid','fbclid','msclkid','ttclid','wbraid','gbraid','li_fat_id'];
var qs = new URLSearchParams(window.location.search);
var urlClickIdKey = null;
for (var i = 0; i < CLICK_IDS.length; i++) {
if (qs.get(CLICK_IDS[i])) { urlClickIdKey = CLICK_IDS[i]; break; }
}// Parse existing cookie.
var existing = null;
var match = document.cookie.match(/(?:^|;\s*)gmx_first_touch=([^;]+)/);
if (match) {
try { existing = JSON.parse(decodeURIComponent(match[1])); } catch (e) { existing = null; }
}// GWP-273 — referrer-enrichment branch.
// Keep existing unless either (a) URL carries a new click id
// the stored payload lacks (paid click is a higher-value
// signal and upgrades direct/organic), OR (b) the stored
// payload has empty referrer AND the current document.referrer
// is non-empty + external (Safari/ITP/policy-quirk catch:
// first-hit may have missed the referrer; later same-session
// page-loads can recover it).
var existingHasRef = !!(existing && existing.referrer && existing.referrer !== '');
var docRef = document.referrer || '';
var refHost = '';
if (docRef) {
try {
refHost = new URL(docRef).hostname.replace(/^www\./, '').toLowerCase();
} catch (e) { refHost = ''; }
}
var ownHost = (location.host || '').replace(/^www\./, '').toLowerCase();
var currentExternalRef = !!(refHost && refHost !== ownHost);
var canEnrichRef = !!existing && !existingHasRef && currentExternalRef;if (existing) {
if (!urlClickIdKey && !canEnrichRef) return;
if (urlClickIdKey && existing[urlClickIdKey] && !canEnrichRef) return;
}var utm_keys = [
'utm_source','utm_medium','utm_campaign','utm_content','utm_term',
'utm_adgroup','utm_matchtype','utm_network','utm_device','utm_placement'
];
// GWP-273 — merge-preserving base. When enriching an existing
// payload, retain its landing_url + ts + prior click ids /
// utms; only overlay referrer (and any click id appended below
// via the forEach). Branches with/without urlClickIdKey were
// collapsed — both produced the identical Object.assign — the
// click id is added uniformly later.
//
// GWP-273 design choice: "latest external referrer wins" —
// accepted edge case where a user opens a new external tab
// post-empty-first-touch and returns; low-volume, simple, no
// sentinel flag needed.
var data;
if (existing && canEnrichRef) {
data = Object.assign({}, existing, { referrer: docRef });
} else {
data = { landing_url: window.location.href, referrer: docRef, ts: Date.now() };
}
utm_keys.concat(CLICK_IDS).forEach(function (k) {
var v = qs.get(k);
if (v) data[k] = v;
});
// GWP-208 — carry Meta's first-party click-linker cookies (_fbc
// = fb.1.<ts>.<fbclid>, _fbp) into the captured payload so they
// ride the persistent gmx_first_touch cookie cross-page (LP X →
// LP Y) the same way the URL click-ids do. The CF7 hidden-field
// populator copies the whole payload verbatim, so fbc/fbp reach
// the lead even when the form lives on a page without ?fbclid.
var fbcMatch = document.cookie.match(/(?:^|;\s*)_fbc=([^;]+)/);
if (fbcMatch && fbcMatch[1]) data.fbc = decodeURIComponent(fbcMatch[1]);
var fbpMatch = document.cookie.match(/(?:^|;\s*)_fbp=([^;]+)/);
if (fbpMatch && fbpMatch[1]) data.fbp = decodeURIComponent(fbpMatch[1]);
var encoded = encodeURIComponent(JSON.stringify(data));
if (encoded.length > 3800) return;
var expires = new Date(Date.now() + 90 * 864e5).toUTCString(); // GWP-143 C1: match Google Ads 90-day attribution window
var secure = window.location.protocol === 'https:' ? '; Secure' : '';
document.cookie = 'gmx_first_touch=' + encoded + '; Path=/; Expires=' + expires + '; SameSite=Lax' + secure;
} catch (e) {}
})();
/* Meta Pixel base — inline in wp_head so Breeze Delay-All-JS does not defer it; fbevents.js is async-injected (optimizer-invisible). */
!function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod?
