• Projects 3
  • Rating 5.0
  • Rating 1 130

Budget: 1000 UAH Deadline: 2 days

Good day! I will take the token from the public code — I will create a small server proxy endpoint: the form will send data not directly to Telegram, but to it, and from there the sending will occur. The token remains only on the server, it is not visible in the output HTML/JS. The "Get Consultation" form and the rest on the Ukrainian/Russian versions work as before — nothing changes for the user.

First, I will review your specifications and the list of pages to make sure nothing is missed. One clarification: is there access to the server part (website hosting) to place a small proxy script, or does Goodshop only allow frontend inserts? This will determine where we place the endpoint — on your hosting or on a separate one.

We create bots and small turnkey integrations, there are live demos — I can send them in the chat if you want to see the quality. I am taking it at a starting price because I am gathering my first reviews here, so it is beneficial and quick (1-2 days).

Petro Pankov, BotCraft Group

  • Projects 16
  • Rating 5.0
  • Rating 3 183

Budget: 1000 UAH Deadline: 1 day

Good day. I am transferring the Telegram bot token to the env file and setting up the operation through Cloudflare so that you have access to change the token without involving third parties. I am ready to discuss the details and start working. I would be happy to collaborate.

  • Projects 5
  • Rating 4.9
  • Rating 756

Budget: 1000 UAH Deadline: 7 days

Hello, I have worked on Telegram bots and proxy endpoints, where the token is hidden on the backend, and the front end only communicates with its API. I have done this for forms on websites, where the code is publicly available, including through inserts in admin panels of builders.

I recommend implementing simple validation and rate-limiting on the proxy, as an open endpoint will quickly be spammed by bots and flood your chat with requests, wasting hours on clearing out the junk.

Is the form currently sending data directly to the Telegram API from the front end, or is there an intermediate handler? And where is it more convenient to host the proxy: separate hosting, serverless function, or your server?

I suggest we have a brief call; before the call, I will draft a solution scheme with the proxy so you can see how it works. When is convenient for you?

  • Projects -
  • Rating -
  • Rating 321

Budget: 1000 UAH Deadline: 1 day

Hello. I can move the submission of applications from the browser to a Cloudflare Worker, remove the Telegram token and chat_id from the public code, and check all specified forms in the Ukrainian and Russian versions. I will set up the Worker, the secrets BOT_TOKEN and CHAT_ID, check the Origin, validate the phone, and implement a honeypot field. After replacing the token, I will check the submission of applications and ensure that the old token is not present in the source code of the pages. I will also verify whether the forms on internal pages use separate handlers so that the token does not remain in another fragment of HTML/JS.

  • Projects 42
  • Rating 5.0
  • Rating 2 578

Budget: 1000 UAH Deadline: 1 day

Hello, I can fix your problem.
I will move the token to the backend so it won't be visible publicly.

  • Projects 32
  • Rating 5.0
  • Rating 8 001

Budget: 1000 UAH Deadline: 2 days

The bot token is currently exposed in the open JS code of the pages, and it needs to be moved to a location where the client cannot see it.

Plan: On the server (or via a serverless function / separate PHP file in Khoroshop), I will set up a simple proxy endpoint that accepts form data and stores the token in an environment variable or configuration file outside the webroot. I will switch the forms on all pages (Ukrainian + Russian) to fetch to this endpoint instead of directly calling the Telegram API. The old token will be revoked through BotFather after the switch.

Is there an option on the hosting profkit.com.ua to add a PHP file or environment variables, or is access only through "Additional HTML/JS code" in the Khoroshop admin panel?

  • Projects -
  • Rating -
  • Rating 318

Budget: 5000 UAH Deadline: 3 days

Hello, Dmitry!
I carefully studied the technical specifications. The problem is critical and completely clear: the form submission goes directly from the JS code in the browser, which makes the Telegram bot token accessible to everyone in the page's source code.
I am ready to safely solve this issue in the shortest possible time without disrupting the operation of existing forms on the site profkit.com.ua.
🛠️ Here’s how I will do it:
Extracting the token from the frontend: I will remove the calls to the Telegram API and the token itself from the "Additional HTML/JS code" section in Goodshop.
Creating a secure proxy: I will connect a lightweight backend endpoint (for example, a Serverless script / Cloudflare Workers / your server) that will safely receive form data from Goodshop and forward it to Telegram.
Spam protection: I will set up basic validation and headers (CORS) so that third-party sites cannot send requests through your proxy.
Testing: I will check submissions from all forms on the site (both in the Ukrainian and Russian versions).
I do not have a dozen parallel projects, so I am ready to start immediately after approval and complete everything in a couple of hours.
I would be happy to help close this vulnerability! Please write in the chat when it is convenient for you to start.

