Fix reCAPTCHA - #1211
Draft
n7studios wants to merge 1 commit into
Draft
Fix reCAPTCHA#1211n7studios wants to merge 1 commit into
n7studios wants to merge 1 commit into
Conversation
WordPress Playground🚀 Your PR has been built and is ready for testing in WordPress Playground! |
n7studios
marked this pull request as ready for review
October 1, 2026 11:23
n7studios
requested review from
a team,
ciccio-kit and
noelherrick
and removed request for
a team
October 1, 2026 11:23
n7studios
marked this pull request as draft
October 2, 2026 02:46
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes several issues with spam protection (Google reCAPTCHA v3 and Cloudflare Turnstile) on the Form Builder block, Restrict Content tag form and Member Content login form:
ConvertKit_Recaptcha::verify()returnedtruewhen the token's action didn't match the form's action, skipping the minimum score check. A token generated for any other action passed verification. A mismatched or missing action now fails with the sameGoogle reCAPTCHA failederror as a low score. A missing score is also treated as a failure. Each form's submit button and server-side check already use the same action, so genuine submissions aren't affected.error-codes,implode()threw aTypeError. Both providers now handle a missingerror-codes. reCAPTCHA also handles a response body that isn't valid JSON. Turnstile also handles a response with nosuccesskey.convertKitRecaptchaFormSubmit()always submitted the first reCAPTCHA protected form on the Page. For example, with two Form Builder blocks, or a Form Builder block and a Restrict Content tag form, clicking the second form's button submitted the first form. The clicked submit button is now stored, and its form is submitted.Testing
New Integration tests in
SpamProtectionTest, mocking Google's and Cloudflare's siteverify responses:testRecaptchaValidTokentestRecaptchaLowScoretestRecaptchaActionMismatchtestRecaptchaNoActiontestRecaptchaFailureWithErrorCodestestRecaptchaFailureWithNoErrorCodestestRecaptchaInvalidResponsetestCloudflareTurnstileValidTokentestCloudflareTurnstileFailureWithNoErrorCodestestCloudflareTurnstileNoSuccessAll of these except
testRecaptchaValidToken,testRecaptchaLowScore,testRecaptchaFailureWithErrorCodesandtestCloudflareTurnstileValidTokenfail onmain.New E2E test,
PageBlockFormBuilderCest::testFormBuilderWithRecaptchaEnabledSubmitsClickedForm:main, the first form is submitted.The existing reCAPTCHA E2E tests in
PageBlockFormBuilderCest,RestrictContentTagCestandRestrictContentMemberContentLoginCestuse real keys from CI secrets, so they need to pass in CI to confirm genuine submissions aren't affected.Checklist