n.callMethod.apply(n,arguments):n.queue.push(arguments)};if(!f._fbq)f._fbq=n;
n.push=n;n.loaded=!0;n.version='2.0';n.queue=[];t=b.createElement(e);t.async=!0;
t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window,document,'script',
'https://connect.facebook.net/en_US/fbevents.js');/* Symmetric with server GMX_Consent: revoke BEFORE init; cookies/sends held until grant. */
fbq('consent', 'revoke');
fbq('init', '1857131551802431');
fbq('track', 'PageView'); /* queued; flushed to Meta only after consent grant *//* Grant bridge — reads the SAME ATR marketing signal as GMX_Consent.applyConsent(). */
(function () {
function read(name){var m=document.cookie.match('(?:^|; )'+name.replace(/([.*+?^${}()|[\]\\])/g,'\\$1')+'=([^;]*)');return m?decodeURIComponent(m[1]):'';}
function marketingGranted(){
try {
var given = read('atr_cookie_notice_consent_given');
if (!given) return false; // undecided -> stay revoked
var c = JSON.parse(read('atr_cookie_notice_consent') || '{}');
return !!(c.marketing || c.ad_storage === 'granted');
} catch (e) { return false; } // NO-SILENT-OK: parse/read failure degrades gracefully to revoked (consent stays held; no marketing send) — not an error to report.
}
function apply(){ if (marketingGranted()) fbq('consent', 'grant'); }
apply();
document.addEventListener('click', function(ev){
if (ev.target && ev.target.closest && ev.target.closest('[class*="atr-cookie"], #atr-cookie-notice')) setTimeout(apply, 50);
}, true);
window.addEventListener('storage', apply);
})();
var breeze_prefetch = {"local_url":"https://gomixapp.com","ignore_remote_prefetch":"1","ignore_list":["/cart/","/checkout/","/my-account/","https://gomixapp.co.il/(.)/u05d4u05d8u05d5u05e4u05e1-u05e0u05e9u05dcu05d7-u05d1u05d4u05e6u05dcu05d7u05d4/","wp-admin","wp-login.php"]};
//# sourceURL=breeze-prefetch-js-extra
Creating secure digital forms for business is the fastest way to save significant time, close deals remotely and keep all customer data protected under ISO 27001. The GoMixApp platform lets you build, send and collect signatures on digital forms from any device — with a legally binding digital signature, full automation and secure cloud storage — with no technical knowledge required.
✓ E2E end-to-end|✓ 300+ customers|★★★★★ Google 5.0
E2E
End-to-end
+500
Screens
+15
Years of experience
+1,000
Projects
09:45
Service agreement form
Full name
John Doe
ID.
•••••••••
I agree to the terms of service
Digital signature
Submit form ←
09:45
Comparison: Why GoMixApp Is the Only Complete Digital Solution
At GoMixApp, your digital form is your business card. Every online form we build for you combines professional design, a legally binding e-signature built into the form and smart automation — so you get digital forms that deliver real results.
Our studio builds a tailored, precise solution for you — from a smooth user experience on every device to complex digital signing cycles. CRM integration solutions and secure cloud storage are available from day one.
Benefits of Creating Online Forms with GoMixApp
Secure Digital Signature
The customer signs remotely on any device — the signature is captured with full legal validity, complete verification data (time, IP, device) and automatic backup in secure cloud storage.
No-Code Form Creation
Build a professional form in minutes with a Drag & Drop editor. Choose ready-made templates or start from scratch — no technical knowledge required.
Compatibility With Any Device
Forms are optimized for mobile, tablet and desktop — the customer fills in and signs from anywhere.
Data Security and Privacy
We encrypt every piece of data with SSL, store it in secure cloud with automatic backups and maintain full ISO 27001 compliance.
Professional Branded Design
Forms designed with your business logo and colors. A professional appearance that conveys credibility to customers.
Diverse Field Types
Text, date, dropdown selection, file upload, signature, GPS location and more. Build a form that fits your needs exactly.
Automatic Delivery
The moment the customer signs — a copy is sent to you and the customer automatically by email. No manual action needed.
Central Organization and Management
All forms are organized in a central dashboard. Search, filter and find any form in seconds. Export to Excel with a click.
Examples of Online Forms
Example of a landing page design for secure digital forms — authentication, signing and end-to-end encrypted data storage.
What Is a Digital Form and Why Does Your Business Need a Digital Contract?
