php – Google reCAPTCHA无效

我将Google Recaptcha整合到了我的网站.

但是,人们仍然可以填写表格并发送邮件而无需填写验证码. (所以他们没有必要解决他们可以直接通过的任何难题,这当然让我有机会参与其中)

因此,我基本上需要PHP代码来检查用户是否实际上已经“勾选”或“完成”Recaptcha.那么他们就可以继续发送邮件了.

这是我的PHP表单代码:

 <!-- Start Contact Form -->

<div id="contact-form" class="contatct-form">
<div class="loader"></div>
<form method="post" action="mail.php">
<div class="row">
<div class="col-md-4">
<label for="name">Name<span class="required">*</span></label>
<span class="name-missing">Please enter your name</span>
<input id="name" name="name" type="text" value="" size="60">
</div>
<div class="col-md-4">
<label for="e-mail">Email<span class="required">*</span></label>
<span class="email-missing">Please enter a valid e-mail</span>
<input id="e-mail" name="email" type="text" value="" size="60">
</div>
<div class="col-md-4">
<label for="url">Website</label>
<input id="url" name="url" type="text" value="" size="80">
</div>
</div>
<div class="row">
<div class="col-md-12">
<label for="message">Add Your Comment</label>
<span class="message-missing">Say something!</span>
<textarea id="message" name="message" cols="45" rows="10"></textarea>
</br>
 <!--Google  reCAPTCHA-->
<?php
require_once('recaptchalib.php');
$publickey = "My Public Key"; // you got this from the signup page
echo recaptcha_get_html($publickey);
?>
<!--End Google  reCAPTCHA-->
<input type="submit" name="submit" class="button" id="submit_btn" value="Send Message" onclick="return valtest();">
</div>
</div>
</form>

这是我的mail.php代码:

<?php
require_once('recaptchalib.php');
$privatekey = "My private key";
$resp = recaptcha_check_answer ($privatekey,
                            $_SERVER["REMOTE_ADDR"],
                            $_POST["recaptcha_challenge_field"],
                            $_POST["recaptcha_response_field"]);
if (!$resp->is_valid) {
  // What happens when the CAPTCHA was entered incorrectly
  die ("The reCAPTCHA wasn't entered correctly. Go back and try it again." .
     "(reCAPTCHA said: " . $resp->error . ")");
} else {
  $sendto = "myemail@domain.com";
$name=$_REQUEST['name']; 
$usermail = $_REQUEST['email']; 
$url=$_REQUEST['url']; 
$content  = nl2br($_POST['message']); 
$subject  = "Web Enquiry"; 
$headers  = "From: " . strip_tags($name) . "\r\n"; 
$headers .= "Reply-To: ". strip_tags($usermail) . "\r\n"; 
$headers .= "MIME-Version: 1.0\r\n"; 
$headers .= "Content-Type: text/html;charset=utf-8 \r\n"; 
$msg  = "<html><body style='font-family:Arial,sans-serif;'>"; 
$msg .= "<h2 style='font-weight:bold;border-bottom:1px dotted #ccc;'>New    Enquiry</h2>\r\n"; 
$msg .= "<p><strong>Sent by:</strong> ".$usermail."</p>\r\n"; 
$msg .= "<p><strong>Client Name:</strong> ".$name."</p>\r\n";
$msg .= "<p><strong>Message:</strong> ".$content."</p>\r\n";
$msg .= "<p><strong>Contact:</strong> ".$url."</p>\r\n";
$msg .= "</body></html>";
mail($sendto, $subject, $msg, $headers);
echo "<script>window.location =\"index.php\";</script>";

这是recaptchalib.php代码:

