Episerver表单reCAPTCHA遭机器人提交:是否需自定义服务端验证?
关于Episerver表单reCAPTCHA防机器人提交的解决方案
优先尝试调高reCAPTCHA评分阈值
Episerver表单自带的reCAPTCHA集成已经包含基础服务端验证,但默认的风险评分阈值可能偏宽松。你可以直接在表单设置里把评分要求调高(比如从默认的0.5调整到0.7或0.8),更高的评分会过滤掉更多疑似机器人的请求。这是无需额外开发的快速方案,建议先测试调整后的拦截效果。自定义服务端验证作为补充(若调分后仍有漏网)
如果调高评分后还是有机器人提交,就需要通过自定义服务端验证来强化防护。Episerver允许你在表单提交的服务端事件中,手动调用Google reCAPTCHA的验证接口做二次校验:- 监听表单的
FormSubmitting事件,获取前端传来的reCAPTCHA响应令牌 - 调用Google的
siteverify接口,传入你的服务端密钥和令牌完成验证 - 若验证失败或评分未达标,直接拒绝表单提交
示例C#代码片段:
public class CustomRecaptchaValidation : IInitializableModule { public void Initialize(InitializationEngine context) { FormEvents.FormSubmitting += OnFormSubmitting; } private void OnFormSubmitting(object sender, FormSubmittingEventArgs e) { var recaptchaToken = e.FormData.GetValue("g-recaptcha-response")?.ToString(); if (string.IsNullOrWhiteSpace(recaptchaToken)) { e.CancelAction = true; e.Message = "reCAPTCHA验证未通过"; return; } using var client = new HttpClient(); var verificationResponse = client.PostAsync( "https://www.google.com/recaptcha/api/siteverify", new FormUrlEncodedContent(new Dictionary<string, string> { {"secret", "你的服务端密钥"}, {"response", recaptchaToken} })).Result; var result = verificationResponse.Content.ReadFromJsonAsync<RecaptchaResult>().Result; if (!result.Success || result.Score < 0.8) { e.CancelAction = true; e.Message = "疑似机器人操作,请重试"; } } public void Uninitialize(InitializationEngine context) { FormEvents.FormSubmitting -= OnFormSubmitting; } private class RecaptchaResult { public bool Success { get; set; } public float Score { get; set; } } }- 监听表单的
额外注意事项
- 检查是否存在机器人绕过前端reCAPTCHA、直接调用表单提交API的情况,这种场景下服务端二次验证是必需的
- 建议给不同表单设置reCAPTCHA v3的
action参数,Google会基于不同动作维度分析风险,提升验证准确性
内容的提问来源于stack exchange,提问作者Farhin Shaikh
相关产品推荐
相关产品推荐

