Skip to content

Instantly share code, notes, and snippets.

@camaleaun
Last active May 22, 2018 02:02
Show Gist options
  • Select an option

  • Save camaleaun/8e002307a18640a2c53708bce26d29f6 to your computer and use it in GitHub Desktop.

Select an option

Save camaleaun/8e002307a18640a2c53708bce26d29f6 to your computer and use it in GitHub Desktop.
Recaptcha v2 php
# This file is for unifying the coding style for different editors and IDEs
# editorconfig.org
root = true
[*]
charset = iso-8859
end_of_line = lf
insert_final_newline = true
trim_trailing_whitespace = true
indent_style = space
indent_size = 4
# Add any directories, files, or patterns you don't want to be tracked by version control
.DS_Store
thumbs.db
desktop.ini
node_modules
.env
<?php
require 'dotenv.php';
/**
* Google Recaptcha Keys
*/
define('G_RECAPTCHA_SITEKEY', getenv('G_RECAPTCHA_SITEKEY'));
define('G_RECAPTCHA_SECRET', getenv('G_RECAPTCHA_SECRET'));
<?php
if (file_exists('.env')) {
$envs = file_get_contents('./.env', FILE_USE_INCLUDE_PATH);
foreach (array_filter(preg_split('/\r\n|\r|\n/', $envs)) as $line) {
list($key, $value) = explode('=', $line);
putenv("$key=$value");
}
}
<?php
header('location:recaptcha-v2.php');
<?xml version="1.0"?>
<ruleset name="Xframe Coding Standards">
<arg name="encoding" value="iso-8859" />
<arg name="tab-width" value="4" />
<arg value="ps" />
<!-- Include the whole PSR2 standard -->
<rule ref="PSR2">
<exclude phpcs-only="true" name="Generic.ControlStructures.InlineControlStructure" />
<exclude phpcs-only="true" name="Generic.Functions.FunctionCallArgumentSpacing" />
<exclude phpcs-only="true" name="Generic.PHP.DisallowShortOpenTag" />
<exclude name="Generic.NamingConventions.UpperCaseConstantName" />
<exclude phpcs-only="true" name="Generic.WhiteSpace.DisallowTabIndent" />
<exclude name="PSR1.Classes.ClassDeclaration" />
<exclude name="PSR1.Files" />
<exclude phpcs-only="true" name="PSR2.Files.ClosingTag" />
<exclude phpcs-only="true" name="Squiz.ControlStructures.ControlSignature" />
</rule>
<rule name="Generic.WhiteSpace.DisallowTabIndent" />
<arg name="extensions" value="php"/>
<file>.</file>
</ruleset>
<?php
require 'config.php';
require 'recaptchalib.php';
?>
<!doctype html>
<html>
<head>
<meta charset="utf-8">
<title>Recaptcha Demo</title>
<script src='https://www.google.com/recaptcha/api.js'></script>
</head>
<body>
<?php
// Checks if form has been submitted
if ('POST' === $_SERVER['REQUEST_METHOD']) {
// Call the function post_captcha
$res = recaptcha_check_answer(G_RECAPTCHA_SECRET, $_POST['g-recaptcha-response']);
if (! $res->is_valid) {
// What happens when the CAPTCHA wasn't checked
echo '<p>Please go back and make sure you check the security CAPTCHA box.</p><br>';
} else {
// If CAPTCHA is successfully completed...
// Paste mail function or whatever else you want to happen here!
echo '<br><p>CAPTCHA was completed successfully!</p><br>';
}
} else {
?>
<!-- FORM GOES HERE -->
<form action="recaptcha-v2.php" method="post">
<label for="fname">First Name*</label><br>
<input type="text" name="fname" id="fname" required value="Fist Name" autofocus><br><br>
<label for="lname">Last Name*</label><br>
<input type="text" name="lname" id="lname" required value="Last Name"><br><br>
<label for="email">Email Address*</label><br>
<input type="email" name="email" id="email" required value="email@domain.com"><br><br>
<?php echo recaptcha_get_html(G_RECAPTCHA_SITEKEY); ?>
<br>
<input type="submit" id="submit" value="Submit">
</form>
<?php } ?>
</body>
</html>
<?php
class ReCaptcha
{
const VERSION = 'php_1.1.3';
private $secret;
private $requestMethod;
public function __construct($secret, RequestMethod $requestMethod = null)
{
if (empty($secret)) {
throw new \RuntimeException('No secret provided');
}
if (! is_string($secret)) {
throw new \RuntimeException('The provided secret must be a string');
}
$this->secret = $secret;
if (! is_null($requestMethod)) {
$this->requestMethod = $requestMethod;
} else {
$this->requestMethod = new RequestMethod();
}
}
public function verify($response, $remoteIp = null)
{
if (empty($response)) {
$recaptchaResponse = new Response(false, array( 'missing-input-response' ));
return $recaptchaResponse;
}
$params = new RequestParameters($this->secret, $response, $remoteIp, self::VERSION);
$rawResponse = $this->requestMethod->submit($params);
return Response::fromJson($rawResponse);
}
}
class RequestMethod
{
const SITE_VERIFY_URL = 'https://www.google.com/recaptcha/api/siteverify';
public function submit(RequestParameters $params)
{
$peer_key = version_compare(PHP_VERSION, '5.6.0', '<') ? 'CN_name' : 'peer_name';
$options = array(
'http' => array(
'header' => "Content-type: application/x-www-form-urlencoded\r\n",
'method' => 'POST',
'content' => $params->toQueryString(),
// Force the peer to validate (not needed in 5.6.0+, but still works)
'verify_peer' => true,
// Force the peer validation to use www.google.com
$peer_key => 'www.google.com',
),
);
$context = stream_context_create($options);
return file_get_contents(self::SITE_VERIFY_URL, false, $context);
}
}
class RequestParameters
{
private $secret;
private $response;
private $remoteIp;
private $version;
public function __construct($secret, $response, $remoteIp = null, $version = null)
{
$this->secret = $secret;
$this->response = $response;
$this->remoteIp = $remoteIp;
$this->version = $version;
}
public function toArray()
{
$params = array(
'secret' => $this->secret,
'response' => $this->response,
);
if (! is_null($this->remoteIp)) {
$params['remoteip'] = $this->remoteIp;
}
if (! is_null($this->version)) {
$params['version'] = $this->version;
}
return $params;
}
public function toQueryString()
{
return http_build_query($this->toArray(), '', '&');
}
}
class Response
{
private $success = false;
private $errorCodes = array();
private $hostname;
public static function fromJson($json)
{
$responseData = json_decode($json, true);
if (! $responseData) {
return new Response(false, array( 'invalid-json' ));
}
$hostname = isset($responseData['hostname']) ? $responseData['hostname'] : null;
if (isset($responseData['success']) && $responseData['success'] == true) {
return new Response(true, array(), $hostname);
}
if (isset($responseData['error-codes']) && is_array($responseData['error-codes'])) {
return new Response(false, $responseData['error-codes'], $hostname);
}
return new Response(false, array(), $hostname);
}
public function __construct($success, array $errorCodes = array(), $hostname = null)
{
$this->success = $success;
$this->errorCodes = $errorCodes;
$this->hostname = $hostname;
}
public function isSuccess()
{
return $this->success;
}
public function getErrorCodes()
{
return $this->errorCodes;
}
public function getHostname()
{
return $this->hostname;
}
}
function recaptcha_get_html($sitekey, $error = null, $use_ssl = false)
{
if ($sitekey == null || $sitekey == '') {
die('To use reCAPTCHA you must get an API key from <a href="https://www.google.com/recaptcha/admin/create">https://www.google.com/recaptcha/admin/create</a>');
}
return '<div class="g-recaptcha" data-sitekey="' . $sitekey . '"></div>';
}
class ReCaptchaResponse
{
var $is_valid;
var $error;
}
function recaptcha_check_answer($secret, $response, $remoteip = '', $extra_params = array())
{
$recaptcha = new Recaptcha($secret);
$response = $recaptcha->verify($response, $remoteip);
$recaptcha_response = new ReCaptchaResponse();
if ($response->isSuccess()) {
$recaptcha_response->is_valid = true;
} else {
$recaptcha_response->is_valid = false;
$recaptcha_response->error = $response->getErrorCodes();
}
return $recaptcha_response;
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment