Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - aryehraber/statamic-captcha: Statamic Addon that protects your Statamic forms using a Captcha service. · GitHub
Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - aryehraber/statamic-captcha: Statamic Addon that protects your Statamic forms using a Captcha service. · GitHub
Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - aryehraber/statamic-captcha: Statamic Addon that protects your Statamic forms using a Captcha service. · GitHub
Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - aryehraber/statamic-captcha: Statamic Addon that protects your Statamic forms using a Captcha service. · GitHub
Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - aryehraber/statamic-captcha: Statamic Addon that protects your Statamic forms using a Captcha service. · GitHub
Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - aryehraber/statamic-captcha: Statamic Addon that protects your Statamic forms using a Captcha service. · GitHub
Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - aryehraber/statamic-captcha: Statamic Addon that protects your Statamic forms using a Captcha service. · GitHub
Skip to content

Latest commit

History

118 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Captcha

Protect your Statamic forms using a Captcha service.

This addon allows you to protect your Statamic forms using any of the following services:

After the initial setup, all you need to do is add the {{ captcha }} tag inside your forms, easy peasy!

Installation

Install the addon via composer:

composer require aryehraber/statamic-captcha

Publish the config file:

 php please vendor:publish --tag=captcha-config

Alternately, you can manually setup the config file by creating captcha.php inside your project's config directory:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => env('CAPTCHA_SITEKEY', ''),
'secret' => env('CAPTCHA_SECRET', ''),
'server_url' => env('CAPTCHA_SERVER_URL', ''), // required for Fcaptcha'verify_ip' => env('CAPTCHA_VERIFY_IP', false), // Fcaptcha only, see below'forms' => [],
'user_login' => false,
'user_registration' => false,
'disclaimer' => '',
'invisible' => false,
'hide_badge' => false,
'enable_api_routes' => false,
'custom_should_verify' => null,
];

Once the config file is in place, make sure to add your sitekey & secret from Recaptcha's Console, hCaptcha's Console, Cloudflare's Dashboard, Altcha's Docs or your FCaptcha server, and add the handles of the Statamic Forms you'd like to protect:

<?phpreturn [
'service' => env('CAPTCHA_SERVICE', 'Recaptcha'), // options: Recaptcha / Hcaptcha / Turnstile / Altcha / Fcaptcha'sitekey' => 'YOUR_SITEKEY_HERE', // Or add to .env'secret' => 'YOUR_SECRET_HERE', // Or add to .env'forms' => ['contact', 'newsletter'],
// ...
];

When using FCaptcha, also point the addon to your self-hosted FCaptcha server:

CAPTCHA_SERVICE=FcaptchaCAPTCHA_SITEKEY=your-site-keyCAPTCHA_SECRET=your-verify-secretCAPTCHA_SERVER_URL=https://captcha.example.com

FCaptcha binds each token to the IP address it saw when the widget was solved, and rejects a token whose remoteip disagrees. Because that only holds when your site reports the exact same address — which needs Laravel's trusted proxies configured, and can still differ for a dual-stack visitor who reaches one host over IPv6 and the other over IPv4 — the addon does not assert an IP by default. Set CAPTCHA_VERIFY_IP=true to turn the check on once you've confirmed both ends agree.

If you would like Captcha to verify ALL forms without having to specify each one in the forms config array, you may use the all option instead.

Note: this should replace the array and be set as a string.

<?phpreturn [
'forms' => 'all',
// ...
];

Usage

<head><title>My Awesome Site</title>
{{ captcha:head }}
</head><body>
{{ form:contact }}
<!-- Add your fields like normal -->
{{ captcha }}
{{ if error:captcha }}
<p>{{ error:captcha }}</p>
{{ /if }}
{{ /form:contact }}
</body>

This will automatically render the Captcha element on the page. After the form is submitted, the addon will temporarily halt the form from saving while the Captcha service verifies that the request checks out. If all is good, the form will save as normal, otherwise an error will be added to the {{ errors }} object.

Invisible Captcha

Simply set invisible to true inside Captcha's config (Turnstile handles invisibility from Cloudflares's Dashboard, so no Captcha config changes are needed). To hide the sticky Recaptcha badge, make sure to also set hide_badge to true.

Note: using Invisible Captcha will require you to display links to the Captcha service's Terms underneath the form, to make this easier use {{ captcha:disclaimer }}. This message can be customised using the disclaimer option inside Captcha's config, however sensible defaults have been added that will automatically switch depending on the Captcha service you're using.

User Registration & Login

Captcha can also verify User Registration & User Login form requests, simply set user_registration / user_login to true inside Captcha's config and use the {{ captcha }} tag as normal inside Statamic's {{ user:register_form }} / {{ user:login_form }} tags.

Data Attributes

Some of the Captcha services offer additional features, such as light/dark mode and sizing options, via data attributes. These can simply be added to the Captcha tag and will be passed through to the client-side widget.

{{ captcha data-theme="dark" data-size="compact" }}

Conditional Captcha

You can now conditionally render Captcha only when it is enabled for the given form. This is especially useful when using dynamic or shared form templates.

Use the captcha:is_enabled tag as a boolean:

{{ if {captcha:is_enabled form="contact"} }}
{{ captcha }}
{{ /if }}

This checks your Captcha configuration and only outputs the Captcha fields when appropriate, it will always return true if your forms config is set to all.

Translations

This package is localized to English and German. If you need translations in another language, you can create them yourself:

  • Create the translations file in resources/lang/vendor/statamic-captcha/{language}/messages.php.
  • You can use the English translation file as a blueprint.
  • You are welcome to share your translations here by submitting a PR.

If you want to change existing messages, you can publish and override them:

php please vendor:publish --tag="captcha-translations"

Advanced

Custom "Should Verify" Logic

You can provide additional custom logic to determine if verification should be attempted using a custom invokable class. This is useful to adjust Captcha's shouldVerify check to include app-specific behaviour, for example: only enforcing Captcha for guest users and bypassing it for logged-in users.

To get started, create an invokable class within your app, and add it as the custom_should_verify property in your config:

<?phpreturn [
// ...'custom_should_verify' => \App\Support\MyCustomShouldVerify::class,
];

This invokable class must implement the \AryehRaber\Captcha\Contracts\CustomShouldVerify interface, which enforces that an event param gets passed into the invoke method and subsequently returns an optional boolean. To stop Captcha's shouldVerify method from getting called, the invoke method must return false, otherwise returning true (or null) will continue Captcha's verification logic.

Note: this custom class is resolved via Laravel's container, meaning dependency injection is available via the constructor.

<?phpnamespaceApp\Support;
useAryehRaber\Captcha\Contracts\CustomShouldVerify;
class MyCustomShouldVerify implements CustomShouldVerify
{
publicfunction__invoke($event): ?bool
{
// bypass verification for authenticated usersif (auth()->check()) {
returnfalse;
}
// bypass verification on dev environmentif (app()->environment('dev')) {
returnfalse;
}
// bypass verification based on event form submissionif ($eventinstanceof \Statamic\Events\FormSubmitted) {
// return $event->submission;
}
// bypass verification based on login eventif ($eventinstanceof \Illuminate\Auth\Events\Login) {
// return $event->user;
}
// bypass verification based on user registration eventif ($eventinstanceof \Statamic\Events\UserRegistering) {
// return $event->user;
}
// bypass verification based on entry saving eventif ($eventinstanceof \Statamic\Events\EntrySaving) {
// return $event->entry;
}
}
}

About

Statamic Addon that protects your Statamic forms using a Captcha service.

Resources

Stars

17 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages