TechnicalCollectible prompt

Cloudflare Turnstile CAPTCHA verified on the server

Stop bots on forms without puzzles, and check every token on the server so nobody can skip the widget.

CursorClaude CodeLovable

Curated by Nvoka

0 saves · 1 view

Nvoka wordmark logo
Nvoka wordmark logoTechnical

Cloudflare Turnstile CAPTCHA verified on the server

Act as a senior web security engineer. Add Cloudflare Turnstile to {{page_or_feature}} in my {{tech_stack}} project. Before changing anything, read the existing forms and server handlers and tell me what you found. Client: - Load the Turnstile script only on pages with a protected form, and reserve the widget's space so nothing shifts - Managed mode by default: most people never see a challenge. Use invisible mode only where a visible widget would hurt a key flow - Send the token with the form. Keep submit disabled until a token exists, refresh the widget when the token expires, and show a plain retry message on errors - Match the widget's theme and language to the page Server, the part AI builders skip: - Verify every token with Cloudflare's siteverify endpoint before doing any work. The widget alone stops nothing; a bot can post straight to the API - Check success, the expected hostname and the action name. Tokens last 5 minutes and work once, so reject reused ones - The secret key stays in a server environment variable; only the site key reaches the browser - If Cloudflare can't be reached: fail closed for sign-up, fail open with stricter rate limits for contact forms, and log it - Return one generic error, never the reason a check failed Also: - Allow challenges.cloudflare.com for scripts and frames in the Content Security Policy - Use Cloudflare's published test keys in development and tests - Accessibility: the widget works by keyboard and screen reader, and the page offers another way to reach us if it fails - Keep the honeypot and rate limits. Turnstile is one layer, not the only one - Alternatives: hCaptcha works the same way; reCAPTCHA v3 returns a score you must threshold on the server. Tell me if either fits better Finish with the files changed, how to test a passing, failing and expired token, and anything you assumed.
0 saves · 1 viewnvoka.com/library/nvoka-cloudflare-turnstile-captcha-with-server-verificationScan to open
Technical

Cloudflare Turnstile CAPTCHA verified on the server

Stop bots on forms without puzzles, and check every token on the server so nobody can skip the widget.

Nvoka logo

Curated by Nvoka

1 viewCursorClaude CodeLovableCodex
Add to my library

Make it yours

Fill in the blanks and change any word. Only your copy changes, never the card.

Fill in the blanks

0 of 2 filled

Your prompt

Act as a senior web security engineer. Add Cloudflare Turnstile to {{page_or_feature}} in my {{tech_stack}} project. Before changing anything, read the existing forms and server handlers and tell me what you found. Client: - Load the Turnstile script only on pages with a protected form, and reserve the widget's space so nothing shifts - Managed mode by default: most people never see a challenge. Use invisible mode only where a visible widget would hurt a key flow - Send the token with the form. Keep submit disabled until a token exists, refresh the widget when the token expires, and show a plain retry message on errors - Match the widget's theme and language to the page Server, the part AI builders skip: - Verify every token with Cloudflare's siteverify endpoint before doing any work. The widget alone stops nothing; a bot can post straight to the API - Check success, the expected hostname and the action name. Tokens last 5 minutes and work once, so reject reused ones - The secret key stays in a server environment variable; only the site key reaches the browser - If Cloudflare can't be reached: fail closed for sign-up, fail open with stricter rate limits for contact forms, and log it - Return one generic error, never the reason a check failed Also: - Allow challenges.cloudflare.com for scripts and frames in the Content Security Policy - Use Cloudflare's published test keys in development and tests - Accessibility: the widget works by keyboard and screen reader, and the page offers another way to reach us if it fails - Keep the honeypot and rate limits. Turnstile is one layer, not the only one - Alternatives: hCaptcha works the same way; reCAPTCHA v3 returns a score you must threshold on the server. Tell me if either fits better Finish with the files changed, how to test a passing, failing and expired token, and anything you assumed.
See all