Index: mollom.module
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/mollom/mollom.module,v
retrieving revision 1.89
diff -u -p -r1.89 mollom.module
--- mollom.module	9 Oct 2010 23:13:01 -0000	1.89
+++ mollom.module	12 Oct 2010 20:37:37 -0000
@@ -1062,6 +1062,13 @@ function mollom_form_get_values($form_va
   // User IP.
   $data['author_ip'] = ip_address();
 
+  // Spambot trap.
+  // Capture and send the actually submitted value, so Mollom can evaluate it
+  // (usually a URL).
+  if (isset($form_values['mollom']['homepage']) && $form_values['mollom']['homepage'] !== '') {
+    $data['post_honeypot'] = $form_values['mollom']['homepage'];
+  }
+
   return $data;
 }
 
@@ -1320,6 +1327,23 @@ function mollom_process_mollom($element,
     $element['captcha']['#access'] = FALSE;
   }
 
+  // Add a spambot trap. Purposively use 'homepage' as field name.
+  // @todo Ideally, we'd additionally add some kind of randomization to make it
+  //   harder to identify this trap.
+  $element['homepage'] = array(
+    '#type' => 'textfield',
+    // @todo Ping accessibility team to confirm that this is correct.
+    '#title' => t('Leave this field blank'),
+    // @todo #title_display 'attribute' does not work for #type textfield... grumble.
+    '#title_display' => 'attribute',
+    '#attributes' => array(
+      'title' => t('Leave this field blank'),
+      // @todo .element-invisible class is only applied on the INPUT, but we
+      //   need it on the wrapping DIV.form-item container to not break themes.
+      'class' => array('element-invisible'),
+    ),
+  );
+
   // Make Mollom form and session information available to entirely different
   // functions.
   $GLOBALS['mollom'] = &$form_state['mollom'];
@@ -1495,8 +1519,13 @@ function mollom_validate_captcha(&$form,
     'session_id' => $form_state['mollom']['response']['session_id'],
     'captcha_result' => $form_state['values']['mollom']['captcha'],
     'author_ip' => $all_data['author_ip'],
-    'author_id' => isset($all_data['author_id']) ? $all_data['author_id'] : NULL,
   );
+  if (isset($all_data['author_id'])) {
+    $data['author_id'] = $all_data['author_id'];
+  }
+  if (isset($all_data['post_honeypot'])) {
+    $data['post_honeypot'] = $all_data['post_honeypot'];
+  }
   $result = mollom('mollom.checkCaptcha', $data);
   // Use all available data properties for log messages below.
   $data += $all_data;
@@ -1551,6 +1580,11 @@ function mollom_validate_post(&$form, &$
 
 /**
  * Form submit handler to flush Mollom session and form information from cache.
+ *
+ * @todo Various forms happen to blatantly take over $form_state['values'] and
+ *   save that into the database. We should clean up and remove our additional
+ *   values to prevent them from being stored. Perhaps, by prepending a separate
+ *   form submit handler.
  */
 function mollom_form_submit($form, &$form_state) {
   // Some modules are implementing multi-step forms without separate form
Index: tests/mollom.test
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/mollom/tests/mollom.test,v
retrieving revision 1.68
diff -u -p -r1.68 mollom.test
--- tests/mollom.test	9 Oct 2010 23:13:01 -0000	1.68
+++ tests/mollom.test	12 Oct 2010 20:40:05 -0000
@@ -2539,7 +2539,7 @@ class MollomDataTestCase extends MollomW
 
     // Verify that submitted data equals post data.
     $data = $this->getServerRecord('mollom.checkCaptcha');
-    $this->assertSame('author_id', $data['author_id'], NULL);
+    $this->assertFalse(isset($data['author_id']), t('author_id: Undefined.'));
 
     // Log in admin user and edit comment containing spam.
     $this->resetServerRecords();