A digital form is the electronic version of a paper form — but with significant advantages. Instead of printing, sending and scanning documents, customers fill in and sign directly from their phone.
Any business that works with contracts, agreements, registration forms or approvals needs digital business forms. Creating online forms lets customers sign a digital contract from anywhere, shortens sales cycles, cuts printing costs and significantly raises closing rates.
With digital forms you:
Shorten closing time — the customer signs in minutes, not days
Save costs — no paper, ink, courier or physical storage
Prevent errors — required fields, automatic validation, no illegible handwriting
Stay compliant — legally binding digital signature under the Electronic Signature Law
Every business sector needs different forms. Here is how businesses in leading sectors use GoMixApp digital forms:
Real Estate and Brokerage
Real-estate brokers use digital forms to sign exclusive listings, brokerage agreements and property visit forms. Instead of arriving with a stack of papers, the broker sends a WhatsApp link, the client signs from their phone and a copy is saved automatically in the cloud.
Property-management companies and homeowner associations use digital forms for signing new tenants, building entry forms, bylaws approvals and more. Tenants sign from their phone — no in-person meeting needed. More on forms for tenant signing →
Schools and Educational Institutions
Educational institutions need registration forms, parental consent, health forms and field-trip forms — all requiring a parent signature. With digital forms, the school sends a link to parents who sign from their phone within minutes. More on forms for educational institutions →
Healthcare and Medicine
Clinics, dentists and medical practices use informed-consent forms, anamnesis questionnaires and patient intake forms. The patient fills in and signs on a tablet in the waiting room or in advance from their phone.
Lawyers and Law Firms
Powers of attorney, fee agreements, new-client forms and affidavits. Lawyers save hours with digital forms that are sent, signed and stored automatically. More on forms for lawyers →
How Do You Create an Online Form With Signature in GoMixApp?
Creating an online form with signature takes only a few minutes. Here is the step-by-step process — no technical knowledge required, suitable for any type of business.
Step 1: Choose a template or start from scratch
Log in to the content editor and choose from dozens of ready-made templates by sector — or start with a blank form.
Step 2: Add fields and content
Drag and drop fields into the form: name, phone, date, signature, file upload and more. Add text, terms of use and a logo.
Step 3: Set up digital signature
Enable a signature field — the customer signs with their finger on the screen or with a mouse. You can set multiple signers on the same form.
Step 4: Send and distribute
Send the form to customers via link, WhatsApp, email or QR. The moment the customer signs — you receive an instant notification.
Digital Signature on Forms — Full Guide
A digital signature (electronic signature) is the legal and secure way to sign documents paperless. In Israel, an electronic signature is recognized by law and is equivalent to a handwritten signature. At GoMixApp every digital contract is stored with full verification data — to ensure full legal validity.
How does it work in GoMixApp?
The customer receives a link to the form
Fills in the details and signs with their finger on the screen
The signature is stored with timestamp, IP address and a unique identifier
A signed copy is sent automatically to both parties
The form is stored in encrypted cloud with automatic backup
Is a digital signature legally valid?
Yes. An advanced electronic signature as defined by law is equivalent to a paper signature. GoMixApp stores all verification data (time, IP, device) to ensure full legal validity.
Data security is not optional — it is a baseline requirement in any digital solution. At GoMixApp every form is protected at the highest level: SSL encryption, secure cloud storage, automatic backups and full ISO 27001 compliance verified by the Standards Institution of Israel.
SSL/TLS encryption — all data is encrypted in transit and at rest
ISO 27001 — compliance with the international information-security management standard
ISO 9001 — certified quality-management system
Automatic backups — data is backed up continuously with restore capability
Access permissions — full control over who can view, edit or delete forms
Timestamp and activity log — every action is recorded for audit and legal validity
More Digital Solutions From GoMixApp
Beyond digital forms, GoMixApp offers a range of solutions for businesses:
Digital Business Card — present your business professionally with a smart business card you can share in a click
“Thank you for years of excellent and professional service. Truly appreciated!”
Inbar Shmueli
Business owner
Service:
★★★★★
Product:
★★★★★
Recommendation:
★★★★★
“Personal and professional service, fast response, great product, very satisfied”
Ariana Negar
Business owner
Service:
★★★★★
Product:
★★★★★
Recommendation:
★★★★★
“Reliable, courteous, professional and understanding service — one of the best I have known”
Join the digital forms revolution with GoMixApp and enjoy not only a great user experience but also significant time savings and maximum efficiency! With our service you can create custom-designed digital forms. Whether it is a web form or an online form, our forms will significantly improve workflows across your organization.
