Hire for Craft CMS

The application form

The application form is what the applicant answers. It is not a Craft field layout, and that is deliberate: a field layout renders control-panel HTML for a trusted author, has no server-side story for an anonymous upload, and no concept of "the visitor must answer this". Forms are managed under Hire → Settings → Application forms and stored in project config.

Built-in fields

Six fields map onto real columns, because Hire has to be able to email the applicant, spot a duplicate and key a CSV:

  • First name, last name, email, phone
  • CV
  • Cover letter

Questions of your own (Pro)

Thirteen more types, validated on the server and stored with the application as JSON:

TypeNotes
Text, textarea, number, URL, date
Dropdown, radio buttons, checkboxesOptions you define
Single checkbox, consentConsent must be ticked to submit when required
FileChecked the same way as the CV
HeadingPresentational — breaks a long form into sections
HiddenA value you set, carried with the submission

Answers are read back in the control panel next to the question that produced them.

Which form a job uses

Each job whose apply method is Form picks a form. Lite has one form; Pro has as many as you need — a short one for internships, a longer one for senior roles.

Validation

All of it is on the server. The form's own field list is the allow-list: a value posted under a handle the form does not define is dropped, not stored. The form comes from the job, never from the request.

A rejected submission comes back with the visitor's answers still in the inputs and each error under its own field — not an empty form and an apology.

CV uploads

Every upload is checked twice:

  1. The extension against the site's list — pdf, doc, docx, odt, rtf, txt and pages by default.
  2. The detected file type against that extension. A script renamed payload.pdf passes the first test and fails the second.

HTML, SVG, XML, JavaScript and PHP are always refused, even if somebody adds them to the accepted types, because served from your domain they run as whoever opens them.

Files are stored in the volume chosen under Settings → Uploads & privacy, in a subfolder (applications/{year}/{month} by default; {day}, {jobCode} and {jobId} work too), with a random prefix on the filename so two candidates who both called their file cv.pdf cannot download each other's. The maximum size defaults to 5 MB.

CVs are streamed through the control panel, behind the View applications permission, rather than linked to directly.

After submitting

The form's success message is shown on the same page, or the browser goes to the form's redirect URI. Settings → Uploads & privacy has a site-wide fallback redirect.