Search by

omnishield / recaptcha

GlitchArt

Omnishield reCAPTCHA: Google's captcha - v2 checkbox and invisible, v3 score with its threshold and action, and reCAPTCHA Enterprise assessments - its token checked by direct calls, no Google library.

1.x-dev 2026-10-09 15:30 UTC

This package is not auto-updated.

Last update: 2026-10-10 14:16:53 UTC


README

Google reCAPTCHA for glitchr/omnishield, in its four forms - v2 checkbox, v2 invisible, v3 score, Enterprise - checked by direct calls to Google: siteverify for v2 and v3, the assessments API for Enterprise. No Google library (google/recaptcha wants PHP 8.4 and takes no HTTP client of yours).

use Omnishield\Model\Attempt;
use Omnishield\Recaptcha\RecaptchaGatewayFactory;

$gateway = (new RecaptchaGatewayFactory($httpClient))->create(['mode' => 'score', 'site_key' => $siteKey, 'secret' => $secret, 'threshold' => 0.5]);

$widget = $gateway->widget('contact');
echo $widget->html();         // api.js?render=<key>, a hidden g-recaptcha-response, a short script that asks for a token on submit

$verdict = $gateway->verify(Attempt::fromPost($_POST, $widget, $ip));
$verdict->score;              // 0.9; under the threshold: reasons ['score']
omnishield:
    gateways:
        google:
            factory: recaptcha
            options: { mode: checkbox, site_key: '%env(RECAPTCHA_SITE_KEY)%', secret: '%env(RECAPTCHA_SECRET)%' }

reCAPTCHA reaches Google and sets a cookie (_GRECAPTCHA): load it after the visitor's consent, and guard the form otherwise when they refuse (ALTCHA) - see omnishield's privacy. glitchr/ux-google keeps its own reCAPTCHA: this package neither touches nor needs it.

Documentation: the four modes, the options, the answers, the test keys, what was verified - v2 against Google with its test keys; v3 and Enterprise on answers written from Google's documentation, no key.

License: MIT since 2026-10-09; earlier versions remain published under LGPL-3.0-or-later.

Formerly omniguard/recaptcha, renamed on 2026-10-10 with its family (glitchr/omnishield).