What is the difference between a digital form and a traditional paper form?
A digital form lets you fill in and sign remotely from any device, save automatically in the cloud and integrate with management systems — with no printing, scanning or manual sending. It is faster, more secure and significantly reduces data errors compared with traditional paperwork.
Is a digital signature legally valid in Israel?
Yes. Electronic signatures are recognized in Israel under the Electronic Signature Law, 2001. GoMixApp operates under the AATL standard and stores all verification data (time, IP, device), giving the signature full legal validity recognized in court.
How long does it take to build a digital form in GoMixApp?
Creating secure digital forms for business with GoMixApp takes between 5 and 15 minutes, depending on form complexity. The Drag and Drop editor lets you choose from ready-made templates or build from scratch — without a single line of code.
What security measures are in place in GoMixApp digital forms?
The system includes SSL encryption, secure cloud storage with automatic backups, two-factor authentication and ISO 27001 compliance. All data is protected in accordance with the requirements of the Privacy Protection Authority and GDPR.
Can the digital forms integrate with existing CRM systems?
Yes. GoMixApp supports CRM integration with a wide range of customer-management systems, including automated workflow management. Data from the forms flows directly into your existing systems with no manual transfer needed.
What is signing software and why does my business need it?
Signing software is a digital system that lets you send, fill in and sign documents electronically and remotely, with full legal documentation. Businesses that use it save hours of work each week, close deals faster and improve the customer experience.
Digital Forms vs. Paper Forms — Full Comparison
Feature
Digital forms (GoMixApp)
Traditional paper forms
Digital signature
✓Legally binding e-signature in the AATL standard
✗Requires physical presence and handwritten signature
Data security
✓SSL encryption and full ISO 27001
✗Physical paperwork exposed to loss and theft
Accessibility from any device
✓Mobile, tablet and desktop, anywhere, anytime
✗Requires physical attendance or postal mail
CRM integration
✓Data flows automatically into management systems
✗Requires manual entry and causes data errors
Automatic delivery
✓A copy is sent instantly upon signing completion
✗Requires scanning, filing and manual sending
Workflow management
✓Reminders, approvals and automated signing cycles
✗Manual tracking and sometimes lost documents
Operating cost
✓Savings of up to 80% on printing and paperwork costs
✗Expensive printing, scanning, mail and physical storage
Key Takeaways
Create secure digital forms without coding
Legal e-signature built into every form
Full customization: design, fields, logic and automations
Integration with CRM systems, email and cloud storage
Compliant with strict security and privacy standards
In Summary: The Smart Way to Manage Business Documents
When creating secure digital forms for business, three critical things make the difference: top-tier data security (ISO 27001, AATL, two-factor authentication), a legally binding digital signature that removes the need for in-person meetings and branded design that conveys credibility and professionalism to every customer. These three together turn an online form from a technical tool into a real business asset.
As of 2026, businesses using electronic forms and digital contracts report up to 70% shorter document-handling times and up to 40% higher closing rates. Every day without a digital system is a day you pay in time, money and customers who are looking for a more convenient experience.
Last updated: January 2026. GoMixApp continues to keep up with evolving standards and legal requirements — so your solution is always current and regulation-compliant.
Ready to make the change? Contact our team and together we will build the perfect digital solution for your business — no commitment, no technical knowledge needed.
