omnishield / turnstile
Omnishield Turnstile: Cloudflare's captcha - the widget, and its token checked by Cloudflare's siteverify (the visitor's address, the action and the host checked back, a request retried under its idempotency key).
Requires
- php: >=8.2
- glitchr/omnishield: ^1.0@dev
- symfony/http-client: ^6.4|^7.0|^8.0
Requires (Dev)
- phpunit/phpunit: ^11.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is not auto-updated.
Last update: 2026-10-10 14:10:38 UTC
README
Cloudflare Turnstile for glitchr/omnishield: the
widget from Cloudflare, its token checked by Cloudflare's siteverify - the visitor's address
sent with it, the action and the host checked back, a request that got no answer sent once more
under the same idempotency key.
use Omnishield\Model\Attempt; use Omnishield\Turnstile\TurnstileGatewayFactory; $gateway = (new TurnstileGatewayFactory($httpClient))->create(['site_key' => $siteKey, 'secret' => $secret]); $widget = $gateway->widget('contact'); echo $widget->html(); // <script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer> <div class="cf-turnstile" ...> $verdict = $gateway->verify(Attempt::fromPost($_POST, $widget, $ip, 'www.example.org')); $verdict->passed; // false: reasons missing, invalid, spent, action, hostname
omnishield: gateways: cloudflare: factory: turnstile options: { site_key: '%env(TURNSTILE_SITE_KEY)%', secret: '%env(TURNSTILE_SECRET)%', theme: auto }
The visitor's browser talks to Cloudflare (Widget::$origins: https://challenges.cloudflare.com):
name it in the privacy policy, and see what the CNIL says of captchas in omnishield's
privacy. No cookie, by
Cloudflare's Turnstile privacy addendum.
Documentation: the options, the answers, the testing keys, what was verified - the three testing secrets against Cloudflare, on 2026-10-07.
License: MIT since 2026-10-09; earlier versions remain published under LGPL-3.0-or-later.
Formerly omniguard/turnstile, renamed on 2026-10-10 with its family (glitchr/omnishield).