Posted in php
335
12:45 am, June 25, 2021

verify the google recapture server php

i was still getting quite a bit of spam even after using google recapture v2 and i think this is just as i was using the javascript only version, which disables the submit button if the capture is not solved.

the issue with this is all you need to do is disable javascript and you can still submit the form, so it needs some server side verification to check that the capture is actually solved.

I added this code to the post back on the form to send a check back to google which verifies the capture is solved

I also found that this cases the form to take a while to submit, so it needs some intervention from jquery. As when the form is submitted it has to wait to get the response from google. When its submitted you have to hide the submit button on the form and replace it with a disabled button that has please wait on it. 

here is a demo of its functionality

 

verify google recapture

verify the google recapture server php Demo

View Demo Full Screen View Demo New Tab

verify the google recapture server php Code

HTML

<form id="subform" method="post">
	<button type="submit" class="btn btn-success" id="commentButton" disabled="disabled">Register</button>
  	<button class="btn btn-primary hide" disabled="disabled" id="pleaseWait">Please Wait...</button>
</form>

Javascript

$(document).ready(function(){ 
	/* hide submit buttons on form clicks */
		$('#subform').on('submit', function(evt) {
				$('#commentButton').hide();
				$('#pleaseWait').show();
		});
  });

PHP

if($_SERVER['REQUEST_METHOD']=="POST") {

// check google recp auth
  $bad_google_cap = "<p class='alert alert-warning'>Recapture Failed</p>";
  if(isset($_POST['g-recaptcha-response'])) {
    $cap_response = $_POST['g-recaptcha-response'];
  } else {
    $page_content .= $bad_google_cap;
    return;
  }
  $google_response = file_get_contents("https://www.google.com/recaptcha/api/siteverify?secret=____your_secret_key_____&response=".$cap_response."&remoteip=".$_SERVER['REMOTE_ADDR']);
  $google_response_decoded = json_decode($google_response);
  if(!$google_response_decoded->success === true) {
    $page_content .= $bad_google_cap;
    return;
  }
  // check google recp auth
}

Related Tags

No Items Found.

Add Comment
Type in a Nick Name here
 
Other Items in php
php return json header and content list_all_array an early stages of list all function that uses an array to pass in main variables replace singular variable assignment with an array loop and variable variables using the $_SERVER['HTTP_REFERER'] to check referring pages timeline class and function php html template class system views list function for checking what views have been made on the current week load array load all items from an array while in a sqlite load sql loop create a 200 character summary from a longer html string using strlen to check the length of a string and do something about it How to record your own page views with PHP, and make them into weekly monthly and yearly charts load from fields array php class function get the current week as a number with php creating embedded php code from a database field test php bundle write check if a file exists with php check if the file is a directory or check if the directory exists in php get the current working directory in php create directory with php create folder with php check if a product already exists by its md5 load random videos module using template PHP/SQLite - Load Random Item split a string into links using the comma extract youtube image from video url simple php ip blocker preg replace clean a string only allow a-zA-Z0-9 characters get last month as a number with php verify the google recapture server php rtrim strip white space or strings from the end of a string get the current month as a number show the difference between two dates in years, months, days, hours and seconds counting the occurrence of words in a multidimensional array write string contents to a file with php unable to access the $_FILES when submitting a form php check column exists in table sqlite show all methods or functions in a class (class function version) show all methods (functions) in a class adding an item to an array with php passing in arrays to your functions rather than using variables check server https or http value in php using $_SERVER Remove background image php with image magic get current url with php list a functions variables or arguments php list all the functions in a class php print an array nicely add a toast alert when logging in with half moon dont use md5 for password hashing using password_hash and password_verify php basic page router checking for spam comments function calculate a percentage (dec) difference based on two numbers