var gmxCf7LegacyUxI18n = {"errName":"Please enter a full name","errPhone":"Please enter a valid phone number","errEmail":"Please enter a valid email address","errRequired":"Required field"};
//# sourceURL=gmx-cf7-legacy-ux-js-extra
var gmxCf7UxI18n = {"progressTemplate":"{N} field(s) remaining","allSet":"All set to send!","sending":"Sending\u2026","successTitle":"Thank you! Your inquiry has been received","successBody":"A representative will get back to you within 24 hours with a tailored quote.","successCtaLabel":"See our areas of expertise","successCtaHref":"/expertise/","errorTitle":"Submission failed","errorBody":"Please try again, or call us directly"};
//# sourceURL=gmx-cf7-ux-js-extra
var atrCookieNoticeSettings = {"cookieName":"atr_cookie_notice_consent","decisionCookieName":"atr_cookie_notice_consent_given","expiryDays":"365","autoHideDelay":"0","enableDebug":"","siteName":"GoMixApp","isPrivacyPage":"","privacyPolicyUrl":"https://gomixapp.com/privacy-policy/","privacyNoteText":"\ud83d\udca1 You can read this page while deciding about cookies","mode":"simple"};
//# sourceURL=atr-cookie-notice-simple-js-extra
(function(){
function cleanUrl(url) {
// Strip query params embedded mid-path: /ID?params/file -> /ID/file
return url.replace(/\?[^\/]+\//g, '/');
}
function addWebPFallback(pic) {
if (pic.getAttribute('data-webp-fb')) return;
pic.setAttribute('data-webp-fb', '1');
var img = pic.querySelector('img');
if (!img) return;
img.onerror = function() {
this.onerror = null;
this.src = cleanUrl(this.src).replace('vi_webp','vi').replace('.webp','.jpg');
var sources = this.parentElement.querySelectorAll('source');
for (var i = 0; i < sources.length; i++) {
sources[i].srcset = cleanUrl(sources[i].srcset).replace('vi_webp','vi').replace('.webp','.jpg');
}
};
}
var observer = new MutationObserver(function() {
var pics = document.querySelectorAll('.video-seo-youtube-picture');
for (var i = 0; i < pics.length; i++) addWebPFallback(pics[i]);
});
observer.observe(document.documentElement, { childList: true, subtree: true });
})();
(function(){
var siteKey = "6Ldnu_gsAAAAAGpkh7vCd_h3L9BA193yFU59I4Do";
var action = "submit_lead_form";
var loaderUrl = "https:\/\/www.google.com\/recaptcha\/enterprise.js?render=6Ldnu_gsAAAAAGpkh7vCd_h3L9BA193yFU59I4Do";
// GWP-506 (perf): the reCAPTCHA Enterprise runtime costs ~900ms of main-thread
// work (PSI contactus TBT 660ms, perf 69). It was loaded eagerly on every page
// carrying a CF7 form. It now loads on the FIRST real page interaction
// (scroll/pointer/key/touch) — warming the runtime well before the user can
// reach submit — and never loads on a no-interaction (lab) page view, so the
// perf win holds. The token is still stamped on form focusin and refreshed at
// submit. IMPORTANT: the server gate is fail-CLOSED by default (GWP-412
// require_token) — a missing token at submit is treated as spam — so the
// runtime MUST be warm before submit; that is exactly why the warm trigger is
// first-page-interaction, NOT focusin-only (focusin-only left a race where a
// fast focus→submit could POST before the ~900ms download finished and drop a
// legit lead). The eager <script src> is gone.
var greReady = false, greWaiters = [], greLoadStarted = false;
function pollGre(attempts) {
if (typeof grecaptcha !== 'undefined' && grecaptcha.enterprise) {
greReady = true;
var queued = greWaiters;
greWaiters = [];
queued.forEach(function (fn) { try { fn(); } catch (e) {} });
return;
}
if (attempts > 200) {
// no-silent-failures: enterprise.js never became ready (network-blocked,
// consent/privacy blocker, or a Google outage). Surface it — a missing
// token fails CLOSED server-side (GWP-412) and drops the lead.
if (window.console && console.warn) {
console.warn('[GMX recaptcha] enterprise.js not ready after ~10s; token will be missing (submit fails closed).');
}
return; // give up after ~10s (200 * 50ms)
}
setTimeout(function () { pollGre(attempts + 1); }, 50);
}
function loadGre() {
if (greLoadStarted) return;
greLoadStarted = true;
var s = document.createElement('script');
s.src = loaderUrl;
s.async = true;
document.head.appendChild(s);
pollGre(0); // begin polling only once the runtime is actually loading
}
function whenGreReady(cb) {
if (greReady) return cb();
greWaiters.push(cb);
}
function stampToken(form) {
if (!form.querySelector('.wpcf7-form-control-wrap input[type="submit"], .wpcf7-submit')) return;
loadGre(); // lazy: kick off enterprise.js on demand (idempotent)
whenGreReady(function () {
grecaptcha.enterprise.ready(function () {
grecaptcha.enterprise.execute(siteKey, { action: action }).then(function (token) {
var hidden = form.querySelector('input[name="gmx_recaptcha_token"]');
if (!hidden) {
hidden = document.createElement('input');
hidden.type = 'hidden';
hidden.name = 'gmx_recaptcha_token';
form.appendChild(hidden);
}
hidden.value = token;
}).catch(function () {
// no-silent-failures: token generation failed; the server gate is
// fail-CLOSED (GWP-412), so this submit will be rejected as spam.
