
Security News
Deno 2.2 Improves Dependency Management and Expands Node.js Compatibility
Deno 2.2 enhances Node.js compatibility, improves dependency management, adds OpenTelemetry support, and expands linting and task automation for developers.
express-recaptcha
Advanced tools
Google recaptcha middleware for express.
express-recaptcha v2 (previous middleware version).
npm install express-recaptcha --save
app.use(bodyParser.json())
app.use(bodyParser.urlencoded({ extended: true }))
var Recaptcha = require('express-recaptcha').RecaptchaV3
//import Recaptcha from 'express-recaptcha'
var recaptcha = new Recaptcha('SITE_KEY', 'SECRET_KEY')
//or with options
var options = { hl: 'de' }
var recaptcha = new Recaptcha('SITE_KEY', 'SECRET_KEY', options)
options
available/properties:option | description |
---|---|
onload | The callback function that gets called when all the dependencies have loaded. |
hl | Forces the widget to render in a specific language (Auto-detects if unspecified). |
callback | In that callback you will call your backend to verify the given token. To be verified, the token needs to be posted with the key g-recaptcha-response (see the example folder) |
action | homepage by default should only be alphanumeric More info on google's web site |
checkremoteip | Adding support of remoteip verification (based on x-forwarded-for header or remoteAddress.Value could be true OR false (default false). |
useRecaptchaDomain | Boolean. Sets www.recaptcha.net as the host; useful in instances where www.google.com may be blocked (as detailed in the reCaptcha docs) |
For more information, please refer to:
recaptcha.middleware.render
The middleware's render method sets the recaptcha
property of res
object, with the generated html code. Therefore, you can easily append recaptcha into your templates by passing res.recaptcha
to the view:
app.get('/', recaptcha.middleware.render, function (req, res) {
res.render('login', { captcha: res.recaptcha })
})
recaptcha.middleware.renderWith
Same as the render middleware method except that you can override the options in parameter :
app.get(
'/',
recaptcha.middleware.renderWith({ hl: 'fr' }),
function (req, res) {
res.render('login', { captcha: res.recaptcha })
}
)
recaptcha.middleware.verify
The middleware's verify method sets the recaptcha
property of req
object, with validation information:
app.post('/', recaptcha.middleware.verify, function (req, res) {
if (!req.recaptcha.error) {
// success code
} else {
// error code
}
})
The response verification is performed on params
, query
, and body
properties for the req
object.
Here is an example of a req.recaptcha
response:
{
error: string, // error code (see table below), null if success
data: {
hostname: string, // the site's hostname where the reCAPTCHA was solved
score: number, // the score for this request (0.0 - 1.0)
action: string // the action name for this request (important to verify)
}
}
Error code | Description |
---|---|
missing-input-secret | The secret parameter is missing. |
invalid-input-secret | The secret parameter is invalid or malformed. |
missing-input-response | The response parameter is missing. |
invalid-input-response | The response parameter is invalid or malformed. |
invalid-json-response | Can't parse google's response. Server error. |
var express = require('express')
var bodyParser = require('body-parser')
var pub = __dirname + '/public'
var app = express()
var Recaptcha = require('express-recaptcha').RecaptchaV3
var recaptcha = new Recaptcha('SITE_KEY', 'SECRET_KEY', { callback: 'cb' })
//- required by express-recaptcha in order to get data from body or query.
app.use(bodyParser.json())
app.use(bodyParser.urlencoded())
app.use(express.static(pub))
app.set('views', __dirname + '/views')
app.set('view engine', 'jade')
app.get('/', recaptcha.middleware.render, function (req, res) {
res.render('login', { captcha: res.recaptcha })
})
// override default options for that route
app.get(
'/fr',
recaptcha.middleware.renderWith({ hl: 'fr' }),
function (req, res) {
res.render('login', { captcha: res.recaptcha })
}
)
app.post('/', recaptcha.middleware.verify, function (req, res) {
if (!req.recaptcha.error) {
// success code
} else {
// error code
}
})
recaptcha.verify
callback instead)var express = require('express')
var bodyParser = require('body-parser')
var pub = __dirname + '/public'
var app = express()
var Recaptcha = require('express-recaptcha').RecaptchaV3
var recaptcha = new Recaptcha('SITE_KEY', 'SECRET_KEY', { callback: 'cb' })
//- required by express-recaptcha in order to get data from body or query.
app.use(bodyParser.json())
app.use(bodyParser.urlencoded())
app.use(express.static(pub))
app.set('views', __dirname + '/views')
app.set('view engine', 'jade')
app.get('/', function (req, res) {
res.render('login', { captcha: recaptcha.render() })
})
// override default options for that route
app.get('/fr', function (req, res) {
res.render('login', { captcha: recaptcha.renderWith({ hl: 'fr' }) })
})
app.post('/', function (req, res) {
recaptcha.verify(req, function (error, data) {
if (!error) {
// success code
} else {
// error code
}
})
})
Run the example folder for a live demo:
$ node example\server.js
FAQs
Google recaptcha middleware for express
The npm package express-recaptcha receives a total of 6,083 weekly downloads. As such, express-recaptcha popularity was classified as popular.
We found that express-recaptcha demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Deno 2.2 enhances Node.js compatibility, improves dependency management, adds OpenTelemetry support, and expands linting and task automation for developers.
Security News
React's CRA deprecation announcement sparked community criticism over framework recommendations, leading to quick updates acknowledging build tools like Vite as valid alternatives.
Security News
Ransomware payment rates hit an all-time low in 2024 as law enforcement crackdowns, stronger defenses, and shifting policies make attacks riskier and less profitable.