Index: mollom.module
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/mollom/mollom.module,v
retrieving revision 1.2.2.173
diff -u -p -r1.2.2.173 mollom.module
--- mollom.module	6 Oct 2010 23:55:31 -0000	1.2.2.173
+++ mollom.module	14 Oct 2010 00:02:44 -0000
@@ -1111,6 +1111,13 @@ function mollom_form_get_values($form_va
   // User IP.
   $data['author_ip'] = ip_address();
 
+  // Spambot trap.
+  // Capture and send the actually submitted value, so Mollom can evaluate it
+  // (usually a URL).
+  if (isset($form_values['mollom']['homepage']) && $form_values['mollom']['homepage'] !== '') {
+    $data['honeypot'] = $form_values['mollom']['homepage'];
+  }
+
   return $data;
 }
 
@@ -1379,6 +1386,17 @@ function mollom_process_mollom($element,
     '#description' => t("Type the characters you see in the picture above; if you can't read them, submit the form and a new image will be generated. Not case sensitive."),
   );
 
+  // Add a spambot trap. Purposively use 'homepage' as field name.
+  // @todo Ideally, we'd additionally add some kind of randomization to make it
+  //   harder to identify this trap.
+  $element['homepage'] = array(
+    '#type' => 'textfield',
+    '#attributes' => array(
+      'title' => t('Leave blank, used to catch spammers'),
+      'style' => 'display: none;',
+    ),
+  );
+
   // Make Mollom form and session information available to #pre_render callback.
   // This must be assigned by reference. It is the essential "communication
   // layer" between form API and the rendering system. Any modifications to
@@ -1456,6 +1474,12 @@ function mollom_validate_analysis(&$form
   if (isset($data['post_id'])) {
     unset($data['post_id']);
   }
+  if (isset($all_data['honeypot'])) {
+    _mollom_watchdog(array(
+      'Honeypot!' => array(),
+      'Data:<pre>@data</pre>' => array('@data' => $all_data),
+    ), WATCHDOG_ALERT);
+  }
   $data['session_id'] = $form_state['mollom']['response']['session_id'];
   $data['checks'] = implode(',', $form_state['mollom']['checks']);
   $result = mollom('mollom.checkContent', $data);
@@ -1567,8 +1591,17 @@ function mollom_validate_captcha(&$form,
     'session_id' => $form_state['mollom']['response']['session_id'],
     'captcha_result' => $form_state['values']['mollom']['captcha'],
     'author_ip' => $all_data['author_ip'],
-    'author_id' => isset($all_data['author_id']) ? $all_data['author_id'] : NULL,
   );
+  if (isset($all_data['author_id'])) {
+    $data['author_id'] = $all_data['author_id'];
+  }
+  if (isset($all_data['honeypot'])) {
+    $data['honeypot'] = $all_data['honeypot'];
+    _mollom_watchdog(array(
+      'Honeypot!' => array(),
+      'Data:<pre>@data</pre>' => array('@data' => $all_data),
+    ), WATCHDOG_ALERT);
+  }
   $result = mollom('mollom.checkCaptcha', $data);
   // Use all available data properties for log messages below.
   $data += $all_data;
@@ -1677,6 +1710,11 @@ function mollom_pre_render_mollom($eleme
 
 /**
  * Form submit handler to flush Mollom session and form information from cache.
+ *
+ * @todo Various forms happen to blatantly take over $form_state['values'] and
+ *   save that into the database. We should clean up and remove our additional
+ *   values to prevent them from being stored. Perhaps, by prepending a separate
+ *   form submit handler.
  */
 function mollom_form_submit($form, &$form_state) {
   // Some modules are implementing multi-step forms without separate form
Index: tests/mollom.test
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/mollom/tests/mollom.test,v
retrieving revision 1.1.2.64
diff -u -p -r1.1.2.64 mollom.test
--- tests/mollom.test	6 Oct 2010 23:55:31 -0000	1.1.2.64
+++ tests/mollom.test	13 Oct 2010 22:09:50 -0000
@@ -2363,7 +2363,7 @@ class MollomDataTestCase extends MollomW
 
     // Verify that submitted data equals post data.
     $data = $this->getServerRecord('mollom.checkCaptcha');
-    $this->assertSame('author_id', $data['author_id'], NULL);
+    $this->assertFalse(isset($data['author_id']), t('author_id: Undefined.'));
 
     // Log in admin user and edit comment containing spam.
     $this->resetServerRecords();