if (window.console && console.warn) {
console.warn('[GMX recaptcha] token execute failed; submit will fail closed.');
}
});
});
});
}
document.addEventListener('wpcf7submit', function (e) { stampToken(e.target); });
// Also stamp on first focus into any CF7 form (so token ready before submit).
// `whenGreReady()` queues the stamp until grecaptcha loads, so the once-
// listener stays safe even if grecaptcha isn't ready at focus-in time.
document.querySelectorAll('form.wpcf7-form').forEach(function (form) {
form.addEventListener('focusin', function once() {
form.removeEventListener('focusin', once);
stampToken(form);
});
});
// GWP-506: warm enterprise.js on the FIRST real page interaction so the ~900ms
// runtime is ready before the user reaches submit (closes the focusin-only race
// against the fail-CLOSED server gate, and covers AJAX/popup-injected forms that
// missed the focusin binding above). Never fires on a no-interaction (lab) view,
// so the perf win holds. Idempotent via loadGre()'s greLoadStarted guard.
var warmOpts = { passive: true, capture: true };
var warmEvents = ['pointerdown', 'keydown', 'touchstart', 'scroll'];
function warmGre() {
loadGre();
warmEvents.forEach(function (e) { window.removeEventListener(e, warmGre, warmOpts); });
}
warmEvents.forEach(function (e) { window.addEventListener(e, warmGre, warmOpts); });// GWP-507 (CONFIRMED LIVE: 19 real leads dropped in 8 days): capture-phase
// submit GATE. The warm/focusin logic above only *helps* the token be ready;
// it is NOT a guarantee. The race: a user whose FIRST interaction is clicking
// submit on an autofilled form (no prior scroll/field-touch to warm the
// ~900ms enterprise.js), or who submits before the runtime readies, serializes
// the AJAX POST with an EMPTY gmx_recaptcha_token → the fail-CLOSED server gate
// (GWP-412 require_token) drops the lead as spam. CF7's `wpcf7submit` fires
// AFTER the AJAX POST (too late), and CF7 exposes no documented pre-POST JS
// hook (verified: contactform7.com/dom-events). So the ONLY seam is to
// intercept the native DOM submit/click in CAPTURE phase, HOLD it until
// greReady + token stamped, then re-dispatch. grecaptcha token lifetime is
// 2 minutes, so holding briefly is safe.
//
// TIMEOUT-FALLBACK CHOICE (a): if enterprise.js never readies within the
// ~10s ceiling (network-blocked / consent-blocker / Google outage), we
// RE-ENABLE the button and let the submit proceed WITHOUT a token rather than
// hard-blocking the user. It will fail-CLOSED server-side (GWP-412), but the
// console.warn fires loudly (no-silent-failures) — we never trap a real user
// behind a spinner they can't escape.
var GATE_TIMEOUT_MS = 10000; // matches pollGre ceiling (200 * 50ms).
function gmxFormHasToken(form) {
var hidden = form.querySelector('input[name="gmx_recaptcha_token"]');
return !!(hidden && hidden.value);
}
function gmxSetVerifying(form, on) {
var btn = form.querySelector('.wpcf7-submit, input[type="submit"], button[type="submit"]');
if (!btn) return;
if (on) {
btn.disabled = true;
btn.setAttribute('data-gmx-verifying', '1');
} else {
btn.disabled = false;
btn.removeAttribute('data-gmx-verifying');
}
}
function gmxReleaseSubmit(form) {
// Mark released so the re-dispatched submit passes straight through the
// capture gate (no re-gate loop), re-enable UX, then re-trigger.
form.__gmxGateReleased = true;
gmxSetVerifying(form, false);
if (typeof form.requestSubmit === 'function') {
form.requestSubmit();
} else {
form.dispatchEvent(new Event('submit', { bubbles: true, cancelable: true }));
}
// GWP-507 finding-1 (BLOCKER fix): reset the release flag on the NEXT tick
// so any FUTURE user submit (user edits a field + resubmits) is re-gated and
// stamps a FRESH token. reCAPTCHA tokens are single-use with a ~2-min
// lifetime — without this reset, __gmxGateReleased stayed true forever after
// the first release, letting a second submit bypass the gate and POST a
// stale/used token. The setTimeout(0) lets the synchronous re-dispatch above
// complete (which short-circuits on the still-true flag) before we re-arm.