 <?php
 /**
 * This is a PHP library that handles calling reCAPTCHA.
 *    - Documentation and latest version
 *          https://developers.google.com/recaptcha/docs/php
 *    - Get a reCAPTCHA API Key
 *          https://www.google.com/recaptcha/admin/create
 *    - Discussion group
 *          http://groups.google.com/group/recaptcha
 *
 * @copyright Copyright (c) 2014, Google Inc.
 * @link      http://www.google.com/recaptcha
 *
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
  * in the Software without restriction, including without limitation the rights
  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
  * copies of the Software, and to permit persons to whom the Software is
  * furnished to do so, subject to the following conditions:
  *
  * The above copyright notice and this permission notice shall be included in
   * all copies or substantial portions of the Software.
    *
    * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
      * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
       * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
      * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
       * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
      * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
       * THE SOFTWARE.
          */
          /**
          * A ReCaptchaResponse is returned from checkAnswer().
          */
           class ReCaptchaResponse
            {
            public $success;
             public $errorCodes;
              }
              class ReCaptcha
                {
                 private static $_signupUrl = "https://www.google.com/recaptcha/admin";
                  private static $_siteVerifyUrl =
                   "https://www.google.com/recaptcha/api/siteverify?";
                  private $_secret;
               private static $_version = "php_1.0";
              /**
 * Constructor.
 *
 * @param string $secret shared secret between site and ReCAPTCHA server.
 */
function ReCaptcha($secret)
{
    if ($secret == null || $secret == "") {
        die("To use reCAPTCHA you must get an API key from <a href='"
            . self::$_signupUrl . "'>" . self::$_signupUrl . "</a>");
    }
    $this->_secret=$secret;
}
/**
 * Encodes the given data into a query string format.
 *
 * @param array $data array of string elements to be encoded.
 *
 * @return string - encoded request.
 */
private function _encodeQS($data)
{
    $req = "";
    foreach ($data as $key => $value) {
        $req .= $key . '=' . urlencode(stripslashes($value)) . '&';
    }
    // Cut the last '&'
    $req=substr($req, 0, strlen($req)-1);
    return $req;
}
/**
 * Submits an HTTP GET to a reCAPTCHA server.
 *
 * @param string $path url path to recaptcha server.
 * @param array  $data array of parameters to be sent.
 *
 * @return array response
 */
 private function _submitHTTPGet($path, $data)
  {
    $req = $this->_encodeQS($data);
    $response = file_get_contents($path . $req);
    return $response;
  }
  /**
   * Calls the reCAPTCHA siteverify API to verify whether the user passes
   * CAPTCHA test.
   *
   * @param string $remoteIp   IP address of end user.
   * @param string $response   response string from recaptcha verification.
    *
    * @return ReCaptchaResponse
    */
     public function verifyResponse($remoteIp, $response)
     {
    // Discard empty solution submissions
    if ($response == null || strlen($response) == 0) {
        $recaptchaResponse = new ReCaptchaResponse();
        $recaptchaResponse->success = false;
        $recaptchaResponse->errorCodes = 'missing-input';
        return $recaptchaResponse;
    }
    $getResponse = $this->_submitHttpGet(
        self::$_siteVerifyUrl,
        array (
            'secret' => $this->_secret,
            'remoteip' => $remoteIp,
            'v' => self::$_version,
            'response' => $response
        )
    );
    $answers = json_decode($getResponse, true);
    $recaptchaResponse = new ReCaptchaResponse();
    if (trim($answers ['success']) == true) {
        $recaptchaResponse->success = true;
    } else {
        $recaptchaResponse->success = false;
        $recaptchaResponse->errorCodes = $answers [error-codes];
    }
    return $recaptchaResponse;
    }
 }
 ?>

当我更换

      <!--Google  reCAPTCHA-->
      <?php
      require_once('recaptchalib.php');
      $publickey = "My Site Key"; // you got this from the signup page
      echo recaptcha_get_html($publickey);
       ?>
      <!--End Google  reCAPTCHA-->

             <!--Google  reCAPTCHA-->
             <div class="g-recaptcha" data-sitekey="My Site key"></div>
             <!--End Google  reCAPTCHA-->

它将显示小部件,但人们仍然可以填写表单并发送邮件而无需完成验证码.

解决方法:

首先,你必须检查是否重新设置了recaptcha:

<?php

$errMsg = "";
$succMsg = "";

/**************************/
/* GOOGLE reCAPTCHA START */
/**************************/
require_once '../../reCAPTCHA/autoload.php';
$siteKey = 'sitekey';
$secret = 'secretkey';
/************************/
/* GOOGLE reCAPTCHA END */
/************************/

if ((isset($_POST['submit']) | !empty($_POST["submit"]))) {

    if ((isset($_POST['g-recaptcha-response'])) && !empty($_POST["g-recaptcha-response"])) {

        $recaptcha = new \ReCaptcha\ReCaptcha($secret);
        $resp = $recaptcha->verify($_POST['g-recaptcha-response'], $_SERVER['REMOTE_ADDR']);
        if ($resp->isSuccess()) {

            $succMsg = "Success Message";

            /**
             * DO THE DB ENTRIES HERE
             */

        }

    } else {

        $errMsg = "Error With Captcha";
    }
}
?>

你将需要谷歌的these文件.
他们在这里加载:require_once’../../reCAPTCHA/autoload.php’;

您的表单页面应如下所示:

<head>
    <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.css">
    <script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.1.1/jquery.min.js"></script>
    <script src="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/js/bootstrap.min.js"></script>

    <script src="https://www.google.com/recaptcha/api.js" async defer></script>
</head>
<div id="contact-form" class="contatct-form">
    <div class="loader"></div>
    <form method="post">
        <div class="row">
            <?php
                if (isset($succMsg)) {
                    echo $succMsg;
                } else {
                    echo "";
                }
                if (isset($errMsg)) {
                    echo $errMsg;
                } else {
                    echo "";
                }
            ?>
            <div class="col-md-4">
                <label for="name">Name<span class="required">*</span></label>
                <span class="name-missing">Please enter your name</span>
                <input id="name" name="name" type="text" value="" size="60">
            </div>
            <div class="col-md-4">
                <label for="e-mail">Email<span class="required">*</span></label>
                <span class="email-missing">Please enter a valid e-mail</span>
                <input id="e-mail" name="email" type="text" value="" size="60">
            </div>
            <div class="col-md-4">
                <label for="url">Website</label>
                <input id="url" name="url" type="text" value="" size="80">
            </div>
        </div>
        <div class="row">
            <div class="col-md-12">
                <label for="message">Add Your Comment</label>
                <span class="message-missing">Say something!</span>
                <textarea id="message" name="message" cols="45" rows="10"></textarea>
                <br>
                <div class="g-recaptcha" data-sitekey="<?php echo $siteKey; ?>"></div>
                <input type="submit" name="submit" class="button" id="submit_btn" value="Send Message" onclick="return valtest();">
            </div>
        </div>
    </form>
</div>
上一篇:单周赛 2022.2.6 题解汇总


下一篇:AtCoder Beginner Contest 238 A - F 题解