One verifier, backend/app/services/captcha.py, and one widget, components/Captcha.jsx. There were two copies of each and they had drifted: the register widget loaded the script itself while the landing one relied on a page-level effect elsewhere in its file, and on the backend auth failed *open* on an unreachable Turnstile while contact failed *shut*. Both failure modes were kept rather than one quietly chosen, as an explicit `fail_open` argument with the reason written down: an outage that stops people creating accounts costs the site its users, while an outage that bounces a contact message costs the sender one retry. An unconfigured secret still skips verification entirely, as before, so a site with no keys keeps working. The keys in .env are empty. The Cloudflare ones there were live and are now dead, so **there is no captcha on register or contact until hCaptcha keys are issued** — this is not a state to leave a public site in. Also corrected on the way: docs/frontend.md still documented `login(email, password, turnstileToken)`, whose third argument had already gone from AuthContext. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TqXevQJhxFrM7jJg82cgZN
10 lines
287 B
Bash
Executable file
10 lines
287 B
Bash
Executable file
#!/bin/sh
|
|
# Generate runtime config from environment variables.
|
|
# This avoids baking secrets/keys into the Docker image at build time.
|
|
cat > /usr/share/nginx/html/config.js <<EOF
|
|
window.__APP_CONFIG__ = {
|
|
HCAPTCHA_SITE_KEY: "${HCAPTCHA_SITE_KEY:-}"
|
|
};
|
|
EOF
|
|
|
|
exec nginx -g 'daemon off;'
|