  • Projects 67
  • Rating 5.0
  • Rating 12 691

Budget: 1000 UAH Deadline: 1 day

Hello! I will complete your task quickly and efficiently.

My latest works
https://indexfast.pro - fast website indexing
https://mono-bank.pp.ua - everything about Monobank
https://mamamia.pp.ua - online store
https://programist.pp.ua/ua/portfolio/ - portfolio of works
https://monitortest.pp.ua - monitor testing
https://keytest.pp.ua - keyboard testing
https://pctest.pp.ua - computer testing

  • Projects 151
  • Rating 5.0
  • Rating 4 741

Budget: 1000 UAH Deadline: 1 day

Good day! I can do it right now. I will be happy to collaborate — feel free to reach out!

  • Projects 41
  • Rating 5.0
  • Rating 3 086

Budget: 1000 UAH Deadline: 1 day

Good day, an open token is very not okay, essentially allowing third parties access to the bot. I will make it so that the token is not publicly accessible.

  • Projects -
  • Rating -
  • Rating 1 441

Budget: 1000 UAH Deadline: 1 day

Good day! I have reviewed the entire technical specification. It is necessary to remove the BOT_TOKEN and chat_id from the public JS, move the sending to Cloudflare Worker, store the secrets on the server, restrict the Origin, add phone validation and a honeypot, and then replace the form handlers in Khoroshop for the Ukrainian and Russian versions.

I will execute without delay: first, I will deploy and test the Worker with a test POST request, then switch the forms, after rotating the token I will update the secret and recheck the sending, ensuring a 403 for external Origin and the absence of token/api.telegram.org in the source code of all specified pages.

Please clarify: are the accesses to Cloudflare and the Khoroshop section "Additional HTML/JS code" already prepared, or does the Worker need to be created in a new account?

As the first step, I will check the current code of all listed forms and deploy a proxy with the old token for a control test.

  • Projects -
  • Rating -
  • Rating 282

Budget: 1000 UAH Deadline: 1 day

Hello.
I specifically researched the problem you are currently facing.
After checking, it was confirmed that your tokens are being exposed, which can lead to serious issues.
I am deeply impressed by your keen observations in identifying this critical problem in advance, and I am confident that I can resolve this issue quickly.
I look forward to our further collaboration.
Thank you.

Denis Vladimirov

Denis Vladimirov

Winning proposal
126 2
  • Projects 135
  • Rating 5.0
  • Rating 11 677

Budget: 1000 UAH Deadline: 1 day

Good day, write. I will do it in an hour, quickly and efficiently.

I will redo the submission to the backend.

  • Projects -
  • Rating -
  • Rating 472

Budget: 950 UAH Deadline: 1 day

I will handle the removal of sensitive data from the public code of your website and will move form processing to a secure server side. Message me, and we can discuss the details, and I will start immediately.

  • Projects -
  • Rating -
  • Rating 133

Budget: 950 UAH Deadline: 1 day

I have worked a lot with websites, let's quickly remove it so the token doesn't show. I can do it now.

  • Projects 167
  • Rating 5.0
  • Rating 6 730

Budget: 999 UAH Deadline: 1 day

Good afternoon, I am ready to complete the task after discussing the detailed specifications.
Please message me privately.

  • Projects 18
  • Rating -
  • Rating 805

Budget: 1000 UAH Deadline: 14 days

Hello. It is necessary to remove the bot token from the public code on profkit.com.ua, this is clear. The key issue is that the token is inserted into custom HTML/JS through the Goodshop admin panel and is visible in the page code. I can check all the mentioned forms, find the source, and remove the token from the public part; can access to the Goodshop admin panel and site files be provided for review?

  • Projects 55
  • Rating 4.7
  • Rating 3 610

Budget: 1000 UAH Deadline: 1 day

Good afternoon
I will do it within 1 hour
I will move the API code and other keys to a separate unreadable file, functionality will be preserved!

  • Projects 6
  • Rating 3.9
  • Rating 788

Budget: 1000 UAH Deadline: 2 days

Dmytro, the task is clear: we need to extract the bot's configuration data from the public JS code so that the token is not exposed in the website's source code. I will set up a server-side proxy script or middleware that will receive data from forms and send it to Telegram, hiding the token from prying eyes in the code of Khoroshop. Do you have access to the hosting where we can move the request processing logic, or is it better to implement this through a third-party automation service?

  • Projects 20
  • Rating 5.0
  • Rating 2 430

Budget: 1000 UAH Deadline: 1 day

Good day, I am ready to complete your task quickly and efficiently. I have extensive experience in creating various bots. Please write to me in private messages to discuss the details. I would be happy to help :)

The list does not show proposals concealed by the client or freelancer with a Plus profile, as well as proposals violating rules