setTimeout(function () { form.__gmxGateReleased = false; }, 0);
}
function gmxSubmitGate(e) {
var form = e.currentTarget;
if (form.tagName !== 'FORM') { form = form.form || form.closest('form.wpcf7-form'); }
if (!form) return;
// Idempotent: a programmatic re-submit we already released proceeds. This is
// the ONLY pass-through — it lets the freshly-stamped re-dispatch reach CF7.
// (The flag is reset on the next tick in gmxReleaseSubmit, so the NEXT user
// submit is re-gated.)
if (form.__gmxGateReleased) return;
// GWP-507 finding-2 (stale/used token fix): every USER submit HOLDS + stamps
// a FRESH token — we do NOT early-return on an already-present token. A token
// already sitting in the hidden input may be stale or already used (single-
// use, ~2-min lifetime); proceeding on it would POST a dead token. enterprise.js
// is warm by submit time, so grecaptcha.enterprise.execute() resolves in
// ~100-300ms — the per-submit hold is brief. stampToken() OVERWRITES the
// hidden input value (hidden.value = token), so no stale token lingers.
// HOLD: block CF7's submit handler before the AJAX POST.
e.preventDefault();
e.stopImmediatePropagation();
if (form.__gmxGateWaiting) return; // a click + submit may both fire; hold once.
form.__gmxGateWaiting = true;
loadGre(); // kick the warm if not started.
gmxSetVerifying(form, true);
var released = false;
function release(missing) {
if (released) return;
released = true;
form.__gmxGateWaiting = false;
if (missing && window.console && console.warn) {
console.warn('[GMX recaptcha] submit gate timed out (~10s); releasing without token (submit fails closed).');
}
gmxReleaseSubmit(form);
}
var timer = setTimeout(function () { release(true); }, GATE_TIMEOUT_MS);
whenGreReady(function () {
stampToken(form);
// stampToken resolves the token asynchronously (enterprise.execute
// promise); poll briefly for the stamp, then release. Bounded by the
// same overall timer above.
(function awaitStamp(n) {
if (released) return;
if (gmxFormHasToken(form)) { clearTimeout(timer); release(false); return; }
if (n > 200) { clearTimeout(timer); release(true); return; } // ~10s (200*50ms)
setTimeout(function () { awaitStamp(n + 1); }, 50);
})(0);
});
}
// GWP-507 finding-4 (CF7 phase): WHY capture phase works. Our gate listener is
// registered in CAPTURE phase (3rd arg `true`), so it runs BEFORE CF7's own
// bubble-phase 'submit' handler on the same form. When we call
// e.stopImmediatePropagation() in the capture listener, the DOM spec stops ALL
// further listeners for that event on the target — including the later
// bubble-phase CF7 handler — so CF7's AJAX POST never fires until we re-dispatch
// with a fresh token. This capture-phase interception is the only documented
// pre-POST seam: CF7 exposes no pre-POST JS hook (wpcf7submit fires AFTER the
// AJAX POST). See contactform7.com/dom-events.
document.querySelectorAll('form.wpcf7-form').forEach(function (form) {
form.addEventListener('submit', gmxSubmitGate, true);
var btn = form.querySelector('.wpcf7-submit, input[type="submit"], button[type="submit"]');
if (btn) { btn.addEventListener('click', gmxSubmitGate, true); }
});
})();
(function(){
var loaded = false;
function loadUserWay() {
if (loaded) return;
loaded = true;
var el = document.createElement('script');
el.setAttribute('data-account', "UX40fo0Ctw");
el.setAttribute('data-language', "en");
el.setAttribute('src', 'https://cdn.userway.org/widget.js');
document.body.appendChild(el);
events.forEach(function(e){ window.removeEventListener(e, loadUserWay, {passive: true}); });
}
var events = ['scroll', 'mousemove', 'touchstart', 'click', 'keydown'];
events.forEach(function(e){ window.addEventListener(e, loadUserWay, {passive: true}); });
})();